All skills
zxkane avatar

/aws-agentic-ai

@e4ef2e2
by Mengxin Zhuzxkane/aws-skills365 stars
40

AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale. Use when working with any AgentCore service including Gateway, Runtime, Memory, Identity, Code Interpreter, Browser, Observability, Agent Registry, or Evaluations. Covers agent deployment, MCP tool integration, credential management, agent discovery, governance workflows, and automated quality assessment. Essential when user mentions AgentCore, agent runtime, agent registry, agent evaluation, MCP gateway, deploy agent, register MCP server, discover agents, evaluate agent quality, agent credentials, or wants to build, deploy, catalog, or monitor AI agents on AWS.

Use this Skill: https://skilld.dev/gh/zxkane/aws-skills/aws-agentic-ai

This session only. Nothing lands on disk.

servicesregistrymcp-endpoint.md

≈2.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Agent Registry - MCP Endpoint

Each Agent Registry exposes an MCP-compatible endpoint (MCP spec 2025-11-25) that any MCP client can connect to for searching registry records. This enables AI coding assistants (Claude Code, Kiro) and agents to discover available tools, agents, and resources through their native MCP integration.

Endpoint Format

https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp

The endpoint exposes a single MCP tool: search_registry_records.

Tool Parameters

Parameter Type Required Description
searchQuery string Yes Natural language or keyword query (1-256 chars)
maxResults integer No Number of results (1-20, default 10)
filter object No Metadata filter using $eq, $ne, $in, $and, $or operators

IAM-Based Access (Recommended)

Using mcp-proxy-for-aws

For IAM (SigV4) authentication, use the mcp-proxy-for-aws proxy which handles AWS signature signing automatically:

{
  "mcpServers": {
    "agent-registry": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "mcp-proxy-for-aws@latest",
        "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp",
        "--service", "bedrock-agentcore",
        "--region", "<region>",
        "--profile", "my-profile"
      ]
    }
  }
}

Add this to ~/.claude/settings.json (Claude Code) or your project's .claude/settings.json.

Required IAM Permissions

MCP tool invocation requires both permissions:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "bedrock-agentcore:InvokeRegistryMcp",
        "bedrock-agentcore:SearchRegistryRecords"
      ],
      "Resource": "arn:aws:bedrock-agentcore:<region>:<account>:registry/<registryId>"
    }
  ]
}

Using via AWS CLI in Skill Context

The aws-agentic-ai skill permits Bash(aws bedrock-agentcore *) for data plane commands. Search directly without MCP configuration:

aws bedrock-agentcore search-registry-records \
  --search-query "your search query" \
  --registry-ids "arn:aws:bedrock-agentcore:us-east-1:<account-id>:registry/reg-abc123def456" \
  --region us-east-1

This approach works out of the box with existing AWS credential chains.

JWT-Based Access (OAuth 2.0)

For external access or cross-organization scenarios. The registry must be created with --authorizer-type CUSTOM_JWT. Authorization type cannot be changed after creation.

Option 1: Bearer Token

{
  "mcpServers": {
    "my-registry": {
      "type": "http",
      "url": "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp",
      "headers": {
        "Authorization": "Bearer ${ACCESS_TOKEN}"
      }
    }
  }
}

Option 2: Pre-Registered Client

Register the client ID in the registry's authorizer configuration:

aws bedrock-agentcore-control update-registry \
  --registry-id <registryId> \
  --authorizer-configuration '{
    "optionalValue": {
      "customJWTAuthorizer": {
        "discoveryUrl": "https://<idp-domain>/.well-known/openid-configuration",
        "allowedClients": ["<client-id>"]
      }
    }
  }' \
  --region us-east-1

MCP client config:

{
  "mcpServers": {
    "pre-registered-registry": {
      "type": "http",
      "url": "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp",
      "oauth": {
        "clientId": "<client-id>",
        "callbackPort": "<port-number>"
      }
    }
  }
}

Option 3: Dynamic Client Registration

Configure with allowedAudience instead of allowedClients:

aws bedrock-agentcore-control update-registry \
  --registry-id <registryId> \
  --authorizer-configuration '{
    "optionalValue": {
      "customJWTAuthorizer": {
        "discoveryUrl": "https://<idp-domain>/.well-known/openid-configuration",
        "allowedAudience": ["https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp"]
      }
    }
  }' \
  --region us-east-1

MCP client config (no oauth needed — uses DCR):

{
  "mcpServers": {
    "dcr-registry": {
      "type": "http",
      "url": "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp"
    }
  }
}

OAuth well-known path for resource metadata discovery:

https://bedrock-agentcore.<region>.amazonaws.com/.well-known/oauth-protected-resource/registry/<registryId>/mcp

Supported identity providers: Amazon Cognito, Okta, Azure AD (Microsoft Entra ID), Auth0, or any OIDC-compatible provider.

