All skills
aws avatar

/agents-build

@f986ec6

Use to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal. Triggers: "add memory", "remember across sessions", "call agent from app", "invoke agent from code", "agent auth", "streaming", "VPC", "VPC connectivity", "can't reach from VPC", "multi-agent", "A2A", "A2A auth", "orchestrator not delegating", "specialist not called", "migrate Bedrock Agent", "migration issue", "change model", "browser tool", "code interpreter", "delete agent", "tear down", "agentcore remove", "cross-account memory", "add payments capability to my agent", "wire payments plugin", "integrate x402 payments with the agent I'm building", "add MPP payments", "Machine Payments Protocol". External APIs via Gateway: use agents-connect. New project: use agents-get-started. CLI/dev-server errors: use agents-debug. Runtime x402/MPP payments: use agents-pay. Migration-specific Strands vs LangGraph routes here.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/agents-build

This session only. Nothing lands on disk.

referencesteardown.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

teardown

Remove individual resources from your project or tear down the entire deployment.

When to use

  • You want to remove a gateway, memory, credential, evaluator, or other resource from your project
  • You want to delete a deployed agent and clean up all AWS resources
  • You're iterating in a sandbox account and want to start fresh
  • You need to remove a resource that's stuck or no longer needed

Process

Removing individual resources from your project

Use agentcore remove to remove a resource from agentcore.json. This marks the resource for deletion — the actual AWS resource is removed on the next agentcore deploy.

# Remove a memory resource
agentcore remove memory --name MyMemory

# Remove a gateway target
agentcore remove gateway-target --name WeatherTools --gateway MyGateway

# Remove a gateway (remove all its targets first)
agentcore remove gateway --name MyGateway

# Remove a credential
agentcore remove credential --name MyAPIKey

# Remove an evaluator
agentcore remove evaluator --name ResponseQuality

# Remove an online eval config
agentcore remove online-eval --name production_monitor

# Remove a policy
agentcore remove policy --name SpendingLimit --engine MyPolicyEngine

# Remove a policy engine (remove all its policies first)
agentcore remove policy-engine --name MyPolicyEngine

After removing, deploy to apply the changes:

agentcore deploy -y

Check what's pending removal before deploying:

agentcore status --state pending-removal

Removing an agent from a multi-agent project

If your project has multiple agents (runtimes), you can remove one:

agentcore remove agent --name SecondAgent
agentcore deploy -y

This deletes the agent's runtime, endpoint, and associated resources from AWS. The agent's code in app/<AgentName>/ is not deleted — remove it manually if you no longer need it.

Tearing down the entire deployment

To remove all deployed AWS resources for a project:

# Preview what will be destroyed
agentcore deploy --diff

# Destroy all resources
npx cdk destroy --app "npx ts-node agentcore/cdk/bin/cdk.ts" --force

Alternatively, delete the CloudFormation stack directly:

# Find the stack name
aws cloudformation list-stacks \
  --stack-status-filter CREATE_COMPLETE UPDATE_COMPLETE \
  --query "StackSummaries[?contains(StackName, '<ProjectName>')].StackName"

# Delete it
aws cloudformation delete-stack --stack-name <StackName>

# Wait for deletion to complete
aws cloudformation wait stack-delete-complete --stack-name <StackName>

What gets deleted and what doesn't

Resource Deleted by cdk destroy Notes
AgentCore Runtime(s) ✅ Includes all endpoints and versions
Memory resource(s) ✅ Memory data is deleted permanently
Gateway(s) and targets ✅
Credentials ✅ Secrets Manager entries are removed
Policy engine(s) and policies ✅
Evaluator definitions ✅
Online eval configs ✅
IAM roles ✅ Created by CDK
CloudWatch log groups ❌ Persist after deletion — delete manually if needed
ECR images (Container builds) ❌ Persist — delete the repository manually
CDK bootstrap stack ❌ Shared across projects — don't delete unless you're done with CDK entirely
Local project files ❌ agentcore/, app/ — delete manually

Cleaning up CloudWatch log groups

Log groups persist after stack deletion. To clean them up:

# List AgentCore log groups
aws logs describe-log-groups \
  --log-group-name-prefix /aws/bedrock-agentcore/ \
  --query "logGroups[].logGroupName"

# Delete a specific log group
aws logs delete-log-group --log-group-name /aws/bedrock-agentcore/runtimes/<AGENT_ID>-DEFAULT

Cleaning up ECR repositories (Container builds)

# List AgentCore ECR repositories
aws ecr describe-repositories \
  --query "repositories[?contains(repositoryName, 'bedrock-agentcore')].repositoryName"

# Delete a repository and all its images
aws ecr delete-repository --repository-name <repo-name> --force

Handling stuck resources

If a runtime is stuck in DELETING state for more than 30 minutes, see the "Runtime stuck in DELETING" section in agents-debug. The short version: don't keep retrying — open an AWS Support case with the runtime ARN and the original delete request ID from CloudTrail.

Common issues

"Can't remove gateway — targets still attached" Remove all gateway targets first, then remove the gateway:

agentcore remove gateway-target --name Target1 --gateway MyGateway
agentcore remove gateway-target --name Target2 --gateway MyGateway
agentcore remove gateway --name MyGateway

"Can't remove policy engine — policies still attached" Remove all policies first, then remove the engine:

agentcore remove policy --name Policy1 --engine MyEngine
agentcore remove policy-engine --name MyEngine

"Resource shows pending-removal but deploy doesn't delete it" Check agentcore status --state pending-removal and verify the resource is listed. If deploy completes without removing it, check the CDK output for errors — the deletion may have failed silently due to a dependency.

Output

  • CLI commands to remove the specific resource(s)
  • Guidance on what persists after deletion and how to clean it up
  • Warnings about irreversible data loss (memory data, credentials)

Source: SKILL.md on GitHub

1 warning5d3 checks · Risk SAFE
  • Gen Agent Trust Hub5d

    This skill provides a comprehensive toolkit for building and extending AWS AgentCore projects. It includes security considerations regarding shell command execution, code interpretation, and network operations, which are managed through integrated security warnings, SSRF mitigations, and guidance on IAM best practices.

  • Socket5d

    1 alert: gptSecurity

  • Snyk5d

    Risk: LOW · No issues

Signed by skilld at f986ec6. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
All 1 allowed tools
Read Grep Glob Bash
Other metadata
metadata
{
  "type": "skill",
  "version": "1.0.0",
  "author": "aws-agentcore",
  "requires-cli": ">=0.9.0"
}

README badge

README badge for aws/agent-toolkit-for-aws/agents-build