aws-cli
georgekhananaev/claude-skills-vault/.claude/skills/aws-cli/SKILL.md
Safety-first AWS CLI v2 skill for full control of AWS from the terminal — EC2, S3, IAM, Lambda, RDS, DynamoDB, CloudFormation, Route 53, EKS/ECS, logs, billing & 300+ services. Classifies every command by risk tier via a deterministic classifier script and gates destructive/breaking/cost-incurring ops behind AskUserQuestion confirmation. Account/region/profile preflight prevents wrong-account accidents. Use when running, planning, or debugging any `aws` command.
What's in it
- AWS CLI
- When to Use
- Prerequisites (run once per session)
- Safety Model
- Decision Flow
- Risk Classifier
- Forbidden Ops (never auto-confirm)
- AskUserQuestion Integration
- Wrong-Account/Region Guard
- Dry-Run & Preview
- Self-Healing
- Output & Querying
- Error Handling
- Shell Safety
- Integration
--- name: aws-cli description: Safety-first AWS CLI v2 skill for full control of AWS from the terminal — EC2, S3, IAM, Lambda, RDS, DynamoDB, CloudFormation, Route 53, EKS/ECS, logs, billing & 300+ services. Classifies every command by risk tier via a deterministic classifier script and gates destructive/breaking/cost-incurring ops behind AskUserQuestion confirmation. Account/region/profile preflight prevents wrong-account accidents. Use when running, planning, or debugging any `aws` command. author: George Khananaev --- # AWS CLI Safety-first wrapper for AWS CLI v2 (`aws`). Every command is classified by risk tier BEFORE execution — full AWS control, w/ anything irreversible, breaking, or cost-incurring gated behind explicit `AskUserQuestion` confirmation. Blast radius on AWS is an entire company's infra: wrong account/region/flag can destroy data, break prod, or spend real money. ## When to Use - Run/inspect any AWS service: EC2, S3, IAM, Lambda, RDS, DynamoDB, CloudFormation, Route 53, ECS/EKS, CloudFront, SQS/SNS, CloudWatch, KMS, Secrets Manager, … - Audit resources, costs, security posture; tail logs; query w/ `--query` (JMESPath) - Deploy/update infra, manage env config, rotate creds, debug failing calls - Set up auth: profiles, IAM Identity Center (SSO), assume-role, MFA ## Prerequisites (run once per session) ```bash bash scripts/aws_preflight.sh [profile] ``` Reports version, profiles, region, and the **active identity** (`sts get-caller-identity`). NEVER run a write op w/o knowing which account+region you're pointed at. No profiles configured → guide setup via [references/patterns.md](references/patterns.md) (keys vs SSO). ## Safety Model | Tier | Action Required | Examples | |------|----------------|----------| | **Safe** | Execute immediately | `describe-*`, `get-*`, `list-*`, `s3 ls`, `sts get-caller-identity`, `logs tail`, any `--dry-run` | | **Write** | Inform user, then execute | `create-*`, `put-*`, `tag-*`, `lambda update-function-code`, `s3 cp/sync` | | **Destructive** | `AskUserQuestion` BEFORE executing | `delete-*`, `terminate-instances`, `stop-*`, `run-instances` (cost), `modify-db-instance` (downtime), `change-resource-record-sets` (live DNS), sg rules w/ `0.0.0.0/0` | | **Forbidden** | Triple typed confirmation, NEVER auto-confirm | `close-account`, IAM user/role deletion, `kms schedule-key-deletion`, `delete-stack`, `s3 rb --force`, `delete-db-instance --skip-final-snapshot`, snapshot/backup deletion, disabling CloudTrail/GuardDuty, purchases (RIs, Savings Plans, domains) | Full classification + per-service rules: [references/safety-rules.md](references/safety-rules.md). ## Decision Flow ```text Command received → bash scripts/aws_preflight.sh (once per session — identity/region) → python3 scripts/aws_risk.py "<cmd>" (deterministic tier + reason) → Safe? Execute immediately → Write? State target account/region + what changes → execute → Destructive? AskUserQuestion (incl. account, region, resource, blast radius) → execute or cancel → Forbidden? Warn → typed confirmation → final confirm → execute or cancel On failure → Self-Healing (aws <svc> <op> help → docs URI) ``` The classifier is advisory — apply judgment on top (a "write" against prod during business hours may still deserve a question). When the user's request implies a **breaking change** (engine upgrade, version bump, policy change, capacity change, anything w/ downtime or no rollback), ALWAYS `AskUserQuestion` first even if the verb looks mild. ## Risk Classifier ```bash python3 scripts/aws_risk.py "aws ec2 terminate-instances --instance-ids i-0abc" # DESTRUCTIVE: Terminates instances — instance-store data is gone [ec2 terminate-instances] # exit codes: 0=safe 10=write 20=destructive 30=forbidden ``` Verb-pattern based (describe/get/list→safe, create/put/update→write, delete/terminate/stop→destructive) + ~80 explicit overrides for cost, breaking, security & account-level ops. Escalation-only: overrides never lower a tier (sole exception: a 3-entry audited list of read-only ops w/ scary verbs, e.g. `logs start-query`). Also catches: - **Compound commands**: splits on `&&`, `;`, `|`, `$()` — EVERY aws invocation classified, highest tier wins (quoted JMESPath pipes survive intact) - **Bulk loops**: `xargs`/`for`/`while` + destructive op → forbidden; + write op → destructive - **Public exposure**: `0.0.0.0/0`, `--acl public-read`, `"Principal": "*"`, weakening `put-public-access-block` - **Admin grants**: `AdministratorAccess`/`IAMFullAccess` ARNs, inline `"Action":"*"` + `"Resource":"*"` policies - **Hidden cost/impact**: `restore-*` into new billable stores, `--desired-count 0` (scale-to-zero), `s3 sync --delete` - Extracts `--profile`/`--region` into the output for the confirmation prompt ## Forbidden Ops (never auto-confirm) | Command | Why | |---------|-----| | `aws account close-account` / `organizations leave-organization` | Account-level — catastrophic | | `iam delete-user/role/group`, `deactivate-mfa-device` | Identity destruction, lockout risk | | `kms schedule-key-deletion` / `disable-key` | All data encrypted under the key → unrecoverable | | `cloudformation delete-stack` | Deletes EVERY resource the stack manages | | `s3 rb --force` / `s3api delete-bucket`, `dynamodb delete-table` | Bulk permanent data loss | | `rds delete-db-instance --skip-final-snapshot` | DB gone w/ NO backup | | `ec2 delete-snapshot`, `rds delete-db-snapshot`, `backup delete-*` | Deletes the backups themselves | | `cloudtrail delete-trail/stop-logging`, `guardduty delete-detector` | Removes audit/security monitoring | | RI/Savings-Plan purchases, `route53domains register-domain` | Spends real money, multi-year commitments | | Bulk destructive loops (`xargs … delete`) | Multiplies blast radius | ## AskUserQuestion Integration For **Destructive** ops, always show account, region & resource; include a "Cancel" option: ```text Q: "Terminate i-0abc123 (prod-api, account 1234…, eu-west-1)?" - "Terminate it" — aws ec2 terminate-instances --instance-ids i-0abc123 - "Stop instead (reversible)" — aws ec2 stop-instances --instance-ids i-0abc123 - "Cancel" Q: "Upgrade RDS prod-db to engine 16.4? Causes downtime; downgrade NOT possible." - "Upgrade now" / "Upgrade in maintenance window (--no-apply-immediately)" / "Cancel" ``` Also ask (not just for deletes) when: choosing between profiles/accounts, picking a region for new resources, anything creating ongoing cost, IAM policy changes, version upgrades, or ambiguous resource matches (multiple instances match a name). Forbidden ops → triple-confirmation protocol in [references/safety-rules.md](references/safety-rules.md). ## Wrong-Account/Region Guard #1 real-world AWS accident. Before