
aws-samples/sample-agent-skills-for-builders
Developer toolsA curated collection of ready-to-use agent skills covering AWS development, security scanning, testing, and AI coding workflows.
Обзор
A curated, open collection of agent skills that extend AI coding agents (Claude Code, Cursor, Copilot, …) with production-ready AWS, CDK, and engineering workflows. Skills are self-contained capability packs. An agent loads only the skill name and one-line description at startup and pulls the full instructions, references, and scripts on demand — so you can ship dozens of capabilities without eating the context window. This repository is both a ready-to-use library and a reference implementation: - — install any skill with a single npx command. - — copy the format when authoring your own. Skills are installed with skills.sh via npx. Once this repository is registered on skills.sh, you will also be able to browse it at skills.sh/aws-samples/sample-agent-skills-for-builders. The full spec lives in AGENTS.md. The 60-second version: - for directory names, matching the name field in frontmatter.
README
Sample Agent Skills for Builders
A curated, open collection of agent skills that extend AI coding agents (Claude Code, Cursor, Copilot, …) with production-ready AWS, CDK, and engineering workflows.
Skills are self-contained capability packs. An agent loads only the skill name and one-line description at startup and pulls the full instructions, references, and scripts on demand — so you can ship dozens of capabilities without eating the context window.
This repository is both a ready-to-use library and a reference implementation:
- Library — install any skill with a single
npxcommand. - Reference — copy the format when authoring your own.
Contents
Install
Skills are installed with skills.sh via npx.
# install every skill in this repo
npx skills add https://github.com/aws-samples/sample-agent-skills-for-builders
# or install just one
npx skills add https://github.com/aws-samples/sample-agent-skills-for-builders --skill security-scan
Once this repository is registered on skills.sh, you will also be able to browse it at skills.sh/aws-samples/sample-agent-skills-for-builders.
Available Skills
AWS foundation
| Skill | What it does |
|---|---|
| aws-mcp-setup | Configure the AWS MCP servers (full server + documentation-only) so agents can query AWS docs and invoke AWS APIs. Prerequisite for the other aws-* skills. |
CDK development
| Skill | What it does |
|---|---|
| aws-cdk-development | CDK expert for TypeScript/Python — app structure, construct patterns, stack composition, and deployment workflows, with MCP-assisted validation. |
| create-install-scripts | Generate interactive install.sh, GitLab CI pipelines, and CodeBuild setup for CDK projects. |
| cost-estimator | Estimate CDK infrastructure cost before deploy using real-time AWS Price List data. Produces Markdown and Excel reports. |
| security-scan | Aggregated SAST / IaC / secrets / license / container scanning for CDK projects via the Automated Security Helper (ASH). |
| api-gateway-authorizer-security | Prioritize Cognito/OIDC JWT and other business authorizers, using an always-allow Lambda authorizer only as a documented fallback for public routes. |
AWS operations & AI
| Skill | What it does |
|---|---|
| aws-cost-operations | Analyze AWS bills, set CloudWatch alarms, query logs, audit CloudTrail, and tighten operational excellence. |
| aws-agentic-ai | Deploy and manage agents on Bedrock AgentCore — Gateway, Runtime, Memory, Identity, Code Interpreter, Browser, Observability, Registry, and Evaluations. |
| agentcore-mcp-oauth-facade | Build an OAuth + MCP protocol facade in front of AgentCore Gateway/Runtime so strict MCP clients connect: OAuth discovery over Cognito, fake DCR, dual session-ids, tools/list pagination aggregation, tool-name prefixes, Gateway schema limits. |
| agentcore-browser-web-scraping | Production web scraping on AgentCore Browser — Playwright over signed CDP, LLM-driven extraction with fixed tool primitives, login state via Browser Profiles + DCV live-view, login-wall detection, external proxy egress. |
| agentic-responsible-ai-assessment | Run a Responsible AI assessment for agentic systems — 20 questions across three maturity phases, scored 0–5 over eight RAI dimensions (Governance, Privacy & Security, Safety, Veracity & Robustness, Controllability, Fairness, Explainability, Transparency), with a live posture chart (Highcharts / Mermaid / ASCII per client). |
Engineering workflows
| Skill | What it does |
|---|---|
| end-to-end-testing | Systematic E2E testing workflow with evidence capture (screenshots, logs) and report generation. |
| gitlab-docs-publishing | Publish styled HTML design docs on GitLab Pages and inject per-section discuss buttons that open pre-filled Issues. |
| quip-to-gitlab-wiki | Migrate Quip documents to GitLab Wiki with full text and media preservation. |
| strands-context-manager | Sliding-window + summarization pattern for managing long conversations in Strands Agents. |
Author a Skill
The full spec lives in AGENTS.md. The 60-second version:
mkdir -p skills/my-skill
---
name: my-skill
description: One sentence describing when to activate. Include the exact trigger phrases a user might say.
---
# My Skill
## When to Apply
- …
## How It Works
1. …
## Usage
…
Optional supporting files:
skills/my-skill/
SKILL.md # required
metadata.json # optional: version, author, tags
references/ # optional: long-form docs, loaded on demand
scripts/ # optional: automation invoked by the agent
Rules of thumb:
- Use kebab-case for directory names, matching the
namefield in frontmatter. - Keep
SKILL.mdunder ~500 lines — push long content intoreferences/so it only loads when the agent decides to use it. - Write the
descriptionas trigger phrases — it is the only text an agent sees at startup when deciding whether to pull the skill.
Contributing
Issues and pull requests are welcome. See CONTRIBUTING.md for the PR workflow and AGENTS.md for the skill spec.
To report a security issue, please use the AWS vulnerability reporting page rather than opening a public issue.
This project adopts the Amazon Open Source Code of Conduct; see CODE_OF_CONDUCT.md.
License
Apache-2.0. See LICENSE.
Рекомендуемые инструменты
Попробуйте другой запрос или уберите фильтр.
Установка
npx skillfish add aws-samples/sample-agent-skills-for-builders