Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation.
Install the "resource-tagging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/resource-tagging into .claude/skills/resource-tagging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "resource-tagging", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add ancoleman/ai-design-components --skill resource-tagging -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "resource-tagging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/resource-tagging into .agents/skills/resource-tagging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "resource-tagging", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add ancoleman/ai-design-components --skill resource-tagging -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "resource-tagging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/resource-tagging into .cursor/skills/resource-tagging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "resource-tagging", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add ancoleman/ai-design-components --skill resource-tagging -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "resource-tagging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/resource-tagging into .gemini/skills/resource-tagging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "resource-tagging", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add ancoleman/ai-design-components --skill resource-tagging -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "resource-tagging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/resource-tagging into .github/skills/resource-tagging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "resource-tagging", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add ancoleman/ai-design-components --skill resource-tagging -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "resource-tagging" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/resource-tagging into .opencode/skills/resource-tagging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "resource-tagging", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
resource-tagging
GitHub stars
526
Token cost
~4k tokens
SKILL.md length
1,383 words
Files
10 (incl. scripts, references)
Skills in repo
75
Repo updated
First seen
Licence
MIT
At a glance
Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation.
Works in 3 steps: Hard enforcement (deny resource… → Soft enforcement (alert only): Use for… → No enforcement (best-effort): Use for…
Implementing cloud governance
SKILL.md covers Purpose, When to Use, Minimum Viable Tagging Strategy and Tag Naming Conventions, plus 7 more sections
Runs Python scripts from its folder; calls gcloud and az
What it does
Resource Tagging is an agent skill from ancoleman/ai-design-components. Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation. Use when implementing cloud governance, optimizing costs, or automating infrastructure management.
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts and reference files (for example `examples/kubernetes/gatekeeper-constraints.yaml`, `outputs.yaml` and `references/compliance-auditing.md`).
It sits in DevOps & Cloud, covering Cloud cost optimization and Container orchestration. It works with Amazon Web Services, Google Cloud, Microsoft Azure and Kubernetes. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.
When your agent uses it
Implementing cloud governance
Optimizing costs
Automating infrastructure management
Example prompts
“/resource-tagging”
Requirements
Python 3
Workflow steps
3 steps, taken from the first numbered list in SKILL.md.
1Hard enforcement (deny resource creation): Use for cost allocation tags
2Soft enforcement (alert only): Use for operational tags
3No enforcement (best-effort): Use for custom/experimental tags
What it can do on your machine
Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gcloud
az
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use gcloud and az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Resource Tagging loads about 4k tokens when it runs, and up to ~28k if it reads all its reference files. Until then it costs about 69 tokens; SKILL.md has 1,383 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~69
When it runs· the whole SKILL.md, loaded when a task matches
~4k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~28k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/resource-tagging/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
resource-tagging
description
Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation. Use when implementing cloud governance, optimizing costs, or automating infrastructure management.
Resource Tagging
Apply comprehensive cloud resource tagging strategies to enable cost allocation, ownership tracking, compliance enforcement, and infrastructure automation across multi-cloud environments.
Purpose
Resource tagging provides the foundational metadata layer for cloud governance. Tags enable precise cost allocation (reducing unallocated spend by up to 80%), rapid ownership identification, compliance scope definition, and automated lifecycle management. Without proper tagging, cloud costs become untrackable, security incidents lack context, and automation policies fail to target resources effectively.
When to Use
Use resource tagging when:
Implementing cloud governance frameworks for cost allocation and accountability
Building FinOps practices requiring spend visibility by team, project, or department
Enforcing compliance requirements (PCI, HIPAA, SOC2) through automated policies
Setting up automated resource lifecycle management (backup, monitoring, shutdown)
Managing multi-tenant or multi-project cloud environments
Implementing disaster recovery and backup policies based on criticality
Tracking resource ownership for security incident response
Optimizing cloud costs through spend analysis and showback/chargeback
Minimum Viable Tagging Strategy
Start with the "Big Six" required tags for all cloud resources:
All resources automatically inherit these tags. Resource-specific tags merge with defaults.
For complete Terraform, Pulumi, and CloudFormation examples, see examples/terraform/, examples/pulumi/, and examples/cloudformation/.
Policy-Based Enforcement
Enforce tagging at resource creation time:
AWS: Use AWS Config rules to check tag compliance (alert or deny)
Azure: Use Azure Policy for tag inheritance and enforcement
GCP: Use Organization Policies to restrict label values
Kubernetes: Use OPA Gatekeeper or Kyverno for admission control
For enforcement implementation patterns, see references/enforcement-patterns.md.
