Onboard a new GitHub repository to the ABCA platform so the agent can target it.

OfficialMIT-0Auto-check passedDevOps & Cloud

Install Onboard Repo

skills CLI
$ npx skills add aws-samples/sample-autonomous-cloud-coding-agents --skill onboard-repo -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/sample-autonomous-cloud-coding-agents onboard-repo --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/sample-autonomous-cloud-coding-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/abca-plugin/skills/onboard-repo .claude/skills/onboard-repo && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
onboard-repo
GitHub stars
158
Token cost
~2.8k tokens
SKILL.md length
1,274 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT-0

At a glance

Onboard a new GitHub repository to the ABCA platform so the agent can target it.

  • Works in 3 steps: Read cdk/src/stacks/agent.ts to find… → Add a construct following the existing… → Redeploy: mise //cdk:compile → mise…
  • The user says onboard a repo
  • SKILL.md covers Gather repository details, Path A — CLI operator…, Path B — CDK Blueprint… and Model not yet wired into the…, plus 2 more sections
  • Calls mise and aws

What it does

Onboard Repo is an agent skill from aws-samples/sample-autonomous-cloud-coding-agents, published by the product's own GitHub organization. Onboard a new GitHub repository to the ABCA platform so the agent can target it. Use when the user says "onboard a repo", "add a repository", "register a repo", "new repo", or gets a REPONOTONBOARDED / 422 error about an unregistered repository.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with GitHub and Amazon Web Services. The repository describes itself as: Autonomous background coding agents on AWS. Turn tasks into pull requests via isolated runtimes, with built-in orchestration, observability, and governance. The licence is MIT-0.

When your agent uses it

  • The user says onboard a repo
  • Add a repository
  • Register a repo
  • Gets a REPONOTONBOARDED / 422 error about an unregistered repository

Example prompts

  • “onboard a repo”
  • “add a repository”
  • “register a repo”
  • “/onboard-repo”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read cdk/src/stacks/agent.ts to find where Blueprint constructs are defined and
  2. Add a construct following the existing pattern
  3. Redeploy: mise //cdk:compile → mise //cdk:diff (show the diff) → mise //cdk:deploy -- --require-approval never.

What it can do on your machine

Read from SKILL.md and the folder at commit dfcde8d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mise
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Onboard Repo loads about 2.8k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 1,274 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/sample-autonomous-cloud-coding-agents at commit dfcde8d, republished under its MIT-0 licence (© aws-samples). 1,274 words, ~2,827 tokens.

Download SKILL.mdSave it as .claude/skills/onboard-repo/SKILL.md (or your agent's skills folder).
name
onboard-repo
description
Onboard a new GitHub repository to the ABCA platform so the agent can target it. Use when the user says "onboard a repo", "add a repository", "register a repo", "new repo", or gets a `REPO_NOT_ONBOARDED` / 422 error about an unregistered repository.

Repository Onboarding

You are helping an operator register a GitHub repository with their running ABCA deployment so tasks can target it.

There are two paths.

Prefer the CLI operator path (Path A) when the repo can run on the platform/default-blueprint setup — the default GitHub token secret, a model already granted to the runtime, and the default egress allowlist. It's a single runtime command against the deployed stack: no code change, no redeploy.

Use the CDK Blueprint path (Path B) when the repo needs its own config that the CLI can't provision at runtime — a per-repo GitHub token, a model not yet granted to the runtime, custom egress domains, Cedar HITL policies, or system-prompt overrides. These are baked into infrastructure and require a redeploy (with the correct permissions). When in doubt, start with Path A; if a task later fails on a missing token / model grant / blocked egress, promote the repo to a Blueprint.

This is an operation, not a contribution. Onboarding a repo into your own deployment writes a record to the platform's RepoTable — it is not a change to the aws-samples codebase, so the ADR-003 contribution flow (GitHub issue → approval → feature branch) does not apply. Only invoke ADR-003 if the user is actually changing the platform source (e.g. wiring a brand-new Bedrock model into the stack — see "Model not yet wired into the runtime" below).