EVERY Write+ op: 1. `aws sts get-caller-identity` (or trust session preflight) — confirm account 2. Confirm region: explicit `--region` beats env beats profile default. New resources default to the profile region — state it 3. Multi-profile setups: prefer explicit `--profile X --region Y` on mutating commands over ambient env ## Dry-Run & Preview Prefer previews before mutating: EC2/VPC support `--dry-run` (returns `DryRunOperation` on success); CloudFormation → `deploy --no-execute-changeset` / `create-change-set` then review; IAM → `simulate-principal-policy`; S3 sync/rm → `--dryrun`; any command → `--generate-cli-skeleton` to inspect shape w/o executing. ## Self-Healing CLI surface is huge & evolves; on any error: read the message → `aws <service> <op> help` (offline, authoritative for the installed version) → if still unclear, WebFetch the v2 reference: - Per-command: `https://awscli.amazonaws.com/v2/documentation/api/latest/reference/<service>/<operation>.html` - Index: https://awscli.amazonaws.com/v2/documentation/api/latest/reference/index.html - Userguide: https://docs.aws.amazon.com/cli/latest/userguide/ - Service errors (`AccessDenied`, throttling, etc.): see [references/patterns.md](references/patterns.md) Service/command map + doc URIs: [references/services.md](references/services.md). ## Output & Querying | Need | Flag | |------|------| | Machine-readable | `--output json` (pipe to `jq` or use `--query`) | | Human table | `--output table` | | Filter server-side | `--filters Name=…,Values=…` (cheaper than client-side) | | Filter client-side | `--query '<JMESPath>'` e.g. `'Reservations[].Instances[].InstanceId'` | | No pager | `--no-cli-pager` (ALWAYS append for non-interactive runs) | | Big lists | auto-paginated; tune w/ `--max-items`, `--page-size` | JMESPath cookbook + pagination details: [references/patterns.md](references/patterns.md). ## Error Handling | Error | Cause | Fix | |-------|-------|-----| | `Unable to locate credentials` | No profile/env creds | `aws configure` / `aws configure sso`, or `export AWS_PROFILE=x` | | `Token has expired` / `ExpiredToken` | SSO/STS session ended | `aws sso login --profile x` | | `AccessDenied` / `UnauthorizedOperation` | Missing IAM permission | Decode w/ `sts decode-authorization-message` if encoded; check policy | | `InvalidClientTokenId` | Deactivated/wrong keys | Rotate keys in IAM | | `Could not connect to the endpoint URL` | Wrong/missing region | Set `--region`; verify service exists in that region | | `ThrottlingException` / `Rate exceeded` | API rate limits | Retry w/ backoff; CLI retries automatically (`AWS_MAX_ATTEMPTS`) | | `ValidationError`/`InvalidParameterValue` | Bad arg shape | `aws <svc> <op> help`; `--generate-cli-skeleton` for the schema | ## Shell Safety - ALWAYS `--no-cli-pager` (or pipe `| cat`) — aws v2 invokes a pager by default - Quote JSON args in single quotes; for complex JSON prefer `file://params.json` - NEVER echo secrets: `secretsmanager get-secret-value`, `ssm get-parameter --with-decryption` → redirect to file/var, never display unless asked - NEVER put access keys on the command line; use profiles/env - No `--force`-style skip flags on Destructive/Forbidden tiers w/o the confirmation flow - Bulk ops: print the resource list FIRST, confirm once w/ exact count, only then loop ## Integration Pairs w/: **terraform** (IaC instead of imperative changes — prefer for repeatable infra), **github-cli** (CI/CD wiring), **mongodb-atlas-cli** / **supabase-cli** (other data planes), **owasp-security** / **trailofbits-security** (security audits of what the CLI finds), **file-converter** (transform exported JSON/CSV).
More agent context in georgekhananaev/claude-skills-vault
63 other files this repository gives its agents, the first 60 shown.
