Skills from aws/agent-toolkit-for-aws: 127 agent skills
agents-build — Use to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments.
agents-connect — Use when connecting your agent to external APIs, tools, or services via Gateway, or restricting tool access with Cedar policies.
agents-debug — Use when your agent or environment is broken — wrong answers, errors, timeouts, tool failures, or CLI issues. Reads traces and logs to diagnose root causes.
agents-deploy — Use when deploying your agent to AWS, or when a deploy has failed.
agents-get-started — Use when a developer wants to create a new agent project or get started with AgentCore.
agents-harden — Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle.
agents-optimize — Use when measuring or improving agent quality and performance — set up evaluators, online monitoring, CI/CD quality gates, observability, or cost optimization.
agents-pay — Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments.
amazon-aurora-mysql — Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query).
amazon-aurora-postgresql — Amazon Aurora PostgreSQL — creates, modifies, and advises on Aurora PostgreSQL clusters specifically (PostgreSQL-compatible engine, Aurora serverless.
amazon-bedrock — Builds generative AI applications on Amazon Bedrock.
amazon-braket — Runs quantum computing workflows on AWS through Amazon Braket — discovering devices (QPUs and simulators) and their availability.
amazon-dynamodb — Designs, reviews, and debugs DynamoDB data layers from design axioms — enumerates access patterns, chooses partition/sort keys and GSIs.
amazon-ec2-image-builder — Creates and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and container images to ECR.
amazon-elasticache — Activate when developers have latent caching needs: slow API responses, database read bottlenecks, DynamoDB throttling or cost, RDS/Aurora scaling pressure.
amazon-ses — Guides Amazon SES onboarding for domain-based email sending.
amazon-workspaces-agent-access — 0) through the managed Agent Access MCP server, and guides reliable desktop automation.
analyzing-release-readiness — Trigger a pre-merge release readiness review on a GitHub PR, GitLab MR, or local branch.
arc-region-switch — Answers questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans, execution blocks, workflows, triggers.
aurora-dsql — Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans.
aws-ai-ml — Selects, deploys, and customizes AI models on Amazon SageMaker.
aws-amplify — Build and deploy full-stack web and mobile apps with AWS Amplify Gen2 (TypeScript code-first).
aws-auth — Adds user authentication to web and mobile apps with Amazon Cognito (user pools and identity pools) and the AWS Amplify client auth libraries.
aws-billing-and-cost-management — Analyze AWS costs, find savings, manage budgets, evaluate Savings Plans and Reserved Instances, right-size EC2/Lambda/RDS/EBS with Compute Optimizer.
aws-blocks — Guides building full-stack applications with AWS Blocks — an Infrastructure-from-Code framework.
aws-cdk — Authors, deploys, and troubleshoots AWS infrastructure using CDK with TypeScript or Python. Covers best practices, stack architecture, and construct patterns.
aws-cleanrooms — Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions.
aws-cloudformation — Authors, validates, and troubleshoots AWS CloudFormation templates.
aws-compute — Provisions, scales, and operates Amazon EC2 virtual-machine workloads: instance-type selection (Graviton/Arm64, burstable T credits, GPU.
aws-containers — Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry).
aws-database — Routes any task involving AWS databases — choosing, comparing, recommending, getting started with.
aws-deployment — Configures CI/CD pipelines using AWS CodePipeline, CodeBuild, CodeDeploy, CodeConnections, and CodeArtifact.
aws-iam — Provides verified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits.
aws-lambda-durable-functions — Builds resilient, long-running, multi-step applications with AWS Lambda durable functions with automatic state persistence, retry logic.
aws-lambda-managed-instances — Evaluates, configures, and migrates workloads to AWS Lambda Managed Instances (LMI).
aws-lambda-microvms — Builds, runs, debugs, and operates applications on AWS Lambda MicroVMs — Firecracker-isolated.
aws-sdk-python-usage — AWS SDK for Python (boto3/botocore) development patterns. You MUST use this skill when writing Python code that uses AWS services via boto3 or botocore.
aws-sdk-swift-usage — AWS SDK for Swift development patterns. Use when writing Swift code that uses AWS services via aws-sdk-swift package.
aws-secrets-manager — Secret safety for AWS Secrets Manager, secret management, credentials, API keys, tokens, and passwords.
