github.com/aws/agent-toolkit-for-aws
| Skill | Added | Review |
|---|---|---|
aws-secrets-manager plugins/aws-core/skills/aws-secrets-manager/SKILL.md Secret safety for AWS Secrets Manager, secret management, credentials, API keys, tokens, and passwords. Prevents AI agents from directly fetching secret values and teaches runtime dynamic references with asm-exec so plaintext never enters the LLM context window. | 56 56 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
aws-security plugins/aws-core/skills/aws-security/SKILL.md Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
aws-serverless plugins/aws-core/skills/aws-serverless/SKILL.md Builds, deploys, manages, debugs, configures, and optimizes serverless applications on AWS using Lambda, API Gateway, Step Functions, EventBridge, and SAM/CDK. Covers cold starts, CORS debugging, event source mappings, troubleshooting, concurrency, SnapStart, Powertools, function URLs, EventBridge Scheduler, Lambda layers, and production readiness. Triggers on mentions of Lambda, API Gateway, Step Functions, SAM templates, CDK serverless stacks, DynamoDB stream triggers, SQS event sources, cold starts, timeouts, 502/504 errors, throttling, concurrency, CORS, Powertools, or any event-driven architecture on AWS, even without the word "serverless." Does not apply to EC2, ECS/Fargate containers, or Amplify hosting. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
aws-storage plugins/aws-core/skills/aws-storage/SKILL.md Selects, investigates, and compares AWS object, file, and block storage services, and answers cost, performance, configuration, security, and troubleshooting questions about storage services. Applies when a user asks where to store or archive data based on their usage patterns; which storage service to choose or how two compare; how to migrate data from on-premises or between AWS services; how to protect, replicate, or recover data; how to optimize storage costs; where to deploy shared NFS, SMB, or POSIX file systems; where to store vector embeddings or tabular data; what storage backs enterprise file shares, self-managed databases on EC2, VMware, or stateful containers; or asks what an AWS storage service can do or how it works. Relevant for storage needs for workloads such as AI/ML, analytics, EDA, HPC, media, genomics, or financial trading. Not applicable for SQL query engines (Athena, Spark, Redshift, EMR), ETL (Glue), streaming (Kafka, MSK, Kinesis), or managed database services (RDS, Aurora, DynamoDB). | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
aws-transform skills/specialized-skills/migration-and-modernization-skills/aws-transform/SKILL.md Performs code upgrades, migrations, and transformations using the AWS Transform (ATX) CLI. Use when upgrading language versions, migrating AWS SDKs, migrating frameworks (Angular, Vue.js, Spring Boot, React), upgrading libraries, optimizing performance, migrating x86 to Graviton, analyzing codebases / generating documentation, or defining custom transformations with natural language. Runs locally on a few repositories or at scale across hundreds via AWS Batch/Fargate. | 68 68 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: b8171ad | |
aws-well-architected-review plugins/aws-core/skills/aws-well-architected-review/SKILL.md Performs a full AWS Well-Architected Framework review evaluating every framework question across all pillars discovered from the live AWS documentation by analyzing code, IaC, and configurations to produce evidence-backed findings with Eisenhower-prioritized remediation. Supports full reviews (every framework best practice with BP ID citations), quick reviews (question-level), pillar-scoped reviews, score-mode reviews (a maturity scorecard with per-pillar scores and filtered findings), and lens-specific reviews using lenses discovered from the live AWS documentation. Triggers on mentions of Well-Architected review, WA review, WAR, pillar assessment, architecture review across pillars, workload assessment, cloud readiness evaluation, or a Well-Architected score, grade, or scorecard request. Does not apply to single-pillar deep-dives, learning WA concepts, ADRs, or migration readiness assessments. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
chatting-with-aws-devops-agent plugins/aws-agents-for-devsecops/skills/chatting-with-aws-devops-agent/SKILL.md Have a fast, conversational analysis with the AWS DevOps Agent. Use for cost optimization, architecture review, topology mapping, knowledge / runbook discovery, security audits, dependency questions, and quick diagnostics — anything that needs a 5-30 second answer rather than a 5-8 minute deep investigation. Trigger words include cost, optimize, review, architecture, topology, what runbooks, show me, compare, audit, what if. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
cloudfront skills/specialized-skills/networking-and-content-delivery-skills/cloudfront/SKILL.md Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a distribution, caching, and Flat Rate Pricing (FRP) versus pay-as-you-go pricing); managing custom-domain TLS certificates (ACM in us-east-1); configuring multi-tenant distributions; protecting origins with origin access control (OAC), VPC origins, and origin mutual TLS (mTLS); securing content with signed URLs and cookies, geographic restrictions, viewer mutual TLS, and edge token validation; and observing traffic with standard and real-time logs. Applicable when the customer wants to put CloudFront in front of content, choose pricing, lock an origin, restrict who can view content, or analyze logs. Not applicable for the Route 53 DNS side of a CloudFront custom domain or failover between distributions (see the route53-cloudfront skill), or for pure-Route 53 DNS work (see the route53 skill). | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