Gather repository details

Use AskUserQuestion to collect (only the repository is required — the rest fall back to platform defaults):

  • Repository — GitHub owner/repo. Must match exactly what's passed to bgagent submit --repo later.
  • Compute type — agentcore (default) or ecs.
  • Model — default is the platform model (Opus 5). The geo prefix in the examples below (global.) must match the deployment's bedrockGeoRegion; bgagent repo onboard rejects a mismatch at the CLI rather than letting the task fail at turn 0. If overriding, it must be a model already granted to the runtime (see "Model not yet wired into the runtime"), specified as a cross-Region inference-profile ID (e.g. global.anthropic.claude-opus-5), not a raw anthropic.* foundation-model ID.
  • Max turns — default 100 (range 1–500).
  • Per-repo GitHub token — only if this repo needs a different token than the platform default (provide its Secrets Manager ARN).

Per-task cost limits aren't set here. max_budget / max_turns per task are flags on bgagent submit (the submit-task skill), not repo-onboarding fields. Onboarding sets only the per-repo default max_turns.

If the repo needs config the CLI can't provision (per-repo egress, Cedar policies, system-prompt overrides, or a not-yet-granted model), use Path B instead.

Path A — CLI operator onboarding (default)

bgagent repo onboard writes (or re-activates) the repository's RepoConfig row in the deployed RepoTable directly. It takes effect immediately — no agent.ts edit, no cdk deploy.

bash
bgagent repo onboard <owner/repo>
# common overrides:
#   --model <inference-profile-id>     e.g. global.anthropic.claude-opus-5 (must be runtime-granted)
#   --compute-type <agentcore|ecs>
#   --max-turns <n>                    per-repo default turn limit
#   --token-secret-arn <arn>           per-repo GitHub token (else platform default)
#   --runtime-arn <arn>                override AgentCore runtime ARN (agentcore only)
#   --poll-interval <ms>               agent completion poll interval

Then confirm it landed:

bash
bgagent repo list                 # status should be "active"
bgagent repo show <owner/repo>    # full resolved config (secret ARNs redacted)

That's it — the repo is onboarded. Submit a task with the submit-task skill.

Pick a model that is already wired into the runtime. With no --model, the repo uses the platform default — read it from the stack's BedrockGeoRegion + BedrockModelIds outputs rather than a literal here. If you pass --model, use a cross-Region inference profile ID (e.g. global.anthropic.claude-opus-5), not a raw anthropic.* foundation-model ID. Only models the stack has granted the runtime can be invoked — see "Model not yet wired into the runtime" before choosing a model the deployment doesn't already support.

Path B — CDK Blueprint (declarative / canonical)

Use this when the operator wants the repo committed to infrastructure-as-code (so a fresh deploy re-creates it) rather than set as a runtime record. This does require editing the stack and redeploying.

  1. Read cdk/src/stacks/agent.ts to find where Blueprint constructs are defined and the repoTable reference.

  2. Add a construct following the existing pattern:

    typescript
    new Blueprint(this, 'MyRepoBlueprint', {
      repo: 'owner/repo',
      repoTable: repoTable.table,
      // Optional overrides:
      // computeType: 'agentcore',
      // modelId: 'global.anthropic.claude-opus-5',
      // maxTurns: 100,
      // maxBudgetUsd: 50,
      // githubTokenSecretArn: 'arn:aws:secretsmanager:...',
    });
  3. Redeploy: mise //cdk:compile → mise //cdk:diff (show the diff) → mise //cdk:deploy -- --require-approval never.

Sample-repo shortcut: the stack's AgentPlugins blueprint resolves its repo from BLUEPRINT_REPO (env) → CDK context blueprintRepo → default awslabs/agent-plugins. To target a fork of the sample without adding a construct, set export BLUEPRINT_REPO=owner/repo (or cdk.json context) and redeploy.

Show full SKILL.md (625 more words)Show less

Model not yet wired into the runtime (the one real code change)

A repo can only use a model the runtime IAM role has grantInvoke for. The granted set is DEFAULT_BEDROCK_MODEL_IDS in cdk/src/handlers/shared/bedrock-model-constants.ts — Sonnet 4.6, Opus 4.8, Opus 5, and Haiku 4.5 — and a deployed stack publishes it as the BedrockModelIds output, so read that rather than trusting this list to stay current:

bash
aws cloudformation describe-stacks --stack-name <stack> \
  --query "Stacks[0].Outputs[?OutputKey=='BedrockModelIds'].OutputValue" --output text

Onboarding a repo pinned to any other model fails at invoke with a 403 — the CLI onboard succeeds, but tasks can't run. bgagent repo onboard --model checks the value against that output and rejects an ungranted model up front.

