CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-architecture-audit

Audits AWS AI/GenAI architectures against the Well-Architected GenAI Lens — operational excellence, security, reliability, performance, cost optimization, and sustainability. This skill should be used when the user asks to 'audit AWS AI architecture', 'review Bedrock configuration', 'assess SageMaker security', 'optimize AWS AI costs', 'evaluate AWS GenAI compliance', 'review AWS Well-Architected for AI', or mentions AWS AI audit, Bedrock audit, SageMaker review, AWS GenAI security assessment, or AWS AI cost optimization review. [EXPLICIT]

SKILL.md
Quality
Evals
Security

AWS Architecture Audit for AI/GenAI Workloads

Generic, brand-neutral engineering capability; deep, sourced playbooks live in references/ and knowledge/. [DOC]

Generic, brand-neutral engineering capability; sourced playbooks in references//knowledge/. [DOC]

TL;DR

Auditar arquitecturas AWS para workloads de AI/GenAI contra el Well-Architected Framework GenAI Lens, evaluando los 6 pilares (GENOPS, GENSEC, GENREL, GENPERF, GENCOST, GENSUS) con checks automatizables, detección de waste, auditoría de seguridad AWS-específica, y compliance mapping por regulación [EXPLICIT]

When to Use

  • Auditar configuración de Bedrock (Guardrails, IAM, VPC endpoints, modelo seleccionado)
  • Revisar seguridad de SageMaker (IAM roles, VPC mode, encryption, endpoints)
  • Detectar cost waste en servicios AI de AWS (idle endpoints, wrong model tier, no batch)
  • Evaluar compliance de workloads AI contra HIPAA, PCI-DSS, SOX, GDPR en AWS
  • Pre-production readiness review para sistemas AI en AWS
  • Auditoría periódica de Well-Architected GenAI Lens (quarterly)
  • Post-incident review de sistemas AI en AWS

When NOT to Use

  • Auditoría de arquitectura AI cloud-agnostic → ai-architecture-audit
  • Diseñar nueva arquitectura AWS para AI → aws-architecture-design
  • Implementar remediaciones en AWS → aws-architecture-implementation
  • Auditoría de infraestructura AWS general (no AI) → infrastructure-architecture
  • Diseño de patrones AI genéricos → ai-design-patterns

Sub-capabilities (resource map)

Deep, evidence-tagged playbooks — open the one the task needs (ICM Layer 3, on-demand). [INFERENCE]

Reference
references/aws-audit-checks.md
references/aws-cost-audit.md
references/aws-security-audit.md
references/full-playbook.md

Procedure

  1. Resolve the sub-capability; open the matching references/ playbook. [EXPLICIT]
  2. Apply its decision tables; pick the strategy explicitly. [EXPLICIT]
  3. Validate against the Quality Criteria and tag every claim. [EXPLICIT]

Quality Criteria

  • Sub-capability resolved to one playbook. [INFERENCE]
  • Claims evidence-tagged. [EXPLICIT]

Contract

  • Aceptación: capability resolved to its reference playbook, applied, validated, evidence-tagged. [EXPLICIT]
  • Límites: 1. NO remedia — solo identifica y prioriza (ver aws-architecture-implementation) 2. NO ejecuta scripts de auditoría automatizados — define los checks conceptualmente 3. NO audi. [EXPLICIT]
  • Casos borde: 1. Cuenta multi-service (AI + non-AI): Focus en recursos taggeados como AI. Si no hay tags, el primer finding es "implementar tagging strategy para AI resources". [EXPLICIT]
  • Supuestos: 1. Acceso a la cuenta AWS con permisos de lectura sobre AI services (Bedrock, SageMaker, OpenSearch, IAM, CloudTrail) 2. CloudTrail habilitado (si no, es el primer finding CRITICAL. [SUPUESTO]
  • Trade-off: Audit Mode Checks Depth Effort When to Use ------------ -------- ------- -------- ------------- Express GENSEC + GENCOST only Config review 1-2 días Qui. [EXPLICIT]

Packet

Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · knowledge/ cuerpo de conocimiento · prompts/ prompts listos · examples/ salida de ejemplo · agents/ subagentes del packet · assets/ recursos estáticos.

Repository
JaviMontano/claude-plugins
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.