configuring-vpc-endpoints-for-private-aws-service-access skills/specialized-skills/networking-and-content-delivery-skills/configuring-vpc-endpoints-for-private-aws-service-access/SKILL.md Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink. Use when setting up secure private connectivity to S3, DynamoDB, and other AWS services without internet gateway, NAT device, or public IP addresses. Covers endpoint creation, security groups, route tables, and DNS configuration. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
connecting-lambda-to-api-gateway skills/specialized-skills/serverless-skills/connecting-lambda-to-api-gateway/SKILL.md Connects an existing AWS Lambda function to Amazon API Gateway by creating a REST or HTTP API with resource/method setup, Lambda proxy integration, permissions, and deployment. Always use this skill when connecting Lambda to API Gateway — it handles CORS, throttling, access logging, and production security hardening that are easy to miss. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
connecting-lambda-to-dynamodb skills/specialized-skills/serverless-skills/connecting-lambda-to-dynamodb/SKILL.md Connects an AWS Lambda function to DynamoDB with IAM roles, stream event source mapping, and read/write permissions. Use when setting up Lambda-DynamoDB integration, processing DynamoDB stream events, or deploying serverless event-driven architectures. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
connecting-to-data-source plugins/aws-data-analytics/skills/connecting-to-data-source/SKILL.md Create and troubleshoot AWS Glue connections to JDBC databases (Oracle, SQL Server, PostgreSQL, MySQL, RDS), Redshift, Snowflake, and BigQuery. Gathers connection hints from user, discovers existing connections and RDS/Redshift candidates, registers credentials in Secrets Manager or IAM DB auth, configures VPC, and tests. Triggers on: connect to database, set up Glue connection, register data source, connect to Snowflake/BigQuery/RDS, connection timeout, test connection, troubleshoot connection. Do NOT use for moving data (use ingesting-into-data-lake), creating tables (use creating-data-lake-table), queries (use querying-data-lake), catalog exploration (use exploring-data-catalog), or SaaS (Salesforce, ServiceNow, SAP, MongoDB, Kafka). | 77 77 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: b8171ad | |
connecting-vpcs-with-peering skills/specialized-skills/networking-and-content-delivery-skills/connecting-vpcs-with-peering/SKILL.md Establishes VPC peering connections between two VPCs for direct private network connectivity. Always use this skill when creating or managing VPC peering — it validates CIDR overlap, updates all route tables in both VPCs, configures DNS resolution, and provides security group guidance that are critical for correct connectivity. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
coordinating-multi-space-devops-agent plugins/aws-agents-for-devsecops/skills/coordinating-multi-space-devops-agent/SKILL.md Coordinate the AWS DevOps Agent across multiple AgentSpaces from one Claude Code session — route questions to the right space (prod vs staging vs knowledge), query several spaces in parallel and synthesize, or compare findings across accounts. Use whenever the user has more than one AgentSpace configured, mentions multiple AWS accounts, or asks something like "check both prod and staging", "compare across accounts", or "ask the knowledge space". | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
creating-amazon-aurora-db-cluster-with-instances skills/specialized-skills/database-skills/creating-amazon-aurora-db-cluster-with-instances/SKILL.md Creates a complete Amazon Aurora database cluster with instances, handling cluster creation, instance provisioning, and Secrets Manager password management in the proper sequence. Use when setting up new Aurora MySQL or PostgreSQL clusters with production-ready configuration. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
creating-api-gateway-stage skills/specialized-skills/serverless-skills/creating-api-gateway-stage/SKILL.md Creates an API Gateway stage with CloudWatch logging, X-Ray tracing, throttling, WAF integration, and IAM roles following AWS best practices. Use when deploying a REST API to different environments such as dev, test, or production. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
creating-data-lake-table plugins/aws-data-analytics/skills/creating-data-lake-table/SKILL.md Create managed Iceberg tables using Amazon S3 Tables (s3tables API namespace) with automatic compaction and snapshot management. Sets up table bucket, namespace, table, schema, Glue catalog registration, partitioning, IAM access control. Triggers on: create table, data lake table, analytics table, structured data storage, S3 Tables, Iceberg, Athena table, partitioning strategy, access permissions. Do NOT use for: importing files (use ingesting-into-data-lake), vector storage (use storing-and-querying-vectors), querying existing tables (use querying-data-lake), or locating existing table (use finding-data-lake-assets). | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
creating-production-vpc-multi-az skills/specialized-skills/networking-and-content-delivery-skills/creating-production-vpc-multi-az/SKILL.md Creates a production-ready VPC with public and private subnets across multiple Availability Zones, including internet gateway, NAT gateways, route tables, and security groups following AWS Well-Architected principles. Use when deploying multi-AZ VPC infrastructure with automatic CIDR planning and DNS resolution. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
creating-secrets-using-best-practices skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices/SKILL.md Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad | |
debugging-lambda-timeouts skills/specialized-skills/serverless-skills/debugging-lambda-timeouts/SKILL.md Debugs AWS Lambda function timeout failures by systematically analyzing function configuration, CloudWatch logs and metrics, VPC/networking, cold starts, memory constraints, and downstream dependencies to identify root causes with actionable fixes. Use when a Lambda function is timing out or approaching its timeout limit. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b8171ad |