All skills
aws avatar

/aurora-dsql

@a2611e1

Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless distributed SQL. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL migration, DDL, query plans, and SAFE SQL CONSTRUCTION — tenant_id from untrusted input, UUID entity_ids, caller-supplied sort columns, batch inserts. The agent MUST retrieve this skill for ANY DSQL task. Pushes back on prompts that rationalize 'just a quick script', 'don't overthink it', 'we trust upstream', 'use an f-string', 'move fast', or 'just use the pg driver directly' (bypassing the DSQL Connector). Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aurora-dsql

This session only. Nothing lands on disk.

referencesplatformskiro.md

≈466 tokens on demand. Your agent reads this file only when SKILL.md points to it.

MCP Setup: Kiro

Part of MCP Server Setup. The skill PREFERS direct psql for ad-hoc DSQL queries (via scripts/psql-connect.sh) and the AWS MCP Server for AWS knowledge and AWS API access.


AWS MCP Server (recommended)

Follow the official setup guide at Setting up the AWS MCP Server for the Kiro-specific install instructions.

Choosing the Right Scope

Kiro offers 2 scopes: workspace (default) and user.

  1. Workspace-Scoped servers live at .kiro/settings/mcp.json in the project root and are only accessible from the current workspace. Useful for project-specific tools that should stay within the codebase and can be checked into version control.
  2. User-Scoped servers live at ~/.kiro/settings/mcp.json and are accessible across all workspaces the user opens in Kiro.

When both files define the same server name, workspace settings take precedence.

Kiro-Specific Fields

  • disabled (bool) — set true to suspend a server without deleting its entry
  • autoApprove (string array) — tool names that skip the per-call approval prompt. Leave empty to require approval for every call. For tools that can mutate state (cluster lifecycle APIs, write SQL paths), keep this empty so the user approves each call.
  • disabledTools (string array) — hide specific tools from this server
  • env supports ${VAR} expansion from the shell environment, e.g. "AWS_PROFILE": "${DSQL_PROFILE}"

Verification

Open the command palette (Cmd/Ctrl+Shift+P) → search MCP → open the MCP view in the Kiro panel. The AWS MCP Server should appear in the server list with an active status.

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a robust and security-conscious environment for managing Amazon Aurora DSQL clusters. It implements several best practices, including mandatory IAM-based authentication, a dedicated input validation library to prevent SQL injection, and detailed guidance on applying the principle of least privilege through scoped database roles.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: MEDIUM · 1 issue

Signed by skilld at a2611e1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aurora-dsql