All skills
lassejlv avatar

/use-aws

@e3d6f13
by Lasselassejlv/skills50 stars
1

Operate and investigate AWS accounts safely through AWS CLI and profile-aware workflows. Use when Codex needs to inspect AWS account identity, profiles, regions, costs, logs, deployments, IAM, S3, EC2, RDS, Lambda, ECS, CloudWatch, Route 53, CloudFormation, or make scoped non-destructive AWS changes. For broad cleanup, nuking, deleting everything, account teardown, or destructive resource removal, use aws-account-cleanup instead.

Use this Skill: https://skilld.dev/gh/lassejlv/skills/use-aws

This session only. Nothing lands on disk.

referencesaws-safety.md

≈713 tokens on demand. Your agent reads this file only when SKILL.md points to it.

AWS Safety

Use this reference before write operations, IAM/security changes, billing-sensitive commands, production-facing changes, or commands with unclear side effects.

Approval Gates

Proceed without extra approval only for clearly read-only commands that match the user's request. Ask for approval before commands that create, update, delete, start, stop, invoke, attach, detach, tag, untag, publish, deploy, rotate, grant, revoke, or change billing/cost exposure.

Before approval, state:

  • AWS account ID and ARN from STS.
  • Profile, region, and credential source if known.
  • Exact resources and commands.
  • Expected effect and whether it can cause downtime, access changes, data exposure, or cost.
  • Verification and rollback plan.

Use this approval shape:

please confirm apply <exact change> in AWS account <account-id> using profile <profile> in <region>

For broad deletion, account teardown, "nuke", "delete everything", or cleanup requests, stop using this skill and use aws-account-cleanup.

Risk Classes

Read-only:

  • sts get-caller-identity
  • list-*, describe-*, get-*, head-*
  • CloudWatch Logs queries and recent log tails without --follow
  • Cost Explorer reads

Mutating:

  • create-*, update-*, put-*, modify-*, set-*
  • start-*, stop-*, restart-*, reboot-*
  • tag-*, untag-*
  • deployment commands, stack updates, ECS/Lambda config updates

Destructive:

  • delete-*, terminate-*, remove-*, empty, destroy
  • detach-*, revoke-*, policy removal, key deletion or scheduling deletion
  • S3 object deletion, snapshot deletion, database deletion, IAM user/role/policy deletion

Cost-triggering or externally visible:

  • Lambda invocation, ECS run task, Batch jobs, Step Functions executions
  • Athena/Glue/EMR jobs, Bedrock/SageMaker calls, large S3 syncs
  • Route 53, CloudFront, ACM, WAF, load balancer, security group, or public access changes

Secrets

  • Never print secret values from Secrets Manager, SSM SecureString, environment variables, credentials files, .env, private keys, or database URLs.
  • If a task requires checking whether a secret exists, report metadata only: name, ARN, version label, last changed date, or policy.
  • If a secret must be passed to a command, use process environment, stdin, or a temporary file with restrictive permissions and remove it after use.
  • Do not paste AWS credentials into chat, commands, logs, or generated files.

Ownership

Prefer changing the source of truth over manual console/CLI edits. Check for Terraform, CDK, Pulumi, Serverless, SAM, CloudFormation, Helm, GitHub Actions, Railway/Fly/Vercel deploy config, or repo scripts before editing AWS resources directly.

If ownership is unclear, inspect tags, CloudFormation stack membership, deployment history, and repo configuration before making changes.

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a secure framework for AWS operations, featuring explicit safety guidelines, credential redaction, and a context-gathering script. It emphasizes read-only workflows and requires user confirmation for any mutating changes.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at e3d6f13. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago

README badge

README badge for lassejlv/skills/use-aws