Agent skill

Well Architected

by avelikiy in avelikiy/great_cto

6-pillar architecture review framework. An agent skill from avelikiy/great_cto.

MITAuto-check passedDevOps & Cloud

Install Well Architected

skills CLI
$ npx skills add avelikiy/great_cto --skill well-architected -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install avelikiy/great_cto well-architected --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/well-architected .claude/skills/well-architected && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
well-architected
GitHub stars
102
Token cost
~1.6k tokens
SKILL.md length
660 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

6-pillar architecture review framework. An agent skill from avelikiy/great_cto.

  • Works in 3 steps: Observability: What metrics, logs,… → Deployability: How do we ship a change?… → Runbooks: When this breaks at 3am, what…
  • Tasks that involve Cloud architecture
  • SKILL.md covers Pillar 1 — Operational…, Pillar 2 — Security, Pillar 3 — Reliability and Pillar 4 — Performance…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Well Architected is an agent skill from avelikiy/great_cto. 6-pillar architecture review framework. Adapted from AWS Well-Architected for use by greatcto's architect agent on every non-nano ARCH document. Forces explicit answers across operational excellence, security, reliability, performance, cost, and sustainability — not just feature design.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud architecture and Software architecture. It works with Amazon Web Services. The repository describes itself as: You already have the agent. This is everything around it. greatcto runs Claude Code as a pipeline of 70 specialist agents — an independent model checks each stage before the next… The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud architecture
  • Tasks that involve Software architecture

Example prompts

  • “/well-architected”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Grep, Glob

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Observability: What metrics, logs, traces do we emit? How do we
  2. Deployability: How do we ship a change? CI gates? Rollback path?
  3. Runbooks: When this breaks at 3am, what does on-call read?

What it can do on your machine

Read from SKILL.md and the folder at commit 97dd037. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Well Architected loads about 1.6k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 660 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from avelikiy/great_cto at commit 97dd037, republished under its MIT licence (© avelikiy). 660 words, ~1,600 tokens.

Download SKILL.mdSave it as .claude/skills/well-architected/SKILL.md (or your agent's skills folder).
name
well-architected
description
6-pillar architecture review framework. Adapted from AWS Well-Architected for use by great_cto's architect agent on every non-nano ARCH document. Forces explicit answers across operational excellence, security, reliability, performance, cost, and sustainability — not just feature design.
allowed-tools
Read, Write, Grep, Glob
when_to_use
Apply when: - architect is writing ARCH-*.md for small/medium/large/enterprise project_size - regulated-reviewer or security-officer is auditing an existing…
effort
high
paths
docs/architecture/**, docs/decisions/**, src/**

Well-Architected — 6 pillars to verify before shipping

Every ARCH document for non-nano work must answer the 6 pillar questions below. Skipping a pillar is allowed only if explicitly justified (e.g. "Sustainability: N/A — backend-only, runs in shared infra.").

This is adapted from AWS Well-Architected (lens: small-team SaaS / LLM applications), trimmed to questions that matter at <10 engineer scale.

Pillar 1 — Operational excellence

Questions
  1. Observability: What metrics, logs, traces do we emit? How do we tell from a dashboard if this is working in prod?
  2. Deployability: How do we ship a change? CI gates? Rollback path?
  3. Runbooks: When this breaks at 3am, what does on-call read?
Pass criteria
  • ✅ One metric per business outcome (e.g. webhook-deliveries-acked)
  • ✅ One log line per request, with request-id correlatable across services
  • ✅ Deploy path is documented and tested (rollback dry-run executed)
  • ✅ Runbook covers top-3 failure modes from pre-mortem
Common fail

❌ "We'll add monitoring later." Monitoring is part of the feature.

Pillar 2 — Security

Questions
  1. Trust boundaries: Where does untrusted data enter? How is it validated/sanitized?
  2. Authn / authz: Who can call this? Who can read/write the data?
  3. Secrets: Where are API keys, DB passwords, JWT signing keys stored?
  4. Data classification: PII? PHI? PCI cardholder data? What's the retention policy?
Pass criteria
  • ✅ Every external input has explicit validation at the boundary
  • ✅ Authz is enforced at the data layer, not just UI
  • ✅ Secrets in env vars or secret manager, never in source
  • ✅ Sensitive data classified and retention policy defined
Common fail

❌ "JWT validates the user, that's our authz." JWT is authentication. Authorization is separate (this user can read THIS row).

