All skills
aws avatar

/aws-cloudformation

@9dd9d8b

Authors, validates, and troubleshoots AWS CloudFormation templates. Covers template authoring with secure defaults, local validation with either cfn-lint or cloudformation-validate, cfn-guard security and compliance checks as a recommended default, account-aware CloudFormation service pre-deployment validation, CloudFormation Express mode for faster deployments, and root-cause diagnosis of failed stacks using CloudFormation events and CloudTrail correlation. Also covers author-time template intelligence with the CloudFormation Language Server and published cloudformation-validate libraries.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-cloudformation

This session only. Nothing lands on disk.

referencesvalidation-tool-selection.md

≈944 tokens on demand. Your agent reads this file only when SKILL.md points to it.

CloudFormation Validation Workflow

Purpose

Use this guide to choose and sequence CloudFormation validation. Run the applicable layers in this order:

  1. One local validator for syntax, schema, and resource-property checks.
  2. cfn-guard for security and compliance checks.
  3. CloudFormation service pre-deployment validation when account-aware checks are needed.

Each layer has different coverage. Report the outcome of each layer separately rather than treating one successful check as proof that the template is deployment-ready.

AWS MCP server: For steps that call AWS APIs, the AWS MCP server (call_aws) is recommended for sandboxed execution and audit logging, but it is not required. Every account-aware step also works with the AWS CLI; local validator steps require neither mechanism.

Select one local validator

Use exactly one local validation tool unless the user explicitly requests a comparison. Honor an explicit tool request first. Otherwise, reuse the tool configured by the project. If the project configures neither tool, use cfn-lint when it is installed; if it is not installed but the cfn-validate CLI is installed, use cloudformation-validate. If neither tool is installed, propose an exact-version cfn-lint installation as the deterministic default and follow the cfn-lint SOP approval flow. Do not propose installing both tools.

Follow the selected SOP's dependency and approval flow if its tool is unavailable. Do not install or download a tool without explicit user approval because those actions change the user's environment.

For validation embedded in code or another process, use a published cloudformation-validate library for the application's language. Follow the in-process and CDK integration guidance in the cloudformation-validate SOP.

Run security and compliance checks by default

After local validation has no blocking findings, run the cfn-guard security and compliance SOP by default. Do not require the user to opt in.

Skip this layer only when the user explicitly requests a skip or confirms that an equivalent project security and compliance check already passed. If cfn-guard, its binding, or applicable rules are unavailable, follow the SOP's dependency and approval flow rather than silently omitting the check. If the layer is skipped or cannot run, state that security and compliance were not evaluated.

Add account-aware pre-deployment validation

When account-aware checks are needed before deployment, follow the CloudFormation service pre-deployment validation SOP.

Before using CloudFormation service operations, confirm that the CloudTrail controls in the Security Considerations section are satisfied. If required audit logging is unavailable, state the reduced auditability.

Pre-deployment validation is enabled by default on Create Stack, Update Stack, and change-set creation. A FAIL-mode finding halts the operation before any resource is provisioned. Retrieve validation results with describe-events using the scoping guidance in the pre-deployment SOP; do not use describe-stack-events because it does not return these validation results.

Security Considerations

Follow the shared security guidance.

Report local, security and compliance, and service pre-deployment validation as separate outcomes; one successful layer does not prove another passed.

Source: SKILL.md on GitHub

1 warning13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    This skill provides specialized procedures for managing AWS CloudFormation templates, incorporating several security best practices and guardrails for handling untrusted template data.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: MEDIUM · 1 issue

Signed by skilld at 9dd9d8b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "3"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-cloudformation