Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…

OfficialMIT-0Auto-check passedAI & LLM Engineering

Install Wa Guardrails

skills CLI
$ npx skills add aws-samples/sample-well-architected-skills-and-steering --skill wa-guardrails -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/sample-well-architected-skills-and-steering wa-guardrails --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/sample-well-architected-skills-and-steering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wa-guardrails .claude/skills/wa-guardrails && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wa-guardrails
GitHub stars
275
Token cost
~2.8k tokens
SKILL.md length
1,054 words
Files
4
Skills in repo
5
Repo updated
First seen
Licence
MIT-0

At a glance

Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…

  • Works in 6 steps: Gather context → Discovery — what to enforce → Select preventive vs. detective for each… → …
  • The user wants to enforce best practices in CI
  • SKILL.md covers Step 1: Gather context, Step 2: Discovery — what to…, Step 3: Select preventive vs.… and Step 4: Generate the controls, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Wa Guardrails is an agent skill from aws-samples/sample-well-architected-skills-and-steering, published by the product's own GitHub organization. Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) — plus an optional governance steering doc, so a workload stays aligned with Well-Architected best practices over time instead of being assessed once. Use when the user wants to enforce best practices in CI, prevent insecure or non-compliant configurations from shipping, detect configuration drift, codify the fixes from…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `evals/evals.json`, `evals/triggering.json` and `metadata.json`).

It sits in AI & LLM Engineering, covering Cloud architecture, LLM guardrails and Spec-driven development. It works with Amazon Web Services. The repository describes itself as: Reusable skills and steering that teach AI coding agents how to apply the AWS Well-Architected Framework. One set of playbooks, 14 supported tools. The licence is MIT-0.

When your agent uses it

  • The user wants to enforce best practices in CI
  • Prevent insecure
  • Non-compliant configurations from shipping
  • Detect configuration drift

Example prompts

  • “/wa-guardrails”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Gather context
  2. Discovery — what to enforce
  3. Select preventive vs. detective for each control
  4. Generate the controls
  5. Produce the guardrails plan
  6. Offer follow-up

What it can do on your machine

Read from SKILL.md and the folder at commit e81835b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml, typescript and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wa Guardrails loads about 2.8k tokens when it runs. Until then it costs about 164 tokens; SKILL.md has 1,054 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~164
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/sample-well-architected-skills-and-steering at commit e81835b, republished under its MIT-0 licence (© aws-samples). 1,054 words, ~2,826 tokens.

Download SKILL.mdSave it as .claude/skills/wa-guardrails/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
wa-guardrails
description
Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) — plus an optional governance steering doc, so a workload stays aligned with Well-Architected best practices over time instead of being assessed once. Use when the user wants to enforce best practices in CI, prevent insecure or non-compliant configurations from shipping, detect configuration drift, codify the fixes from a Well-Architected review as ongoing controls, or capture standards as an always-on steering file for their AI coding agent.
version
1.0.0

Well-Architected Guardrails

This skill generates preventive and detective controls that keep a workload Well-Architected over time. Unlike the assessment skills (which find gaps) or remediation (which fixes a specific finding once), guardrails codify best practices so non-compliant changes are blocked or flagged automatically — in CI, at deploy time, and continuously in the account.

What you'll produce: ready-to-commit control files (Config rules, SCPs, CI policy checks, alarms), each tied to the WA Question/Best Practice ID it enforces, with a note on whether the control is preventive (blocks the bad change) or detective (flags it after the fact).

Step 1: Gather context

Ask the user (skip any already provided or inferable from the codebase):

I can generate guardrails to keep your workload Well-Architected. Let me know:

  • Workload name and code packages/directories (IaC, CI/CD configs)
  • IaC dialect: CDK (which language), CloudFormation, Terraform, SAM, or mixed
  • Source of controls: a prior /aws-well-architected-framework-review or assessment output, specific concerns, or "scan and propose"
  • Enforcement points available: CI pipeline (which one), AWS Organizations/SCPs, AWS Config, account-level admin — so controls target what you can actually deploy
  • Pillars to prioritize (optional; default: Security and Reliability)

If you are in a codebase, proceed directly and infer the IaC dialect and CI system from the files present.

Step 2: Discovery — what to enforce

Determine the controls to generate from one of two inputs:

Path A — From an assessment (preferred): parse the prior review for findings, their pillar, severity, evidence (file:line), and the Best Practice IDs cited. Each High/Critical finding becomes a candidate guardrail so the same gap cannot recur.

Path B — Standalone scan: analyze the IaC and identify the control-worthy configurations actually in use — storage encryption, public access, IAM scope, multi-AZ, backups, logging, TLS, tagging. Map each to the WA Best Practice it relates to.

Produce a control candidate list: for each, record the pillar, the WA Question/BP ID, the resource type it applies to, the current state (compliant / non-compliant / absent), and the enforcement point that fits (CI check, Config rule, SCP, alarm).