Pillar 3 — Reliability

Questions
  1. Failure modes: What happens when a downstream dependency is slow / down / corrupted?
  2. Idempotency: Can a retried request safely re-execute?
  3. Backups & recovery: What's the RPO (data-loss tolerance)? RTO (downtime tolerance)? Test plan for both?
  4. Capacity: What's the max QPS this can handle? What happens at 1.5x that?
Pass criteria
  • ✅ Circuit breakers / timeouts on external calls
  • ✅ State-mutating endpoints accept idempotency keys
  • ✅ Backups documented + restore tested in the last 90 days
  • ✅ Load test exists; results in docs/perf/
Common fail

❌ "Postgres has backups." Backups without a tested restore aren't backups.

Pillar 4 — Performance efficiency

Questions
  1. SLOs: What's the p50/p95/p99 latency target? Error rate? Availability?
  2. Bottlenecks: Profile the critical path — what's the slowest step?
  3. Caching: What's cacheable? Cache invalidation strategy?
  4. Scaling: Vertical or horizontal? Auto-scale rules?
Show full SKILL.md (262 more words)Show less
Pass criteria
  • ✅ SLO numbers in the ARCH doc (not "fast enough")
  • ✅ Profile attached for non-trivial requests
  • ✅ Cache strategy documented; invalidation explicit
  • ✅ Scaling decision justified by data, not "feels right"
Common fail

❌ "Database can handle it." Quantify: queries/sec, row count, index hit rate.

Pillar 5 — Cost optimization

Questions
  1. Hot path: What's the most expensive operation per request? Why?
  2. Right-sizing: Is the chosen instance type / model / DB tier the smallest one that meets SLO?
  3. Cleanup: What happens to old data? Old logs? Old branch environments?
Pass criteria
  • ✅ Use skill cost-model to document explicit $ numbers
  • ✅ Choose smallest LLM model that meets quality SLO (haiku before sonnet, sonnet before opus)
  • ✅ Retention policy for logs, metrics, old data
Common fail

❌ Defaulting to Opus / GPT-4 when Haiku would work. Test on Haiku first.

Pillar 6 — Sustainability (env / energy)

Questions
  1. Workload efficiency: Is the code O(n log n) when it could be O(n)?
  2. Idle resources: Can dev environments scale to zero overnight?
  3. Data minimization: Do we collect / store data we never query?
Pass criteria
  • ✅ Hot loop complexity documented
  • ✅ Non-prod resources have shutdown schedules
  • ✅ Data lifecycle covers ingestion, retention, deletion
Common fail

❌ Logs at debug level in prod, never reviewed. Waste of storage + carbon.

Output format — add to ARCH

markdown
## Well-Architected review

### 1. Operational excellence
- Metrics: <list>
- Deploy path: <link to runbook>
- Verdict: PASS | RISKS LISTED

### 2. Security
- Trust boundaries: <list>
- Data classification: <PII / PHI / PCI / none>
- Verdict: PASS | RISKS LISTED

### 3. Reliability
- Failure modes: <link to pre-mortem>
- Idempotency: <yes/no per endpoint>
- Verdict: PASS | RISKS LISTED

### 4. Performance
- SLOs: p99=<ms>, error_rate=<%>, availability=<%>
- Verdict: PASS | RISKS LISTED

### 5. Cost
- Per-request cost: $<amount>
- Verdict: PASS | RISKS LISTED

### 6. Sustainability
- Hot-path complexity: O(<n>)
- Verdict: PASS | N/A | RISKS LISTED

## Open risks (rolled up)

<bullet list of all RISKS LISTED items + mitigation in plan>

When PASS is acceptable with risks listed

Not every architecture is bulletproof. PASS-with-risks is OK if:

  • Each risk is explicit (not hand-waved)
  • Each risk has either a mitigation in the plan OR explicit acceptance by the user
  • The pre-mortem section addresses the top-3 risk-score items

Gate:plan can approve a PASS-with-risks; gate:ship needs the mitigations shipped.

