All skills
zxkane avatar

/aws-agentic-ai

@e4ef2e2
by Mengxin Zhuzxkane/aws-skills365 stars
40

AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale. Use when working with any AgentCore service including Gateway, Runtime, Memory, Identity, Code Interpreter, Browser, Observability, Agent Registry, or Evaluations. Covers agent deployment, MCP tool integration, credential management, agent discovery, governance workflows, and automated quality assessment. Essential when user mentions AgentCore, agent runtime, agent registry, agent evaluation, MCP gateway, deploy agent, register MCP server, discover agents, evaluate agent quality, agent credentials, or wants to build, deploy, catalog, or monitor AI agents on AWS.

Use this Skill: https://skilld.dev/gh/zxkane/aws-skills/aws-agentic-ai

This session only. Nothing lands on disk.

servicesidentityREADME.md

≈1.7k tokens on demand. Your agent reads this file only when SKILL.md points to it.

AgentCore Identity Service

Status: ✅ Available

Overview

Amazon Bedrock AgentCore Identity is an identity and credential management service designed specifically for AI agents and automated workloads. It provides secure authentication, authorization, and credential management capabilities that enable agents and tools to access AWS resources and third-party services on behalf of users while maintaining strict security controls and audit trails.

Core Capabilities

Centralized Agent Identity Management

  • Workload Identities: Agent identities implemented as workload identities with specialized attributes
  • Unified Directory: Create, manage, and organize agent identities through unified directory service
  • Hierarchical Organization: Group-based access controls and hierarchical organization
  • Cross-Environment: Consistent identity management regardless of deployment location

Secure Credential Storage

  • Token Vault: Securely store OAuth 2.0 tokens, client credentials, and API keys
  • Encryption: Comprehensive encryption at rest and in transit
  • Access Controls: Strict access controls with independent request validation
  • Defense-in-Depth: Protects end-user data from malicious or misbehaving agent code

OAuth 2.0 Flow Support

  • Client Credentials Grant: Machine-to-machine authentication (2LO)
  • Authorization Code Grant: User-delegated access (3LO)
  • Built-in Providers: Pre-configured providers for Google, GitHub, Slack, Salesforce
  • Custom Providers: Configurable OAuth 2.0 credential providers for custom integrations

Credential Provider Management

  • API Key Providers: Securely store and manage API keys
  • OAuth Credential Providers: Handle OAuth flow and token management
  • Token Lifecycle: Automatic token refresh and expiration handling
  • Provider Discovery: Automatically discover available credential providers

Agent Identity and Access Controls

  • Impersonation Flow: Agents access resources using provided credentials
  • Audit Trails: Maintain audit trails for all actions performed on behalf of users
  • Request Verification: Token signature verification, expiration checks, scope validation
  • Identity-Aware Authorization: Pass user context to agent code for dynamic decisions

Use Cases

Securing AI Agent Access

Enable agents to:

  • Authenticate with external services securely
  • Access resources on behalf of users
  • Maintain proper audit trails
  • Implement least-privilege access patterns

Multi-Provider Authentication

Support scenarios like:

  • Different authentication methods for different APIs
  • Unified credential management across services
  • OAuth flows for user-delegated access
  • API key management for service accounts

Zero-Trust Security Models

Allow implementation of:

  • No long-lived credentials in application code
  • Centralized, audited credential vault
  • Automated rotation to reduce attack window
  • Comprehensive access logging

Compliance and Auditing

Enable teams to:

  • Generate reports for compliance audits (SOC2, ISO27001)
  • Implement periodic access reviews
  • Maintain secrets inventory
  • Enforce credential policies

Quick Start

Create API Key Credential Provider

aws bedrock-agentcore-control create-api-key-credential-provider \
  --name MyAPICredentialProvider \
  --api-key "YOUR_API_KEY" \
  --region us-west-2

Create OAuth Credential Provider

aws bedrock-agentcore-control create-oauth2-credential-provider \
  --name MyOAuthProvider \
  --client-id "YOUR_CLIENT_ID" \
  --client-secret "YOUR_CLIENT_SECRET" \
  --authorization-url "https://provider.com/oauth/authorize" \
  --token-url "https://provider.com/oauth/token" \
  --scopes '["read", "write"]' \
  --region us-west-2

Using Credentials with SDK

from bedrock_agentcore.identity import CredentialProvider

# Get credentials for external API
provider = CredentialProvider("MyAPICredentialProvider")
api_key = provider.get_api_key()

# Get OAuth token
oauth_provider = CredentialProvider("MyOAuthProvider")
token = oauth_provider.get_access_token()

Common Operations

List Credential Providers

aws bedrock-agentcore-control list-api-key-credential-providers \
  --region us-west-2

Update Credential Provider

aws bedrock-agentcore-control update-api-key-credential-provider \
  --name MyAPICredentialProvider \
  --api-key "NEW_API_KEY" \
  --region us-west-2

Delete Credential Provider

aws bedrock-agentcore-control delete-api-key-credential-provider \
  --name MyAPICredentialProvider \
  --region us-west-2

Built-in OAuth Providers

AgentCore Identity includes built-in providers for popular services:

Provider Use Case
Google Google Workspace, Gmail, Drive
GitHub Repository access, Actions
Slack Messaging, channel access
Salesforce CRM data access

Best Practices

Security

  • Use credential providers instead of hardcoded credentials
  • Implement least-privilege access for each credential
  • Rotate credentials regularly (quarterly minimum)
  • Monitor credential usage with CloudWatch

Development

  • Use separate credential providers per environment
  • Implement proper error handling for credential access
  • Test credential flows in non-production first
  • Use SDK annotations for cleaner code

Operations

  • Set up alerts for credential access failures
  • Audit credential usage periodically
  • Implement automated rotation where possible
  • Document credential ownership and purpose

Troubleshooting

Issue Cause Solution
Credential not found Provider doesn't exist or name typo Verify provider name with list command
Invalid API key Key expired or incorrect Update credential provider with new key
OAuth token expired Token refresh failed Check OAuth provider configuration
Access denied Insufficient permissions Verify IAM policy for credential access

Related Services

References

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive AWS Bedrock AgentCore orchestration guide with documentation, templates, and reference materials. No security issues, prompt injections, malicious dependencies, or obfuscation layers were detected.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    10/13 files flagged

Signed by skilld at e4ef2e2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago
What it can do
Network Runs commands
MCP servers
aws-mcpawsdocsacdocs
Modelsonnet
aliases
[
  "bedrock-agentcore"
]
context
fork
model
sonnet
All 12 allowed tools
mcp__aws-mcp__*mcp__awsdocs__*mcp__acdocs__search_agentcore_docsmcp__acdocs__fetch_agentcore_docBash(aws bedrock-agentcore *)Bash(aws bedrock-agentcore-control *)Bash(aws bedrock-agentcore-runtime *)Bash(aws bedrock *)Bash(aws s3 cp *)Bash(aws s3 ls *)Bash(aws secretsmanager *)Bash(aws sts get-caller-identity)
Other metadata
skills
[
  "aws-mcp-setup"
]
hooks
{
  "PreToolUse": [
    {
      "matcher": "Bash(aws bedrock-agentcore-control create-*)",
      "command": "aws sts get-caller-identity --query Account --output text",
      "once": true
    }
  ]
}

README badge

README badge for zxkane/aws-skills/aws-agentic-ai