AGENTS.md
Skill
- agy-cli.claude/skills/agy-cli/SKILL.md
- better-auth.claude/skills/better-auth/SKILL.md
- brainstorm.claude/skills/brainstorm/SKILL.md
- claude-seo.claude/skills/claude-seo/SKILL.md
- code-quality.claude/skills/code-quality/SKILL.md
- codex-cli.claude/skills/codex-cli/SKILL.md
- color-accessibility-audit.claude/skills/color-accessibility-audit/SKILL.md
- vercel-composition-patterns.claude/skills/composition-patterns/SKILL.md
- data-wrangler.claude/skills/data-wrangler/SKILL.md
- doc-navigator.claude/skills/doc-navigator/SKILL.md
- domain-checker.claude/skills/domain-checker/SKILL.md
- fastapi-senior-dev.claude/skills/fastapi-senior-dev/SKILL.md
- file-converter.claude/skills/file-converter/SKILL.md
- firebase-cli.claude/skills/firebase-cli/SKILL.md
- firecrawl.claude/skills/firecrawl-cli/SKILL.md
- frontend-design.claude/skills/frontend-design/SKILL.md
- gemini-cli.claude/skills/gemini-cli/SKILL.md
- github-cli.claude/skills/github-cli/SKILL.md
- materialreacttable-mastery.claude/skills/materialreacttable-mastery/SKILL.md
- mcp-builder.claude/skills/mcp-builder/SKILL.md
- mermaid-diagram.claude/skills/mermaid-diagram/SKILL.md
- monday-com.claude/skills/monday-com/SKILL.md
- mongodb-atlas-cli.claude/skills/mongodb-atlas-cli/SKILL.md
- multi-agent-patterns.claude/skills/multi-agent-patterns/SKILL.md
- n8n-cli.claude/skills/n8n-cli/SKILL.md
- natural-language.claude/skills/natural-language/SKILL.md
- neon-postgres-agent-platforms.claude/skills/neon-postgres-agent-platforms/SKILL.md
- next-cache-components.claude/skills/next-cache-components/SKILL.md
- nextjs-senior-dev.claude/skills/nextjs-senior-dev/SKILL.md
- next-upgrade.claude/skills/next-upgrade/SKILL.md
- notebooklm.claude/skills/notebooklm-skill/SKILL.md
- obsidian-skills.claude/skills/obsidian-skills/SKILL.md
- owasp-security.claude/skills/owasp-security/SKILL.md
- parallel-agents.claude/skills/parallel-agents/SKILL.md
- planning-with-files.claude/skills/planning-with-files/SKILL.md
- plan-to-tdd.claude/skills/plan-to-tdd/SKILL.md
- project-change-log.claude/skills/project-change-log/SKILL.md
- pydantic-model.claude/skills/pydantic-model/SKILL.md
- react-best-practices.claude/skills/react-best-practices/SKILL.md
- salesforce-cli.claude/skills/salesforce-cli/SKILL.md
- semantic-coding.claude/skills/semantic-coding/SKILL.md
- senior-backend.claude/skills/senior-backend/SKILL.md
- skill-creator.claude/skills/skill-creator/SKILL.md
- stripe-best-practices.claude/skills/stripe-best-practices/SKILL.md
- supabase-cli.claude/skills/supabase-cli/SKILL.md
- swift-concurrency-6-2.claude/skills/swift-concurrency6.2/SKILL.md
- swiftui-patterns.claude/skills/swiftui-patterns/SKILL.md
- system-architect.claude/skills/system-architect/SKILL.md
- terraform.claude/skills/terraform/SKILL.md
- testing-automation-expert.claude/skills/testing-automation-expert/SKILL.md
- test-levels.claude/skills/test-levels/SKILL.md
- token-optimizer.claude/skills/token-optimizer/SKILL.md
- trailofbits-security.claude/skills/trailofbits-security/SKILL.md
- ui-ux-pro-max.claude/skills/ui-ux-pro-max/SKILL.md
- uiux-toolkit.claude/skills/uiux-toolkit/SKILL.md
- upgrade-packages-js.claude/skills/upgrade-packages-js/SKILL.md
- vercel-cli.claude/skills/vercel-cli/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