Tag Compliance Auditing
Run regular audits (weekly recommended) to identify untagged resources:
AWS Config Query (SQL):
sql
SELECT resourceId, resourceType, configuration.tags
WHERE resourceType IN ('AWS::EC2::Instance', 'AWS::RDS::DBInstance')
AND (configuration.tags IS NULL OR NOT configuration.tags.Environment EXISTS)
Azure Resource Graph Query (KQL):
kusto
Resources
| where type in~ ('microsoft.compute/virtualmachines')
| where isnull(tags.Environment) or isnull(tags.Owner)
| project name, type, resourceGroup, tags
GCP Cloud Asset Inventory:
bash
gcloud asset search-all-resources \
--query="NOT labels:environment OR NOT labels:owner" \
--format="table(name,assetType,labels)"
For complete audit queries and scripts, see references/compliance-auditing.md and scripts/audit_tags.py.
Cost Allocation with Tags
Enable cost allocation tags to track spending by team, project, or department:
AWS Cost Explorer
Activate cost allocation tags (up to 24 hours for activation):
hcl
# Enable cost allocation tags via Terraform
resource "aws_ce_cost_allocation_tag" "environment" {
tag_key = "Environment"
status = "Active"
}
resource "aws_ce_cost_allocation_tag" "project" {
tag_key = "Project"
status = "Active"
}
Set up cost anomaly detection by tag to catch unusual spending:
Group costs by tags in Azure Cost Management dashboards. Export cost data with tag breakdowns:
bash
az consumption usage list \
--start-date 2025-12-01 \
--query "[].{Cost:pretaxCost, Project:tags.Project, Team:tags.Owner}"
GCP Cloud Billing
Export billing data to BigQuery with label breakdowns:
sql
SELECT
labels.key AS label_key,
labels.value AS label_value,
SUM(cost) AS total_cost
FROM `project.dataset.gcp_billing_export_v1_XXXXX`
CROSS JOIN UNNEST(labels) AS labels
WHERE labels.key IN ('environment', 'project', 'costcenter')
GROUP BY label_key, label_value
ORDER BY total_cost DESC
For cost allocation implementation details, see references/cost-allocation.md.
Decision Framework: Required vs. Optional Tags
Determine which tags to enforce at creation time:
REQUIRED (enforce with hard deny):
Cost allocation: Owner, CostCenter, Project
Lifecycle: Environment, ManagedBy
Identification: Name
RECOMMENDED (soft enforcement - alert only):
Operational: Backup, Monitoring, Schedule
Security: Compliance, DataClassification
Support: SLA, ChangeManagement
OPTIONAL (no enforcement):
Custom: Application, Component, Customer
Experimental: Any non-standard tags
Enforcement methods:
Hard enforcement (deny resource creation): Use for cost allocation tags
AWS: AWS Config rules with deny mode
Azure: Azure Policy with deny effect
GCP: Organization policies with constraints
Soft enforcement (alert only): Use for operational tags
AWS: AWS Config rules with notification
Azure: Azure Policy with audit effect
GCP: Cloud Asset Inventory reports
No enforcement (best-effort): Use for custom/experimental tags
Tag Inheritance Strategies
Reduce manual tagging effort through automatic inheritance:
AWS Tag Policies
Inherit tags from AWS Organizations account hierarchy:
Resource Tagging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Resource Tagging compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Resource Tagging this skillancoleman/ai-design-components
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation. Resource Tagging is an agent skill from ancoleman/ai-design-components. Apply and enforce cloud resource tagging strategies across AWS, Azure, GCP, and Kubernetes for cost allocation, ownership tracking, compliance, and automation.
Run `npx skills add ancoleman/ai-design-components --skill resource-tagging -a claude-code`. Or copy the skill folder (skills/resource-tagging in ancoleman/ai-design-components) into .claude/skills/resource-tagging in your project. Claude Code loads it when a task matches its description.
How do I install Resource Tagging in Codex?
Run `npx skills add ancoleman/ai-design-components --skill resource-tagging -a codex`. Or copy the skill folder (skills/resource-tagging in ancoleman/ai-design-components) into .agents/skills/resource-tagging in your project. Codex loads it when a task matches its description.
Can I use Resource Tagging in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill resource-tagging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/resource-tagging, .gemini/skills/resource-tagging, .github/skills/resource-tagging and .opencode/skills/resource-tagging in your project.
What does Resource Tagging need to run?
Going by SKILL.md and its folder, Resource Tagging needs Python for the scripts in its folder and the command-line tools its instructions call (gcloud and az). Our summary lists: Python 3.
Does Resource Tagging access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Resource Tagging safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does Resource Tagging use?
Resource Tagging is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Resource Tagging use?
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.
What are the alternatives to Resource Tagging?
Skills that share tags, products or a category with Resource Tagging: Infrastructure Devops Cloud Architect (chendongqi/OPB-Skills, 125 stars), Provider Bug Review (mondoohq/mql, 411 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars) and Extend Discovery Type (runwhen-contrib/runwhen-local, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Resource Tagging?
ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.