Pin the geo-prefixed inference-profile form, matching the stack's BedrockGeoRegion output (e.g. global.anthropic.claude-opus-4-8), not the bare id — Bedrock refuses bare ids for on-demand invocation, and the IAM grant is scoped to one geography's profile ARNs.

Granting a new model is a deploy-time change, not a construct edit: the list is overridable via CDK context, either on the command line or in cdk.json. Both forms behave identically — the resolver JSON-parses the string -c delivers.

bash
cdk deploy -c bedrockModels='["anthropic.claude-opus-5","anthropic.claude-haiku-4-5-20251001-v1:0","anthropic.claude-sonnet-4-6"]'

The override REPLACES the default list rather than adding to it, so it must include the two models the stack injects as ANTHROPIC_MODEL and ANTHROPIC_DEFAULT_HAIKU_MODEL — Opus 5 and Haiku 4.5. Omitting either fails at synth, naming the missing model, because every substrate is told to invoke them regardless of this list. (--context-file does not work for this: it is accepted and silently ignored.)

For a persistent setting, put the same array in the context block of cdk.json:

jsonc
// cdk.json — this REPLACES the default list, so include the platform defaults
// (Opus 5 + Haiku 4.5) or the stack's own defaults are ungranted
"context": {
  "bedrockModels": [
    "anthropic.claude-opus-5",
    "anthropic.claude-haiku-4-5-20251001-v1:0",
    "anthropic.claude-sonnet-4-6"
  ]
}

Three constraints on the value. Entries are bare ids — the geo prefix is derived from bedrockGeoRegion, and a prefixed entry is rejected. Patterns are rejected too: these ids become the resource half of the IAM grant, so a * would grant every inference profile in the account. And each entry must have a live cross-Region inference profile:

bash
aws bedrock get-inference-profile --inference-profile-identifier <geo>.<model>

A granted model with no profile is the trap — it passes the CLI's --model check and workflow admission (both read the grant list) and only fails at turn 0. bgagent platform doctor checks the whole granted set for exactly this and names any model that does not resolve.

Account-level Bedrock model access is separate from IAM: the account must have the model enabled for the Region — complete model access prerequisites (Marketplace actions / Anthropic first-time use where applicable). For cross-Region profiles, IAM and SCPs must allow Bedrock in source and destination Regions.

If the user just wants the agent working now, leave model_id unset so the repo takes the platform default, and treat "add model X" as a separate, later change.

Per-repository configuration reference

SettingPurposeDefault
compute_typeExecution strategyagentcore
runtime_arnAgentCore runtime overridePlatform default
model_idAI model for tasks (inference profile ID)Platform default (Opus 5, as <BedrockGeoRegion>.anthropic.claude-opus-5)
max_turnsTurn limit per task100
max_budget_usdCost ceiling per taskUnlimited
system_prompt_overridesCustom system instructionsNone
github_token_secret_arnRepo-specific GitHub tokenPlatform default
poll_interval_msCompletion polling frequency30000ms

Task-level parameters override per-repo defaults; if neither specifies a value, platform defaults apply.

Common issues

  • REPO_NOT_ONBOARDED / 422 — the repo isn't registered. Run bgagent repo onboard <owner/repo> (Path A). Confirm the owner/repo matches exactly what you pass to bgagent submit --repo.
  • Preflight failure after onboarding — the GitHub PAT lacks access to the new repo. Ensure the token has Contents (read/write) + Pull requests (read/write) on it, or onboard with a repo-specific --token-secret-arn.
  • 400 "Invocation with on-demand throughput isn't supported" — model_id is a raw foundation-model ID; use the inference-profile ID (e.g. global.anthropic.claude-opus-5).
  • 403 "not authorized to perform bedrock:InvokeModelWithResponseStream" — the repo's model isn't wired into the runtime. See "Model not yet wired into the runtime."
  • Model not available / "not available on your Bedrock deployment" — account-level Bedrock access isn't enabled for that model/Region (separate from IAM); complete model access, then use an enabled inference-profile ID.

© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/abca-plugin/skills/onboard-repo of aws-samples/sample-autonomous-cloud-coding-agents.