© avelikiy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/well-architected of avelikiy/great_cto.

Open the folder on GitHubat commit 97dd037

Compare with similar skills

Well Architected next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Well Architected compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Well Architected this skillavelikiy/great_cto102—~1.6kAutomated safety check: PassMIT
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Thesvgglincker/thesvg2.8k—~1.5kAutomated safety check: PassMIT
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0
AWS Architecture Diagramvidanov/aws-architecture-diagram-skill159—~4.9kAutomated safety check: PassMIT

Similar skills

  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • AWS Architecture Diagram

    vidanov/aws-architecture-diagram-skill

    Generate AWS architecture diagrams in draw.io format. An agent skill from vidanov/aws-architecture-diagram-skill.

    159 GitHub stars~4.9k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Configure secure, high-performance connectivity between on-premises infrastructure and cloud platforms using VPN and dedicated connections.

    40k GitHub starsUsed in 11 repos~1.5k tokens
    DevOps & CloudAuto-check passed

More from avelikiy/great_cto

All 27 skills in this repo
  • AnyDesign Design Analyzer

    avelikiy/great_cto

    Analyzes a screenshot, website or Figma file and writes a `design.md` with its token system, component inventory and reconstruction notes, or an `element.md` for one element.

    103 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Opportunity Solution Tree

    avelikiy/great_cto

    Builds an Opportunity Solution Tree that links one measurable outcome to customer opportunities, candidate solutions and experiments.

    103 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Rewrites a feature-list roadmap into outcome statements that name the customer segment, the result they get and the business impact, grouped into themes.

    103 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Exposed Secret Rotation

    avelikiy/great_cto

    Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.

    103 GitHub stars~884 tokensUpdated today
    Auto-check: notes
  • Skeptical Triage

    avelikiy/great_cto

    Runs a three-round self-challenge plus an arbiter over high-stakes findings, so false positives from reviews, audits and flaky-test verdicts do not become blockers.

    103 GitHub stars~2.1k tokensUpdated today
    Auto-check: notes
  • Aesthetic Instrument

    avelikiy/great_cto

    greatcto's own committed aesthetic — the instrument panel. An agent skill from avelikiy/great_cto.

    103 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Well Architected

What does Well Architected do?

6-pillar architecture review framework. An agent skill from avelikiy/great_cto. Well Architected is an agent skill from avelikiy/great_cto. 6-pillar architecture review framework.

When should I use Well Architected?

Well Architected fits situations like: tasks that involve Cloud architecture; tasks that involve Software architecture.

How do I install Well Architected in Claude Code?

Run `npx skills add avelikiy/great_cto --skill well-architected -a claude-code`. Or copy the skill folder (skills/well-architected in avelikiy/great_cto) into .claude/skills/well-architected in your project. Claude Code loads it when a task matches its description.

How do I install Well Architected in Codex?

Run `npx skills add avelikiy/great_cto --skill well-architected -a codex`. Or copy the skill folder (skills/well-architected in avelikiy/great_cto) into .agents/skills/well-architected in your project. Codex loads it when a task matches its description.

Can I use Well Architected in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add avelikiy/great_cto --skill well-architected -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/well-architected, .gemini/skills/well-architected, .github/skills/well-architected and .opencode/skills/well-architected in your project.

What does Well Architected need to run?

SKILL.md names no scripts, command-line tools or credentials: Well Architected is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Grep, Glob.

Does Well Architected access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Well Architected safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Well Architected use?

Well Architected is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Well Architected use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Well Architected?

Skills that share tags, products or a category with Well Architected: Cloud Cost Optimization (wshobson/agents, 40k stars), Thesvg (glincker/thesvg, 2.8k stars), AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars) and Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Well Architected?

avelikiy (a GitHub user) maintains it in avelikiy/great_cto, which has 102 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 9, 2026.

Source: avelikiy/great_cto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.