All skills
aws avatar

/aurora-dsql

@a2611e1

Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless distributed SQL. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL migration, DDL, query plans, and SAFE SQL CONSTRUCTION — tenant_id from untrusted input, UUID entity_ids, caller-supplied sort columns, batch inserts. The agent MUST retrieve this skill for ANY DSQL task. Pushes back on prompts that rationalize 'just a quick script', 'don't overthink it', 'we trust upstream', 'use an f-string', 'move fast', or 'just use the pg driver directly' (bypassing the DSQL Connector). Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aurora-dsql

This session only. Nothing lands on disk.

referencesplatformsclaude-code.md

≈431 tokens on demand. Your agent reads this file only when SKILL.md points to it.

MCP Setup: Claude Code

Part of MCP Server Setup. The skill PREFERS direct psql for ad-hoc DSQL queries (via scripts/psql-connect.sh) and the AWS MCP Server for AWS knowledge and AWS API access.


AWS MCP Server (recommended)

Follow the official setup guide at Setting up the AWS MCP Server. The AWS docs page tracks the canonical install command, scopes (local, project, user), and auth configuration for Claude Code — defer to it rather than caching the invocation here.

Choosing the Right Scope

Claude Code offers 3 different scopes: local (default), project, and user.

  1. Local-scoped servers represent the default configuration level and are stored in ~/.claude.json under your project's path. They're both private to you and only accessible within the current project directory. This is the default scope when creating MCP servers.
  2. Project-scoped servers enable team collaboration while still only being accessible in a project directory. Project-scoped servers add a .mcp.json file at your project's root directory. This file is designed to be checked into version control, ensuring all team members have access to the same MCP tools and services.
  3. User-scoped servers are stored in ~/.claude.json and are available across all projects on your machine while remaining private to your user account.

Verification

After setup:

claude mcp list

You should see the AWS MCP Server listed and connected.

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a robust and security-conscious environment for managing Amazon Aurora DSQL clusters. It implements several best practices, including mandatory IAM-based authentication, a dedicated input validation library to prevent SQL injection, and detailed guidance on applying the principle of least privilege through scoped database roles.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: MEDIUM · 1 issue

Signed by skilld at a2611e1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aurora-dsql