Terror is an agentic Terraform replacement that lets you provision and manage cloud infrastructure through natural language, using a stateless, plan-then-apply architecture with built-in rollback.
SaferSkills independently audited Terror (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center">
▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄ ▄▄▄▄▄▄ ▄▄▄▄▄▄ ▄▄▄▄▄▄▄ ▄▄▄▄▄▄
█ █ █ ▄ █ █ ▄ █ █ █ ▄ █
█▄ ▄█ ▄▄▄█ █ █ █ █ █ █ █ █ ▄ █ █ █ █
█ █ █ █▄▄▄█ █▄▄█▄█ █▄▄█▄█ █ █ █ █▄▄█▄
█ █ █ ▄▄▄█ ▄▄ █ ▄▄ █ █▄█ █ ▄▄ █
█ █ █ █▄▄▄█ █ █ █ █ █ █ █ █ █ █
█▄▄▄█ █▄▄▄▄▄▄▄█▄▄▄█ █▄█▄▄▄█ █▄█▄▄▄▄▄▄▄█▄▄▄█ █▄The ghost in your cloud.
</div>
Terror is an agentic Terraform replacement built as an MCP tool. Agents provision and manage cloud infrastructure through natural language -- no HCL, no state files. Cloud provider APIs are the sole source of truth, and every mutation passes through a decision gate where the agent evaluates its own plan before executing.
bun add @terror/core @terror/gcpAdd Terror to your MCP config:
// .mcp.json
{
"mcpServers": {
"terror": {
"command": "npx",
"args": ["@terror/core"],
"env": {
"GOOGLE_APPLICATION_CREDENTIALS": "/path/to/credentials.json"
}
}
}
}Then ask your agent to manage infrastructure:
> Create a Cloud Storage bucket called "my-assets" in us-central1
> Deploy this Cloud Run service with 512MB memory
> Show me all VMs in project "staging"| Provider | Status |
|---|---|
| GCP | Full CRUD -- Compute, Storage, VPC, IAM, Cloud Run, Functions, SQL, Pub/Sub |
| AWS | Coming soon |
| Cloudflare | Coming soon |
| DigitalOcean | Coming soon |
Agent <--stdio--> @terror/core <--plugin--> @terror/gcp
| |
Plan Engine Cloud APIs
OAuth Broker
Tool RegistryTwo-layer tool design: low-level CRUD per resource type, plus high-level intent-based composite operations. Every mutation carries a rollback handler.
See CLAUDE.md for full architectural details.
Tell your agent to read docs/install.md.
MIT -- Roguelite Software
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.