All skills
zxkane avatar

/aws-agentic-ai

@e4ef2e2
by Mengxin Zhuzxkane/aws-skills365 stars
40

AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale. Use when working with any AgentCore service including Gateway, Runtime, Memory, Identity, Code Interpreter, Browser, Observability, Agent Registry, or Evaluations. Covers agent deployment, MCP tool integration, credential management, agent discovery, governance workflows, and automated quality assessment. Essential when user mentions AgentCore, agent runtime, agent registry, agent evaluation, MCP gateway, deploy agent, register MCP server, discover agents, evaluate agent quality, agent credentials, or wants to build, deploy, catalog, or monitor AI agents on AWS.

Use this Skill: https://skilld.dev/gh/zxkane/aws-skills/aws-agentic-ai

This session only. Nothing lands on disk.

cross-serviceregistry-integration.md

≈3.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cross-Service: Registry Integration Patterns

Applies to: Registry, Gateway, Runtime, Identity

Overview

Agent Registry becomes most powerful when combined with other AgentCore services. This guide covers cross-service patterns for discovering, deploying, and operating AI resources through the registry.

Pattern 1: Registry + Gateway (Discover and Deploy MCP Servers)

Discover MCP servers from the registry, then deploy them as Gateway targets for agent consumption.

┌──────────────┐  search   ┌──────────────┐  deploy   ┌──────────────┐
│ Developer /  │ ────────> │ Agent        │ ────────> │ Gateway      │
│ Agent        │           │ Registry     │           │ Target       │
└──────────────┘           └──────────────┘           └──────────────┘
                                  │                          │
                                  │ MCP schema               │ serves tools
                                  ▼                          ▼
                           ┌──────────────┐           ┌──────────────┐
                           │ External     │           │ AI Agents    │
                           │ MCP Server   │           │ (consumers)  │
                           └──────────────┘           └──────────────┘

Workflow

REGION="us-east-1"
REGISTRY_ID="reg-abc123"
GATEWAY_ID="gw-xyz789"

# 1. Search registry for a useful MCP server
RESULT=$(aws bedrock-agentcore search-registry-records \
  --search-query "payment processing" \
  --registry-ids "arn:aws:bedrock-agentcore:${REGION}:$(aws sts get-caller-identity --query Account --output text):registry/${REGISTRY_ID}" \
  --filter '{"descriptorType": {"$eq": "MCP"}}' \
  --region $REGION)

echo "$RESULT"
# Extract the MCP server schema from the search results

# 2. Save the discovered schema to S3
echo "$RESULT" | jq -r '.records[0].descriptors.mcp.server.inlineContent' > /tmp/discovered-schema.json
aws s3 cp /tmp/discovered-schema.json s3://my-schemas-bucket/discovered/payments-mcp.json

# 3. Deploy as a Gateway target
aws bedrock-agentcore-control create-gateway-target \
  --gateway-identifier $GATEWAY_ID \
  --name "payments-from-registry" \
  --endpoint-configuration '{
    "openApiSchema": {
      "s3": {"uri": "s3://my-schemas-bucket/discovered/payments-mcp.json"}
    }
  }' \
  --region $REGION

Bi-directional Sync

Register your Gateway targets back into the registry so other teams can discover them using URL-based sync:

# Sync a Gateway target into the registry
aws bedrock-agentcore-control create-registry-record \
  --registry-id $REGISTRY_ID \
  --name "platform/payments-gateway" \
  --description "Payment tools exposed via Gateway (team: platform)" \
  --descriptor-type MCP \
  --synchronization-type URL \
  --synchronization-configuration "{
    \"fromUrl\": {
      \"url\": \"https://bedrock-agentcore.${REGION}.amazonaws.com/gateway/${GATEWAY_ID}/target/tgt-payments/mcp\",
      \"credentialProviderConfigurations\": [{
        \"credentialProviderType\": \"IAM\",
        \"credentialProvider\": {
          \"iamCredentialProvider\": {
            \"roleArn\": \"arn:aws:iam::$(aws sts get-caller-identity --query Account --output text):role/RegistrySyncRole\",
            \"service\": \"bedrock-agentcore\"
          }
        }
      }]
    }
  }" \
  --region $REGION

Pattern 2: Registry + Identity (Credential-Aware Discovery)

Use Identity service credentials when syncing from protected external sources.

