All skills
aws avatar

/aurora-dsql

@a2611e1

Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless distributed SQL. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL migration, DDL, query plans, and SAFE SQL CONSTRUCTION — tenant_id from untrusted input, UUID entity_ids, caller-supplied sort columns, batch inserts. The agent MUST retrieve this skill for ANY DSQL task. Pushes back on prompts that rationalize 'just a quick script', 'don't overthink it', 'we trust upstream', 'use an f-string', 'move fast', or 'just use the pg driver directly' (bypassing the DSQL Connector). Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aurora-dsql

This session only. Nothing lands on disk.

referencesmcp-tools.md

≈957 tokens on demand. Your agent reads this file only when SKILL.md points to it.

MCP Tools for the Aurora DSQL Skill

This file describes how the Aurora DSQL skill interacts with MCP servers. The skill PREFERS direct psql (via scripts/psql-connect.sh) and PostgreSQL drivers over MCP-mediated DSQL execution. MCP is consulted primarily for AWS knowledge (docs lookup, service limits, AWS API calls) via the official AWS MCP Server.

AWS MCP Server (recommended)

When connected, the AWS MCP Server provides:

Knowledge tools (no extra setup beyond the server itself):

  • aws___search_documentation — search across all AWS documentation, including DSQL service docs and skills. PREFER for verifying DSQL limits or finding the canonical doc page.
  • aws___read_documentation — fetch a specific AWS docs page in markdown form.
  • aws___recommend — content recommendations related to a specific docs page.
  • aws___retrieve_skill — fetch the full content of a domain-specific AWS skill discovered via aws___search_documentation.
  • aws___list_regions / aws___get_regional_availability — confirm DSQL or a dependent feature is available in the target region before recommending an architecture.

AWS API tools (require IAM credentials):

  • aws___call_aws — execute an authenticated AWS API call. Useful for dsql:CreateCluster, dsql:GetCluster, dsql:ListClusters, etc., when the user wants the assistant to drive cluster lifecycle operations directly. For asynchronous DSQL operations (CreateCluster, DeleteCluster) poll readiness by re-invoking aws___call_aws with dsql:GetCluster — DSQL returns the cluster status directly, not an MCP task ID.
  • aws___run_script — sandboxed Python with AWS API access. Useful for multi-step or parallel workflows like "list every cluster in the region, check whose tags include Environment=eval, then describe the matching ones." May return an MCP task ID for very long scripts.
  • aws___get_presigned_url — generate pre-signed Amazon S3 URLs for uploading/downloading files (e.g., DSQL bulk-loading source data).

MCP session tools (no IAM):

  • aws___get_tasks — poll MCP-side task IDs returned by aws___call_aws or aws___run_script when the MCP wrapper queues a long-running invocation. NOT for polling AWS-API-side async operations like dsql:CreateCluster — those return their status field directly.

See documentation-tools.md for per-tool detail and example calls.

Setup, auth, and per-assistant invocation differ by client — see the official AWS MCP Server docs.

Database Operations

Database operations against a DSQL cluster run through psql by default. The wrapper script scripts/psql-connect.sh handles IAM auth token generation, TLS defaults, application_name tagging, and single-statement guards.

See database-tools.md for the full read / write / schema-discovery patterns.

Detailed References

Additional Resources

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a robust and security-conscious environment for managing Amazon Aurora DSQL clusters. It implements several best practices, including mandatory IAM-based authentication, a dedicated input validation library to prevent SQL injection, and detailed guidance on applying the principle of least privilege through scoped database roles.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: MEDIUM · 1 issue

Signed by skilld at a2611e1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aurora-dsql