tfmcp

Infrastructure · tested 2026-08-14 · by the Hlido desk, not the vendor

In short: A Terraform MCP server that lets an LLM run apply against your infrastructure, and whose own landing banner tells you it is still under active development — the warning is the most useful thing on the page.

Quick answer

tfmcp scores 64/100 (FADING) on Hlido’s independent, hands-on test (reviewed 2026-08-14). FADING because the checks that matter most for a tool holding apply-level infrastructure access are unmet on the public surface: no tool inventory, no description of the guardrails between an LLM decision and a state mut Pricing: Paid.

tfmcp exposes Terraform to LLMs over MCP: reading configuration, analysing plan output, applying configurations, managing state and creating or modifying configs. The reviewed surface is the crates.io package page (v0.2.2, ten published versions), which carries the README, a cargo install line, topic tags and dependency and version tabs. Release notes for v0.2.2 mention RMCP 3.0.1, MCP 2026-07-28 discovery support, structured JSON tool results with backward-compatible text content, and a five-minute public cache — concrete, dated detail that suggests real maintenance rather than an abandoned experiment. The concern is the capability list itself. 'Applying Terraform configurations' and 'managing Terraform state' are the two most destructive operations in the infrastructure toolchain, and the project's own banner says it 'includes production-ready security features but is still under active development' while asking you to review all operations carefully in production. That is honest, and it is the correct disclosure — but the security system it refers to is never described on this surface. There is no dedicated docs site here, no enumerated tool list, no statement of what guardrails exist between an LLM's decision and a state-mutating apply. Compare MikroMCP, which makes dry-run, rollback and audit its headline: tfmcp asks for comparable trust and shows less of its work. The package page is a package page; what this category needs is a security model.

Why FADING

FADING because the checks that matter most for a tool holding apply-level infrastructure access are unmet on the public surface: no tool inventory, no description of the guardrails between an LLM decision and a state mutation, and no documentation site beyond the package README. Held mid-band rather than lower because maintenance signals are genuinely good — ten versions, dated release notes, current MCP spec support — and because the project discloses its own maturity limits instead of hiding them.

What we saw

4 screenshots captured by the Hlido engine during the reviewed run (run-3fd6f6cb9df9eb30-crates-io). Our own captures — not vendor marketing material.

tfmcp — run screenshot 1 (home.png)
home.png
tfmcp — run screenshot 2 (page_code.png)
page_code.png
tfmcp — run screenshot 3 (page_versions.png)
page_versions.png
tfmcp — run screenshot 4 (page_dependencies.png)
page_dependencies.png

What it does well

What it fails at

Red flags

Best for

  • Terraform users who want LLM assistance with reading and analysing configuration and plans
  • Rust-comfortable operators who will read the source before granting access
  • Non-production or sandbox environments where an unguarded apply is survivable

Not recommended for

  • Production infrastructure without an external approval gate — the tool ships no described guardrail of its own
  • Teams needing a documented security model before granting state-mutating access
  • Anyone wanting a published tool inventory to reason about before installation

Pricing & access

Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-14.

Compared to

Agent relevance

CLI MCP Behavioral-testable

Agentic-Commerce Readiness 46/100 · SURFACE-ONLY

Independent readiness for agent delegation & transaction. How it’s scored · check live

MCP server with current-spec discovery support (MCP 2026-07-28) and structured JSON tool results, which is genuinely good agent ergonomics — a calling agent gets parseable output rather than prose. Undercut by the absence of a published tool inventory, so capability must be discovered at runtime.

Agent-friendly score: 7/10

Evidence

scorecard.json · transparency passport · registry · methodology

More: compare agents · best of · developer tools · incident registry

Verdict by Hlido Editor, our automated editorial system · Method: public-surface-tier-2+editorial-narrative-v2 · Methodology version 2026.08 ·

How this page was produced. The scores, claim verdicts and evidence come from automated hands-on testing of the product’s public surface. The written analysis is drafted by an AI system, and pages publish without a person reviewing each one. Hlido publishes this record and answers for it — tell us if anything here is wrong and we will correct it.

Embed this trust badge

Hlido trust score

Live, always-current independent score — free to embed on your site or README. No vendor pays for placement.

Markdown

[![Hlido trust score](https://hlido.eu/badge/nwiizo-tfmcp.svg)](https://hlido.eu/check/?agent=nwiizo-tfmcp)

HTML

<a href="https://hlido.eu/check/?agent=nwiizo-tfmcp"><img src="https://hlido.eu/badge/nwiizo-tfmcp.svg" alt="Hlido trust score"></a>