Agent skill

AWS Cloud Monitoring

by automateyournetwork in automateyournetwork/netclaw

AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

Apache-2.0Auto-check passedDevOps & Cloud

Install AWS Cloud Monitoring

skills CLI
$ npx skills add automateyournetwork/netclaw --skill aws-cloud-monitoring -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw aws-cloud-monitoring --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/aws-cloud-monitoring .claude/skills/aws-cloud-monitoring && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-cloud-monitoring
GitHub stars
677
Token cost
~1k tokens
SKILL.md length
402 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

  • Works in 6 steps: Check alarms: List CloudWatch alarms in… → VPN metrics: Tunnel state, bytes in/out… → NAT Gateway metrics: Active connections,… → …
  • Checking AWS alarms
  • SKILL.md covers MCP Server, Key Capabilities, Workflow: Network Monitoring… and Workflow: Flow Log Analysis, plus 5 more sections
  • Calls uvx; needs AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY

What it does

AWS Cloud Monitoring is an agent skill from automateyournetwork/netclaw. AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance. Use when checking AWS alarms, analyzing VPC flow logs, investigating network latency, or monitoring VPN and NAT Gateway metrics.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Amazon Web Services. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Checking AWS alarms
  • Analyzing VPC flow logs
  • Investigating network latency
  • Monitoring VPN and NAT Gateway metrics

Example prompts

  • “/aws-cloud-monitoring”

Requirements

  • A credential in AWS_SECRET_ACCESS_KEY

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Check alarms: List CloudWatch alarms in ALARM state
  2. VPN metrics: Tunnel state, bytes in/out for site-to-site VPNs
  3. NAT Gateway metrics: Active connections, packets dropped, bytes processed
  4. Transit Gateway metrics: Bytes in/out, packets dropped per attachment
  5. ELB metrics: Healthy/unhealthy targets, latency, 5xx errors
  6. Report: Network health dashboard with any issues flagged

What it can do on your machine

Read from SKILL.md and the folder at commit f943637. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uvx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uvx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_ACCESS_KEY_ID
    • AWS_SECRET_ACCESS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Cloud Monitoring loads about 1k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 402 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit f943637, republished under its Apache-2.0 licence (© automateyournetwork). 402 words, ~1,036 tokens.

Download SKILL.mdSave it as .claude/skills/aws-cloud-monitoring/SKILL.md (or your agent's skills folder).
name
aws-cloud-monitoring
description
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance. Use when checking AWS alarms, analyzing VPC flow logs, investigating network latency, or monitoring VPN and NAT Gateway metrics.
version
1.0.0
license
Apache-2.0
tags
aws, cloudwatch, monitoring, metrics, alarms, logs, flow-logs

AWS Cloud Monitoring

MCP Server

  • Command: uvx awslabs.cloudwatch-mcp-server@latest (stdio transport)
  • Requires: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION (or AWS_PROFILE)

Key Capabilities

  • Metrics: Query CloudWatch metrics for any AWS service (EC2, ELB, TGW, NAT GW, VPN)
  • Alarms: List and inspect CloudWatch alarms and their states
  • Logs: Run CloudWatch Logs Insights queries across any log group
  • Flow Logs: Analyze VPC and TGW flow logs for traffic patterns and dropped connections

Workflow: Network Monitoring Dashboard

When a user asks "how is our AWS network performing?":

  1. Check alarms: List CloudWatch alarms in ALARM state
  2. VPN metrics: Tunnel state, bytes in/out for site-to-site VPNs
  3. NAT Gateway metrics: Active connections, packets dropped, bytes processed
  4. Transit Gateway metrics: Bytes in/out, packets dropped per attachment
  5. ELB metrics: Healthy/unhealthy targets, latency, 5xx errors
  6. Report: Network health dashboard with any issues flagged

Workflow: Flow Log Analysis

When investigating traffic patterns or security events:

  1. Query VPC flow logs: Filter by source IP, destination IP, port, action (ACCEPT/REJECT)
  2. Identify rejected traffic: Find REJECT entries to see blocked connections
  3. Top talkers: Aggregate by source/destination to find heaviest traffic flows
  4. Time correlation: Narrow to specific time windows around incidents
  5. Report: Traffic analysis with recommendations

