Skip to content
Back to skills

Infrastructure As Code Safety

ASecurity

IaC state, identity, drift, destruction, and recovery safety.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 8, 2026
devops

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add machenjie/rd-skills --skill infrastructure-as-code-safety --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Infrastructure As Code Safety?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Infrastructure As Code Safety
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/machenjie-infrastructure-as-code-safety/badge)](https://www.skillsdirectory.com/skills/machenjie-infrastructure-as-code-safety)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: infrastructure-as-code-safety
description: "IaC state, identity, drift, destruction, and recovery safety."
---

# infrastructure-as-code-safety

## Registry Trigger

**Use when**

- IaC state/identity/drift/destruction/recovery/proposal limits

**Do not use when**

- docs, production mutation, or provider-only policy

## Skill Role

Own cross-tool state/identity/destruction/recovery; exclude adjacent and production authority.

## High-Value Rules

- Bind state authority and layer boundaries.
- Bind proposals to source/recorded/effective state, identity/effects/recovery, versions, and unknowns.
- Reject unproved tool equivalence, execution, or convergence.

## Anti-Patterns

- Local success is not IaC evidence.

## Stop Conditions

- Stop on unresolved authority, effects, recovery, or production mutation.

## Output Contract

- target and state authority proposal limits identity and graph effects destruction sensitive outcomes recovery validation proof limits and residual owner

## Targeted References

| Path | Type | Load when | Do not load when | Required by | Required output |
|---|---|---|---|---|---|
| [state plan and drift contracts](references/state-plan-and-drift-contracts.md) | targeted | State authority locking drift unknown values or proposal freshness differs by the selected tool | One bounded source change preserves recorded and effective state without tool-specific proposal interpretation | analysis-agent, task-agent, review-agent | decision-record, proof-limit, residual-risk |
| [identity destruction and recovery contracts](references/identity-destruction-and-recovery-contracts.md) | targeted | Resource identity targeting replacement destruction protection recovery or secret exposure differs by the selected tool | No identity destructive sensitive or recovery outcome can change | analysis-agent, task-agent, review-agent | decision-record, proof-limit, residual-risk |

Files in this skill

  • SKILL.md4.1 KB
  • references/identity-destruction-and-recovery-contracts.md4.6 KB
  • references/state-plan-and-drift-contracts.md4.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…