All skills
aws avatar

/amazon-bedrock

@3b23681

Builds generative AI applications on Amazon Bedrock. Covers model invocation (Converse API, InvokeModel), RAG with Knowledge Bases, Bedrock Agents, Guardrails, and AgentCore (including the Harness managed agent loop). Applies when invoking models, setting up Knowledge Bases, creating agents, applying guardrails, deploying to AgentCore, migrating/porting/converting a Bedrock Agent (including inline agents) to an AgentCore Harness, troubleshooting Bedrock errors (ThrottlingException, AccessDeniedException), or choosing models (Claude, Llama, Nova, Titan). Also for prompt caching, quota and throttling diagnosis, cost tracking, migrating between Claude model generations (4.5 to 4.6 to 4.7), chunking strategies, API selection (Converse vs InvokeModel), guardrail capabilities, and model selection. Also covers AgentCore Payments (x402, microtransactions, Payment Manager, Connector, Instrument, Coinbase CDP, Stripe Privy, paid endpoints, agent payments). NOT for custom model training, Rekognition, or Comprehend.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-bedrock

This session only. Nothing lands on disk.

referencesknowledge-bases-decision-guide.md

≈718 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Knowledge Bases (retrieval, agentic retrieval and RAG) — Decision Guide & Routing

Choose the knowledge base type first, then route to the correct setup and retrieval reference. Creation and the query API differ by type.

Decision: Managed KB vs Customer-managed KB

Default to the Managed Knowledge Base (MKB) for agentic retrieval and RAG on Bedrock — AWS recommends it and it fully manages storage, chunking, parsing, and retrieval, with no infrastructure to provision. Use it for essentially all new RAG work.

Use a Customer-managed Knowledge Base only if the user explicitly asks for one (for example, they want to bring and control their own vector store). Do not screen the request against a capability list or try to predict whether MKB can satisfy it — default to MKB and proceed; if a specific configuration is not supported, let the create call surface the error. Connector, feature, quota, and region specifics change frequently and differ by type — consult the Bedrock Knowledge Base docs; this skill deliberately does not maintain a capability matrix.

Create / manage a knowledge base

  • Managed KB (default): you MUST read managed KB setup and execute it step by step (create → connect a data source via the managed connector → ingest/sync → verify with Retrieve). Do NOT summarize — execute each step, respecting all MUST constraints before proceeding.
  • Customer-managed KB (only if explicitly asked): you MUST read customer-managed KB setup and execute its 7-step procedure (choose chunking → choose/provision vector store → IAM role → create KB → data source → ingest → verify).

Query a knowledge base

  • Managed KB: you MUST read managed KB retrieval. Use Retrieve (single-shot chunks) or AgenticRetrieveStream (agentic: plan → retrieve → evaluate → iterate across multiple KBs — check the service quota). AgenticRetrieveStream is streaming ⇒ SDK-only (not the AWS CLI). RetrieveAndGenerate (synthesized answer with citations) is the Customer-managed path; if you specifically need it on MKB, verify support against the docs.
  • Customer-managed KB: you MUST read customer-managed KB retrieval. Present the retrieve-and-generate / retrieve / manual modes so the user selects the right one.

Security

Before creating or querying, review the Security Considerations in managed KB setup and managed KB retrieval: least-privilege connector IAM roles, customer-managed KMS encryption, and CloudTrail data-event logging for KB access apply to both the create and query paths.

Source: SKILL.md on GitHub

1 warning2d3 checks · Risk SAFE
  • Gen Agent Trust Hub2d

    This skill provides a comprehensive and secure framework for building generative AI applications on Amazon Bedrock. It incorporates industry-standard security practices, including IAM least-privilege guidance, SSRF protections, and robust encryption recommendations for sensitive data.

  • Socket2d

    1 alert: gptSecurity

  • Snyk2d

    Risk: LOW · No issues

Signed by skilld at 3b23681. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 days ago
metadata
{
  "version": "6"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-bedrock