tfmcp
Infrastructure · tested 2026-08-14 · by the Hlido desk, not the vendor
In short: A Terraform MCP server that lets an LLM run apply against your infrastructure, and whose own landing banner tells you it is still under active development — the warning is the most useful thing on the page.
Quick answer
tfmcp scores 64/100 (FADING) on Hlido’s independent, hands-on test (reviewed 2026-08-14). FADING because the checks that matter most for a tool holding apply-level infrastructure access are unmet on the public surface: no tool inventory, no description of the guardrails between an LLM decision and a state mut Pricing: Paid.
tfmcp exposes Terraform to LLMs over MCP: reading configuration, analysing plan output, applying configurations, managing state and creating or modifying configs. The reviewed surface is the crates.io package page (v0.2.2, ten published versions), which carries the README, a cargo install line, topic tags and dependency and version tabs. Release notes for v0.2.2 mention RMCP 3.0.1, MCP 2026-07-28 discovery support, structured JSON tool results with backward-compatible text content, and a five-minute public cache — concrete, dated detail that suggests real maintenance rather than an abandoned experiment. The concern is the capability list itself. 'Applying Terraform configurations' and 'managing Terraform state' are the two most destructive operations in the infrastructure toolchain, and the project's own banner says it 'includes production-ready security features but is still under active development' while asking you to review all operations carefully in production. That is honest, and it is the correct disclosure — but the security system it refers to is never described on this surface. There is no dedicated docs site here, no enumerated tool list, no statement of what guardrails exist between an LLM's decision and a state-mutating apply. Compare MikroMCP, which makes dry-run, rollback and audit its headline: tfmcp asks for comparable trust and shows less of its work. The package page is a package page; what this category needs is a security model.
Why FADING
FADING because the checks that matter most for a tool holding apply-level infrastructure access are unmet on the public surface: no tool inventory, no description of the guardrails between an LLM decision and a state mutation, and no documentation site beyond the package README. Held mid-band rather than lower because maintenance signals are genuinely good — ten versions, dated release notes, current MCP spec support — and because the project discloses its own maturity limits instead of hiding them.
What we saw
4 screenshots captured by the Hlido engine during the reviewed run (run-3fd6f6cb9df9eb30-crates-io). Our own captures — not vendor marketing material.
What it does well
- Publishes real version history — v0.2.2 with ten released versions visible
- Release notes are specific and dated (RMCP 3.0.1, MCP 2026-07-28 discovery, structured JSON results)
- Tracks the current MCP specification rather than an old snapshot
- Discloses its own maturity limits prominently instead of burying them
- Single-command install via cargo; Rust implementation means a self-contained binary
What it fails at
- No enumerated tool inventory — a buyer cannot see what the server exposes before installing
- The 'production-ready security features' it cites are never described anywhere on the surface
- No guardrail story (dry-run, plan gating, approval, rollback) for a tool that can run apply
- No dedicated documentation site; the package README is the entire public surface
- No statement on how Terraform credentials or state backends are accessed
Red flags
- The server can apply Terraform configurations and manage state — the two most destructive operations available — while publishing no description of what stands between an LLM's decision and that mutation.
- The project's own banner states it is under active development and asks users to review all operations carefully in production. Treat that as the operative guidance, not marketing caution.
Best for
- Terraform users who want LLM assistance with reading and analysing configuration and plans
- Rust-comfortable operators who will read the source before granting access
- Non-production or sandbox environments where an unguarded apply is survivable
Not recommended for
- Production infrastructure without an external approval gate — the tool ships no described guardrail of its own
- Teams needing a documented security model before granting state-mutating access
- Anyone wanting a published tool inventory to reason about before installation
Pricing & access
- ModelPaid
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-14.
Compared to
-
MikroMCP
published-safety-model
MikroMCP asks for comparable infrastructure trust and makes dry-run, rollback, RBAC and audit its headline. tfmcp targets Terraform rather than RouterOS but publishes far less about its safety model — the useful contrast is what each chooses to show.
-
Open Source MCP Servers for AWS
provenance-vs-portability
AWS's infrastructure-and-deployment servers are first-party with vendor continuity; tfmcp is a single-maintainer community project but is Terraform-native and cloud-agnostic. Choose on provenance versus portability.
Agent relevance
CLI MCP Behavioral-testable
Agentic-Commerce Readiness 46/100 · SURFACE-ONLY
Independent readiness for agent delegation & transaction. How it’s scored · check live
MCP server with current-spec discovery support (MCP 2026-07-28) and structured JSON tool results, which is genuinely good agent ergonomics — a calling agent gets parseable output rather than prose. Undercut by the absence of a published tool inventory, so capability must be discovered at runtime.
Agent-friendly score: 7/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Homepage publicly accessible and value proposition clearly stated — source (2026-08-14) verified
- Pricing page discoverable in 2 clicks from homepage — source (2026-08-14)
- Documentation or live demo accessible without login — source (2026-08-14)
- Integration list or supported frameworks documented — source (2026-08-14)
- Authentication / data handling claims publicly stated — source (2026-08-14)