Kiro Integration

Kiro supports MCP servers natively. Use the same mcp-proxy-for-aws approach for IAM:

{
  "mcpServers": {
    "org-registry": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "mcp-proxy-for-aws@latest",
        "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp",
        "--service", "bedrock-agentcore",
        "--region", "<region>"
      ]
    }
  }
}

Search Examples via MCP

Basic Search

{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": {
    "name": "search_registry_records",
    "arguments": {
      "searchQuery": "payment processing tools"
    }
  },
  "id": 1
}

Filtered Search (MCP Servers Only)

{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": {
    "name": "search_registry_records",
    "arguments": {
      "searchQuery": "data analytics",
      "maxResults": 5,
      "filter": {
        "descriptorType": {
          "$eq": "MCP"
        }
      }
    }
  },
  "id": 1
}

Complex Filter

{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": {
    "name": "search_registry_records",
    "arguments": {
      "searchQuery": "customer",
      "filter": {
        "$and": [
          {"descriptorType": {"$in": ["A2A", "MCP"]}},
          {"name": {"$ne": "deprecated-agent"}}
        ]
      }
    }
  },
  "id": 1
}

Verification

IAM Verification

curl -s -X POST \
  "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp" \
  -H "Content-Type: application/json" \
  -H "X-Amz-Security-Token: ${AWS_SESSION_TOKEN}" \
  --aws-sigv4 "aws:amz:<region>:bedrock-agentcore" \
  --user "${AWS_ACCESS_KEY_ID}:${AWS_SECRET_ACCESS_KEY}" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_registry_records","arguments":{"searchQuery":"weather"}}}'

OAuth Verification

curl -s -X POST \
  "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp" \
  -H "Authorization: Bearer ${ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_registry_records","arguments":{"searchQuery":"weather"}}}'

Agent-to-Agent Discovery Pattern

An AI agent can use the MCP endpoint to dynamically discover and invoke other agents:

  1. Discover: Agent searches registry for agents with specific capabilities
  2. Evaluate: Agent reads the A2A agent card to understand capabilities and endpoints
  3. Invoke: Agent calls the discovered agent via its advertised URL

This enables dynamic, runtime agent composition without hardcoded dependencies.

Troubleshooting

Issue Cause Solution
403 Forbidden Missing IAM permission Add both InvokeRegistryMcp and SearchRegistryRecords to role
Connection refused Wrong region or registry ID Verify endpoint URL matches registry region and ID
Empty results No approved records Ensure records are approved, not just in Draft status
JWT auth fails Token expired or wrong audience Check token validity and allowedClients/allowedAudience config
Timeout Network/VPC configuration Ensure outbound HTTPS (443) to bedrock-agentcore.<region>.amazonaws.com
mcp-proxy-for-aws errors Missing AWS credentials Ensure --profile or environment variables are configured

Related

Source: SKILL.md on GitHub

1 alert16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a comprehensive AWS Bedrock AgentCore orchestration guide with documentation, templates, and reference materials. No security issues, prompt injections, malicious dependencies, or obfuscation layers were detected.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    10/13 files flagged

Signed by skilld at e4ef2e2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago
What it can do
Network Runs commands
MCP servers
aws-mcpawsdocsacdocs
Modelsonnet
aliases
[
  "bedrock-agentcore"
]
context
fork
model
sonnet
All 12 allowed tools
mcp__aws-mcp__*mcp__awsdocs__*mcp__acdocs__search_agentcore_docsmcp__acdocs__fetch_agentcore_docBash(aws bedrock-agentcore *)Bash(aws bedrock-agentcore-control *)Bash(aws bedrock-agentcore-runtime *)Bash(aws bedrock *)Bash(aws s3 cp *)Bash(aws s3 ls *)Bash(aws secretsmanager *)Bash(aws sts get-caller-identity)
Other metadata
skills
[
  "aws-mcp-setup"
]
hooks
{
  "PreToolUse": [
    {
      "matcher": "Bash(aws bedrock-agentcore-control create-*)",
      "command": "aws sts get-caller-identity --query Account --output text",
      "once": true
    }
  ]
}

README badge

README badge for zxkane/aws-skills/aws-agentic-ai