┌──────────────┐           ┌──────────────┐           ┌──────────────┐
│ Identity     │  provide  │ Registry     │  sync     │ External     │
│ Service      │ ────────> │ Sync Engine  │ ────────> │ MCP Server   │
│ (OAuth cred) │           │              │           │ (protected)  │
└──────────────┘           └──────────────┘           └──────────────┘

Setup

# 1. Create OAuth credential in Identity service
aws bedrock-agentcore-control create-oauth-credential-provider \
  --name "partner-api-oauth" \
  --credential-provider-vendor CUSTOM \
  --oauth-discovery '{"discoveryUrl": "https://auth.partner.com/.well-known/openid-configuration"}' \
  --credential-provider-auth-parameters '{
    "oauthParameters": {
      "oauthClientId": "registry-sync-client",
      "oauthClientSecret": "<CLIENT_SECRET>"
    }
  }' \
  --region us-east-1

# 2. Create synced record using the credential
aws bedrock-agentcore-control create-registry-record \
  --registry-id <REGISTRY_ID> \
  --name "partner/logistics-server" \
  --descriptor-type MCP \
  --synchronization-type URL \
  --synchronization-configuration '{
    "fromUrl": {
      "url": "https://api.partner.com/mcp",
      "credentialProviderConfigurations": [{
        "credentialProviderType": "OAUTH",
        "credentialProvider": {
          "oauthCredentialProvider": {
            "providerArn": "arn:aws:bedrock-agentcore:us-east-1:<account-id>:oauth-credential-provider/partner-api-oauth",
            "grantType": "CLIENT_CREDENTIALS"
          }
        }
      }]
    }
  }' \
  --region us-east-1

Pattern 3: Registry + Runtime (Dynamic Agent Composition)

Agents running in Runtime can query the registry to dynamically discover and invoke other agents or tools.

┌──────────────┐  invoke   ┌──────────────┐  search   ┌──────────────┐
│ User         │ ────────> │ Orchestrator │ ────────> │ Agent        │
│              │           │ Agent        │           │ Registry     │
└──────────────┘           │ (Runtime)    │           └──────┬───────┘
                           └──────┬───────┘                  │
                                  │                   discover│
                                  │ invoke                   │
                                  ▼                          ▼
                           ┌──────────────┐           ┌──────────────┐
                           │ Discovered   │ <──────── │ Agent Card   │
                           │ Agent        │   A2A     │ (from record)│
                           └──────────────┘           └──────────────┘

Agent Code Example

import boto3
import json

agentcore_client = boto3.client("bedrock-agentcore")
agentcore_control = boto3.client("bedrock-agentcore-control")

REGISTRY_ARN = "arn:aws:bedrock-agentcore:us-east-1:<account-id>:registry/reg-abc123"

def discover_and_delegate(user_query: str) -> dict:
    """Orchestrator agent discovers relevant agents/tools at runtime."""

    # 1. Search registry for relevant capabilities
    results = agentcore_client.search_registry_records(
        searchQuery=user_query,
        registryIds=[REGISTRY_ARN],
        maxResults=5
    )

    # 2. Filter for agents or MCP servers
    for record in results.get("records", []):
        if record["descriptorType"] == "A2A":
            # Parse A2A agent card
            agent_card = json.loads(
                record["descriptors"]["a2a"]["agentCard"]["inlineContent"]
            )
            # Invoke the discovered agent via its endpoint
            return invoke_a2a_agent(agent_card["url"], user_query)

        elif record["descriptorType"] == "MCP":
            # Parse MCP server definition
            mcp_def = json.loads(
                record["descriptors"]["mcp"]["server"]["inlineContent"]
            )
            # Use the discovered tools
            return invoke_mcp_tools(mcp_def, user_query)

    return {"error": "No relevant agents or tools found"}

Pattern 4: Multi-Registry Architecture

Use multiple registries for different purposes, environments, or access levels.