Open the folder on GitHubat commit dfcde8d

Compare with similar skills

Onboard Repo next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Onboard Repo compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Onboard Repo this skillaws-samples/sample-autonomous-cloud-coding-agents158—~2.8kAutomated safety check: PassMIT-0
Update Provider Depsmondoohq/mql412—~4.5kAutomated safety check: PassCustom licence
Secrets Managementdavila7/claude-code-templates33k12 repos~2kAutomated safety check: PassMIT
Phase 9 Deploymentww-w-ai/bkit-claude-code601—~2.7kAutomated safety check: NotesApache-2.0
AWS Cost Optimizegithub/awesome-copilot40k—~2kAutomated safety check: PassMIT
AWS Well Architected Reviewgithub/awesome-copilot40k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Upgrade an mql provider's vendored SDKs (all providers or a named subset), audit the new versions for breaking changes and fix call sites while keeping shipped MQL fields backwards-compatible, check…

    412 GitHub stars~4.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    33k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Phase 9 Deployment

    ww-w-ai/bkit-claude-code

    Deploy to production — CI/CD pipelines, environment config, deployment strategies.

    601 GitHub stars~2.7k tokensUpdated 14 days ago
    DevOps & CloudAuto-check: notes
  • AWS Cost Optimize

    github/awesome-copilot

    Official

    Analyze AWS resources used in the app (IaC files and/or resources in a target account/region) and optimize costs - creating GitHub issues for identified optimizations.

    40k GitHub stars~2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • AWS Well Architected Review

    github/awesome-copilot

    Official

    Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

    40k GitHub stars~1.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM.

    360 GitHub stars~1.6k tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed

More from aws-samples/sample-autonomous-cloud-coding-agents

  • Deploy

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Deploy, diff, or destroy the ABCA CDK stack. An agent skill from aws-samples/sample-autonomous-cloud-coding-agents.

    158 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Setup

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Guided installation and first-time setup for ABCA. An agent skill from aws-samples/sample-autonomous-cloud-coding-agents.

    158 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Submit Task

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Submit a coding task to the ABCA platform via CLI or REST API.

    158 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Troubleshoot

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Diagnose and fix common ABCA issues: deployment failures, preflight errors, authentication problems, agent failures, and build issues.

    158 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Status

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Check ABCA platform status — stack health, running tasks, and recent task history.

    158 GitHub stars~438 tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Onboard Repo

What does Onboard Repo do?

Onboard a new GitHub repository to the ABCA platform so the agent can target it. Onboard Repo is an agent skill from aws-samples/sample-autonomous-cloud-coding-agents, published by the product's own GitHub organization. Onboard a new GitHub repository to the ABCA platform so the agent can target it.

When should I use Onboard Repo?

Onboard Repo fits situations like: the user says onboard a repo; add a repository; register a repo; gets a REPONOTONBOARDED / 422 error about an unregistered repository.

How do I install Onboard Repo in Claude Code?

Run `npx skills add aws-samples/sample-autonomous-cloud-coding-agents --skill onboard-repo -a claude-code`. Or copy the skill folder (docs/abca-plugin/skills/onboard-repo in aws-samples/sample-autonomous-cloud-coding-agents) into .claude/skills/onboard-repo in your project. Claude Code loads it when a task matches its description.

How do I install Onboard Repo in Codex?

Run `npx skills add aws-samples/sample-autonomous-cloud-coding-agents --skill onboard-repo -a codex`. Or copy the skill folder (docs/abca-plugin/skills/onboard-repo in aws-samples/sample-autonomous-cloud-coding-agents) into .agents/skills/onboard-repo in your project. Codex loads it when a task matches its description.

Can I use Onboard Repo in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/sample-autonomous-cloud-coding-agents --skill onboard-repo -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/onboard-repo, .gemini/skills/onboard-repo, .github/skills/onboard-repo and .opencode/skills/onboard-repo in your project.

What does Onboard Repo need to run?

Going by SKILL.md and its folder, Onboard Repo needs the command-line tools its instructions call (mise and aws).

Does Onboard Repo access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Onboard Repo safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Onboard Repo use?

Onboard Repo is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Onboard Repo use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Onboard Repo?

Skills that share tags, products or a category with Onboard Repo: Update Provider Deps (mondoohq/mql, 412 stars), Secrets Management (davila7/claude-code-templates, 33k stars), Phase 9 Deployment (ww-w-ai/bkit-claude-code, 601 stars) and AWS Cost Optimize (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Onboard Repo?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/sample-autonomous-cloud-coding-agents, which has 158 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 10, 2026.

Source: aws-samples/sample-autonomous-cloud-coding-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.