Extend IaC Code with Skills

Updated at:

Skills inject domain knowledge, task standards, and reusable workflows into IaC Code. Using a ROS template review example, this topic describes the Skill discovery scopes, how to create a Skill, and how to verify and invoke it in the REPL and in the web version.

Prerequisites

  • You have completed the operations in Install and configure IaC Code.

  • You are in the project directory where you want to use the Skill.

  • You have permission to create directories and files in the project directory.

Skill discovery scopes

A Skill is a directory that contains SKILL.md. The following table lists the locations from which IaC Code discovers Skills, in ascending order of priority. If two Skills have the same name, the Skill from the scope with the higher priority takes effect.

Scope

Directory

Scenarios

User level

~/.iac-code/skills/

Shared by multiple projects of the current user.

Project level

<project>/skills/

Compatible with existing project directory conventions.

Project configuration level

<project>/.iac-code/skills/

IaC Code extensions that are maintained together with the project.

Built-in

Not applicable. Built-in Skills are released with IaC Code.

Official capabilities. A user Skill or project Skill with the same name cannot override them.

Project directories are discovered level by level from the Git repository root to the current directory. You can define common Skills in the repository root and add more specific Skills in subdirectories.

Create a minimal Skill

Create the following files in the project root directory:

.iac-code/
└── skills/
    └── ros-template-review/
        └── SKILL.md

Add the following content to SKILL.md:

---
name: ros-template-review
description: Review a ROS template against project standards and output a graded issue list
when_to_use: When you are asked to check or review a ROS template
argument_hint: <template-path>
user_invocable: true
---

Review the ROS template specified by `$ARGUMENTS`. Only read files. Do not modify files or deploy resources.

Check the following items in order:

1. Whether the template syntax, parameter types, AllowedValues, and default values are consistent.
2. Whether resource dependencies such as Ref, Fn::GetAtt, and DependsOn are valid.
3. Security risks such as security groups, public access, long-term credentials, and overly broad permissions.
4. Whether resource naming, Tag, and Outputs comply with project conventions.

Output issues at three levels: Blocker, Warning, and Suggestion. Each item includes the file location, the cause, and a suggested fix. If no issue is found, state the scope that was checked.

Verify and invoke a Skill in the REPL

  1. Start IaC Code in the project directory:

    iac-code
  2. Enter /skills, and confirm in the Skill manager that ros-template-review appears and is enabled.

  3. Enter the following command to invoke the Skill.

    $ros-template-review template.yaml

    /ros-template-review template.yaml produces the same result.

Expected result: IaC Code reads and reviews template.yaml in the order defined in SKILL.md, and outputs results at three levels: “blocker,” “warning,” and “suggestion.” It does not modify or deploy resources.

After modifying SKILL.md, restart the session or re-enter the project to refresh the discovery results. When you need to reference longer specifications, templates, or examples, you can add files such as references/ under the Skill directory and reference them in SKILL.md as needed, to avoid repeating all the content in the main file.

Verify and invoke a Skill in the web version

  1. Start the web version of IaC Code. Create or open a session that uses the project directory.

  2. Open Settings > Plugins > Skills, select the project, and confirm that ros-template-review appears. You can search for Skills here, and enable or disable Skills that are not built-in.

  3. Return to the session, and enter $ros-template-review template.yaml in the input box.

Expected result: The result is the same as in the REPL. After the Skill is triggered, the web version displays the tool cards, the execution results, and the permission requests in the conversation.

Typical use cases

Use Skills for the following types of work:

  • Resource operation processes — Codify your organization's processes for cloud resource planning, creation, modification, and cleanup.

  • Template standards and reviews — Codify organizational standards and review checklists for ROS or Terraform templates.

  • Baseline standardization — Standardize environments, regions, naming, tags, networks, and security baselines.

  • Operational procedures — Encapsulate pre-deployment checks, cost reviews, or troubleshooting procedures.

  • Reusable inputs and outputs — Unify input parameters and output formats so that team members can reuse them.

Permissions and security

  • Trusted sources — Install and enable only Skills from trusted sources, and review SKILL.md and its referenced files before you use them.

  • Code review — Skills in a project repository affect agent behavior. Review them as you review code.

  • Secrets — Do not store an API key, an AccessKey, or other secrets in SKILL.md or its referenced files.

  • Least privilege — Skills cannot bypass the tool permissions of IaC Code. Apply least privilege to files, commands, and write operations in the cloud.

FAQ

A Skill is not discovered

  1. Confirm that the directory name and the file name are <skill-name>/SKILL.md.

  2. Confirm that the YAML frontmatter contains a non-empty name and a non-empty description.

  3. Confirm that the current directory is in the expected project.

  4. Enter /skills to check whether the Skill is disabled or is overridden by a higher-priority Skill with the same name.

A Skill does not use arguments as expected

Use $ARGUMENTS in the body to get the full set of arguments, or use $0, $1, and named parameters for positional substitution. When invoking, use $<skill-name> <arguments> to search only within Skills, avoiding confusion with ordinary slash commands.

References