┌─────────────────────────────────────────────────────┐
│                  Organization                        │
│                                                      │
│  ┌──────────────┐  ┌──────────────┐  ┌────────────┐│
│  │ Dev Registry │  │ Prod Registry│  │ Partner    ││
│  │ (auto-approve)│ │ (manual)     │  │ Registry   ││
│  │              │  │              │  │ (JWT auth) ││
│  │ - prototypes │  │ - validated  │  │ - external ││
│  │ - experiments│  │ - production │  │ - partner  ││
│  │ - draft tools│  │ - curated    │  │ - shared   ││
│  └──────────────┘  └──────────────┘  └────────────┘│
│                                                      │
│  Promotion flow:  Dev ──> Prod ──> Partner          │
└─────────────────────────────────────────────────────┘

Promoting Records Across Registries

# 1. Read record from dev registry
RECORD=$(aws bedrock-agentcore-control get-registry-record \
  --registry-id $DEV_REGISTRY_ID \
  --record-id $RECORD_ID \
  --region us-east-1)

# 2. Extract descriptor and create in prod registry
DESCRIPTORS=$(echo "$RECORD" | jq '.descriptors')
NAME=$(echo "$RECORD" | jq -r '.name')
DESC=$(echo "$RECORD" | jq -r '.description')
TYPE=$(echo "$RECORD" | jq -r '.descriptorType')

aws bedrock-agentcore-control create-registry-record \
  --registry-id $PROD_REGISTRY_ID \
  --name "$NAME" \
  --description "$DESC" \
  --descriptor-type "$TYPE" \
  --descriptors "$DESCRIPTORS" \
  --record-version "1.0.0" \
  --region us-east-1

# 3. Submit for prod approval
aws bedrock-agentcore-control submit-registry-record-for-approval \
  --registry-id $PROD_REGISTRY_ID \
  --record-id $NEW_RECORD_ID \
  --region us-east-1

Security Considerations

Cross-Service IAM Policy

A role that can discover resources and deploy them to Gateway:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "RegistrySearch",
      "Effect": "Allow",
      "Action": [
        "bedrock-agentcore:SearchRegistryRecords",
        "bedrock-agentcore:InvokeRegistryMcp"
      ],
      "Resource": "arn:aws:bedrock-agentcore:*:*:registry/*"
    },
    {
      "Sid": "RegistryRead",
      "Effect": "Allow",
      "Action": [
        "bedrock-agentcore:GetRegistryRecord",
        "bedrock-agentcore:ListRegistryRecords"
      ],
      "Resource": "arn:aws:bedrock-agentcore:*:*:registry/*"
    },
    {
      "Sid": "GatewayDeploy",
      "Effect": "Allow",
      "Action": [
        "bedrock-agentcore:CreateGatewayTarget",
        "bedrock-agentcore:GetGatewayTarget"
      ],
      "Resource": "arn:aws:bedrock-agentcore:*:*:gateway/*"
    }
  ]
}

Least Privilege by Persona

Persona Registry Permissions Cross-Service Permissions
Consumer SearchRegistryRecords, InvokeRegistryMcp None required
Publisher + CreateRegistryRecord, SubmitRegistryRecordForApproval None required
Curator + UpdateRegistryRecordStatus None required
Platform Engineer + All Registry operations Gateway, Runtime, Identity operations

Related

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive AWS Bedrock AgentCore orchestration guide with documentation, templates, and reference materials. No security issues, prompt injections, malicious dependencies, or obfuscation layers were detected.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    10/13 files flagged

Signed by skilld at e4ef2e2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago
What it can do
Network Runs commands
MCP servers
aws-mcpawsdocsacdocs
Modelsonnet
aliases
[
  "bedrock-agentcore"
]
context
fork
model
sonnet
All 12 allowed tools
mcp__aws-mcp__*mcp__awsdocs__*mcp__acdocs__search_agentcore_docsmcp__acdocs__fetch_agentcore_docBash(aws bedrock-agentcore *)Bash(aws bedrock-agentcore-control *)Bash(aws bedrock-agentcore-runtime *)Bash(aws bedrock *)Bash(aws s3 cp *)Bash(aws s3 ls *)Bash(aws secretsmanager *)Bash(aws sts get-caller-identity)
Other metadata
skills
[
  "aws-mcp-setup"
]
hooks
{
  "PreToolUse": [
    {
      "matcher": "Bash(aws bedrock-agentcore-control create-*)",
      "command": "aws sts get-caller-identity --query Account --output text",
      "once": true
    }
  ]
}

README badge

README badge for zxkane/aws-skills/aws-agentic-ai