aws-serverless — Builds, deploys, manages, debugs, configures, and optimizes serverless applications on AWS using Lambda, API Gateway, Step Functions, EventBridge, and SAM/CDK.
aws-sms-voice — Onboards RCS Business Messaging and Notify OTP via the pinpoint-sms-voice-v2 AWS CLI.
aws-social-messaging — Manages WhatsApp messaging through AWS End User Messaging Social.
aws-step-functions — Authors and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses and structures state types (Task, Choice, Map.
aws-storage — Selects, investigates, and compares AWS object, file, and block storage services, and answers cost, performance, configuration, security.
aws-transform — Performs code upgrades, migrations, and transformations using the AWS Transform (ATX) CLI.
cloudfront — Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions.
connecting-lambda-to-api-gateway — Connects an existing AWS Lambda function to Amazon API Gateway by creating a REST or HTTP API with resource/method setup, Lambda proxy integration.
connecting-lambda-to-dynamodb — Connects an AWS Lambda function to DynamoDB with IAM roles, stream event source mapping, and read/write permissions.
connecting-to-data-source — Create and troubleshoot AWS Glue connections to JDBC databases (Oracle, SQL Server, PostgreSQL, MySQL, RDS), Redshift, Snowflake, and BigQuery.
connecting-vpcs-with-peering — Establishes VPC peering connections between two VPCs for direct private network connectivity.
coordinating-multi-space-devops-agent — Coordinate the AWS DevOps Agent across multiple AgentSpaces from one Claude Code session — route questions to the right space (prod vs staging vs knowledge).
creating-api-gateway-stage — Creates an API Gateway stage with CloudWatch logging, X-Ray tracing, throttling, WAF integration, and IAM roles following AWS best practices.
creating-data-lake-table — Create managed Iceberg tables using Amazon S3 Tables (s3tables API namespace) with automatic compaction and snapshot management.
creating-production-vpc-multi-az — Creates a production-ready VPC with public and private subnets across multiple Availability Zones, including internet gateway, NAT gateways, route tables.
debugging-lambda-timeouts — Debugs AWS Lambda function timeout failures by systematically analyzing function configuration, CloudWatch logs and metrics, VPC/networking, cold starts.
deploying-custom-domain-rest-api — Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI.
directconnect — Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private.
dms-schema-conversion — Handles the full DMS Schema Conversion lifecycle including creating migration projects, converting database schemas to a target engine.
enabling-lambda-vpc-internet-access — Enables internet access for AWS Lambda functions deployed in VPC subnets by creating NAT Gateway infrastructure, configuring public/private subnet routing.
exploring-data-catalog — Full inventory and audit of AWS Glue Data Catalog assets across S3 Tables, Redshift-federated, and remote Iceberg catalogs.
exporting-rds-to-s3 — Exports Amazon RDS or Aurora database snapshots to Amazon S3 in Apache Parquet format for analytics, backup, or data migration.
finding-data-lake-assets — Resolve data lake and lakehouse asset references across Glue Data Catalog, S3, S3 Tables, and Redshift.
ingesting-into-data-lake — Import data into the AWS data lake from S3 files, local uploads, JDBC databases (Oracle, SQL Server, PostgreSQL, MySQL, RDS, Aurora), Amazon Redshift.
launch-with-aws — Migrates vibe-coded web applications to AWS.
launching-ec2-instance-with-best-practices — Launches an EC2 instance with secure, cost-efficient defaults including AMI selection, burstable instance sizing, least-privilege IAM roles.
migrating-to-amazon-redshift — Guides an end-to-end data-warehouse migration to Amazon Redshift — discovery, schema/SQL/stored-procedure/macro/script conversion, data migration, validation.
pentesting-with-aws-security-agent — Run an AWS Security Agent penetration test against a live web application — registers and verifies the target domain.
processing-s3-uploads-with-step-functions — Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.
querying-aws-cloudwatch — Runs SQL queries on CloudWatch Logs data exported as Apache Iceberg tables in S3 Tables.
querying-aws-redshift — Enables Redshift system-table (SYS_*) log publishing to S3 Tables in Apache Iceberg format for both Provisioned clusters and Serverless namespaces.