Common CloudWatch Network Metrics

ServiceMetricWhat It Tells You
VPNTunnelState0=down, 1=up for each tunnel
VPNTunnelDataIn/OutBytes through each VPN tunnel
NAT GWActiveConnectionCountActive NAT connections
NAT GWPacketsDropCountPackets dropped (capacity issue)
NAT GWBytesProcessedTraffic volume through NAT
TGWBytesIn/BytesOutTraffic per TGW attachment
TGWPacketDropCountBlackholeBlackhole route drops
ELBHealthyHostCountHealthy targets behind ALB/NLB
ELBTargetResponseTimeBackend latency
EC2NetworkIn/NetworkOutInstance network throughput
EC2NetworkPacketsIn/OutInstance packet rate
Show full SKILL.md (129 more words)Show less

Flow Log Query Examples

# Top rejected connections in last hour
fields @timestamp, srcAddr, dstAddr, dstPort, action
| filter action = "REJECT"
| stats count() as rejections by srcAddr, dstAddr, dstPort
| sort rejections desc
| limit 20

# Traffic from specific source
fields @timestamp, srcAddr, dstAddr, dstPort, bytes, action
| filter srcAddr = "10.0.1.50"
| sort @timestamp desc

# Top talkers by bytes
fields srcAddr, dstAddr, bytes
| stats sum(bytes) as totalBytes by srcAddr, dstAddr
| sort totalBytes desc
| limit 10

Important Rules

  • CloudWatch Logs Insights queries have a cost — be mindful of time range and data volume
  • Region-specific — metrics and logs are scoped to the configured region
  • Record in GAIT — log monitoring investigations for audit trail

Environment Variables

  • AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION (or AWS_PROFILE)

Failure Behavior

  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/aws-cloud-monitoring of automateyournetwork/netclaw.

Open the folder on GitHubat commit f943637

Compare with similar skills

AWS Cloud Monitoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Cloud Monitoring compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Cloud Monitoring this skillautomateyournetwork/netclaw677—~1kAutomated safety check: PassApache-2.0
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Review Docshashicorp/terraform-provider-aws11k—~1.3kAutomated safety check: PassMPL-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only

Similar skills

  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Review Docs

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…

    11k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Batfish Config Analysis

    automateyournetwork/netclaw

    Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking.

    676 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about AWS Cloud Monitoring

What does AWS Cloud Monitoring do?

AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance. AWS Cloud Monitoring is an agent skill from automateyournetwork/netclaw. AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

When should I use AWS Cloud Monitoring?

AWS Cloud Monitoring fits situations like: checking AWS alarms; analyzing VPC flow logs; investigating network latency; monitoring VPN and NAT Gateway metrics.

How do I install AWS Cloud Monitoring in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill aws-cloud-monitoring -a claude-code`. Or copy the skill folder (workspace/skills/aws-cloud-monitoring in automateyournetwork/netclaw) into .claude/skills/aws-cloud-monitoring in your project. Claude Code loads it when a task matches its description.

How do I install AWS Cloud Monitoring in Codex?

Run `npx skills add automateyournetwork/netclaw --skill aws-cloud-monitoring -a codex`. Or copy the skill folder (workspace/skills/aws-cloud-monitoring in automateyournetwork/netclaw) into .agents/skills/aws-cloud-monitoring in your project. Codex loads it when a task matches its description.

Can I use AWS Cloud Monitoring in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill aws-cloud-monitoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-cloud-monitoring, .gemini/skills/aws-cloud-monitoring, .github/skills/aws-cloud-monitoring and .opencode/skills/aws-cloud-monitoring in your project.

What does AWS Cloud Monitoring need to run?

Going by SKILL.md and its folder, AWS Cloud Monitoring needs the command-line tools its instructions call (uvx) and credentials named AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY. Our summary lists: A credential in AWS_SECRET_ACCESS_KEY.

Does AWS Cloud Monitoring access the network?

SKILL.md contains no URLs. Its commands use uvx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is AWS Cloud Monitoring safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Cloud Monitoring use?

AWS Cloud Monitoring is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Cloud Monitoring use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AWS Cloud Monitoring?

Skills that share tags, products or a category with AWS Cloud Monitoring: Cloud Cost Optimization (wshobson/agents, 40k stars), Review Docs (hashicorp/terraform-provider-aws, 11k stars), AWS Cdk Development (zxkane/aws-skills, 367 stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Cloud Monitoring?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 677 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 11, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.