Step 3: Select preventive vs. detective for each control

For every candidate, choose the strongest control the user's enforcement points allow. Prefer preventive (stops the bad change before it ships) over detective (catches it afterward). Use this decision guidance:

  • Can the misconfiguration be caught in IaC before deploy? → CI policy check (CDK Aspect, cfn-guard/cfn-lint, Terraform OPA/Sentinel). Strongest and cheapest.
  • Must it be blocked org-wide regardless of who deploys? → SCP or permission boundary.
  • Is it only observable on the live resource (e.g. drift, runtime state)? → AWS Config rule (detective; add auto-remediation only if the user confirms).
  • Is it a continuous reliability/cost/performance signal? → CloudWatch metric + alarm.

If a control cannot be enforced with the available points, say so explicitly rather than emitting a control that won't run.

Step 4: Generate the controls

Generate every selected control as ready-to-commit code in the workload's existing dialect and conventions. Each control MUST:

  • Cite the WA Question/BP ID it enforces (e.g. SEC 8, REL 9)
  • Be labeled 🛡️ Preventive or 🔍 Detective
  • Include a one-line statement of what it blocks/flags and why it matters

Cover, as applicable to the workload:

Security (SEC) — examples: s3-bucket-server-side-encryption-enabled, s3-bucket-public-read-prohibited, iam-policy-no-statements-with-admin-access (Config); SCP denying creation of unencrypted resources or disabling CloudTrail; a CDK Aspect failing synth on a security group open to 0.0.0.0/0 on non-web ports.

Reliability (REL) — rds-multi-az-support, dynamodb-pitr-enabled, db-instance-backup-enabled (Config); a cfn-guard rule requiring DeletionProtection on stateful resources; an alarm on DLQ depth.

Operational Excellence (OPS) — a CI check requiring tags (owner, cost-center, environment); a Config rule for required CloudWatch log retention; an SCP preventing manual changes outside IaC.

Cost (COST) — a CI check flagging instance types or capacity modes outside an approved list; a budget/anomaly alarm.

Performance / Sustainability (PERF/SUS) — a CI check preferring Graviton/managed services where applicable.

Provide each control's snippet in a fenced code block with the target filename, so the user can commit it directly. Match the workload's dialect — examples of the three most common forms:

Detective — AWS Config managed rule (SEC 8, encryption at rest), CloudFormation:

yaml
# guardrails/config-rules.yaml
Resources:
  S3EncryptionEnabled:                      # 🔍 Detective — flags any S3 bucket without SSE
    Type: AWS::Config::ConfigRule
    Properties:
      ConfigRuleName: s3-bucket-server-side-encryption-enabled
      Source: { Owner: AWS, SourceIdentifier: S3_BUCKET_SERVER_SIDE_ENCRYPTION_ENABLED }

Preventive — CDK Aspect (SEC 5, no open security groups), TypeScript:

typescript
// guardrails/no-open-sg.aspect.ts
import { IAspect, Annotations } from "aws-cdk-lib";
import { CfnSecurityGroupIngress } from "aws-cdk-lib/aws-ec2";
import { IConstruct } from "constructs";

// 🛡️ Preventive — fails `cdk synth` on 0.0.0.0/0 ingress to non-web ports
export class NoOpenIngress implements IAspect {
  visit(node: IConstruct): void {
    if (node instanceof CfnSecurityGroupIngress &&
        node.cidrIp === "0.0.0.0/0" && ![80, 443].includes(Number(node.fromPort))) {
      Annotations.of(node).addError(`SEC 5: security group open to 0.0.0.0/0 on port ${node.fromPort}`);
    }
  }
}

Preventive — cfn-guard rule (REL 9, stateful resources need deletion protection):

# guardrails/reliability.guard
# 🛡️ Preventive — blocks RDS instances without Multi-AZ + deletion protection
AWS::RDS::DBInstance {
  Properties { MultiAZ == true  DeletionProtection == true }
}
Show full SKILL.md (384 more words)Show less

Step 5: Produce the guardrails plan

Output a structured deliverable:

markdown
# Well-Architected Guardrails: {Workload Name}

## Summary
- **IaC dialect**: {CDK/CloudFormation/Terraform/SAM}
- **Enforcement points used**: {CI / Config / SCP / alarms}
- **Source**: {prior review / standalone scan}
- **Controls generated**: {N} ({P} preventive, {D} detective) across {pillars}

## Controls by pillar

### {Pillar} — {WA Question/BP ID}
- **Control**: {name}  |  🛡️ Preventive / 🔍 Detective  |  Enforcement: {CI / Config / SCP / alarm}
- **Blocks/flags**: {what, and why it matters}
- **File**: `{path}`
  ```{lang}
  {ready-to-commit snippet}
  • Coverage gap (if any): {what this control does NOT catch}

Rollout plan

OrderControlEnforcementRisk of false-positiveNotes
{Start in warn/log mode for preventive CI checks and SCPs, then promote to block once clean.}

Verification

{How to confirm each control works — e.g. attempt a known-bad change in a branch and confirm CI fails; check Config rule compliance status.}

Not covered

{Controls the available enforcement points cannot implement, and what would be needed.}


## Step 6: Offer a governance steering doc

Beyond machine-enforced controls, offer to capture the same standards as a **human- and agent-readable governance doc** — the prose counterpart to the guardrails. This is useful for the standards a control can't fully express (design conventions, review expectations) and for teams that want an always-on policy their AI coding agent will follow.

Generate it on request as a steering file the agent loads automatically (e.g. `.kiro/steering/`, `CLAUDE.md`, `.cursor/rules/`), structured as:

```markdown
# {Workload} — Well-Architected Guardrails (Governance)

## Enforced automatically
{One line per machine control, linking the rule file and its WA BP ID — so readers know what is already gated in CI/Config.}

## Conventions to follow (not auto-enforced)
- {Pillar} — {convention}, because {WA BP ID rationale}. {How a reviewer/agent checks it.}

## When proposing or reviewing changes to this workload
- {Standing instruction, e.g. "new data stores MUST set encryption + backups before merge (SEC 8 / REL 9)"}

Keep each statement tied to a WA Question/BP ID, and keep the doc short enough to live in always-on context without bloat.

Step 7: Offer follow-up

Would you like me to:

  • Generate the CI workflow wiring (GitHub Actions / CodePipeline step) to run the policy checks?
  • Produce a governance steering doc (CLAUDE.md / .cursor/rules/ / .kiro/steering/) capturing these standards for your AI agent?
  • Add auto-remediation to a detective Config rule (with safety review)?
  • Fix the existing violations these guardrails would block (remediate the current code)?
  • Tighten a control from warn mode to block mode?

Calibration Guidance

  • Prefer preventive controls (catch in CI/IaC) over detective — they're cheaper and stop the problem before it ships; only fall back to detective when the issue is only visible on the live resource.
  • Never emit a control for an enforcement point the user doesn't have — say it's not enforceable and what's needed instead.
  • Roll out preventive controls in warn/log mode first. Recommending a hard block or Deny SCP on day one risks breaking existing pipelines — flag this and stage it.
  • Auto-remediation is destructive: only generate it when the user explicitly asks, and include a safety/rollback note.
  • Tie every control to a WA Question/BP ID so the builder can trace the rationale — a guardrail without a "why" gets disabled the first time it's inconvenient.
  • Don't over-generate: a focused set of high-value controls that the team will keep beats 50 noisy rules they'll mute.
  • Respect the workload's existing dialect and conventions — emit CDK Aspects for a CDK app, cfn-guard for CloudFormation, OPA/Sentinel for Terraform; don't mix paradigms.
  • The governance steering doc complements controls, it doesn't replace them — prefer a machine-enforced control whenever one exists, and use the doc for what code can't express. Keep it concise enough for always-on context.
<!--
Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
SPDX-License-Identifier: MIT-0
-->

© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in skills/wa-guardrails of aws-samples/sample-well-architected-skills-and-steering.

  • SKILL.md
  • evals/evals.json
  • evals/triggering.json
  • metadata.json

Open the folder on GitHubat commit e81835b

Compare with similar skills

Wa Guardrails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wa Guardrails compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wa Guardrails this skillaws-samples/sample-well-architected-skills-and-steering275—~2.8kAutomated safety check: PassMIT-0
Cloud Securityborghei/Claude-Skills891—~3.5kAutomated safety check: PassMIT
GCP To AWSaws/agent-toolkit-for-aws2.8k—~15kAutomated safety check: PassApache-2.0
Hardening Cloud Posturetrilwu/secskills157—~1.9kAutomated safety check: PassMIT
Investigation Cost Guardrailaws/tools-for-devops-agent103—~4.5kAutomated safety check: PassApache-2.0
Ak Add Capabilitiesyaalalabs/agent-kernel192—~13kAutomated safety check: PassApache-2.0

Similar skills

  • Cloud Security

    borghei/Claude-Skills

    Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.

    891 GitHub stars~3.5k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • GCP To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Google Cloud Platform to AWS — plus AI and agentic workloads from any provider.

    2.8k GitHub stars~15k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Hardening Cloud Posture

    trilwu/secskills

    Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

    157 GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Investigation Cost Guardrail

    aws/tools-for-devops-agent

    Official

    Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools.

    103 GitHub stars~4.5k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Ak Add Capabilities

    yaalalabs/agent-kernel

    Add capabilities to an existing Agent Kernel project. An agent skill from yaalalabs/agent-kernel.

    192 GitHub stars~13k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed

More from aws-samples/sample-well-architected-skills-and-steering

  • Wa Builder

    aws-samples/sample-well-architected-skills-and-steering

    Official

    "Learn then Build" — help developers understand AWS Well-Architected best practices for their specific workload, then produce actionable visual artifacts (architecture diagrams with WA annotations…

    275 GitHub stars~3.8k tokensUpdated 4 days ago
    Auto-check passed
  • AWS Well Architected Framework Review

    aws-samples/sample-well-architected-skills-and-steering

    Official

    Perform a full AWS Well-Architected Framework review evaluating all 57 questions across 6 pillars by analyzing code, IaC, and configurations to produce evidence-backed findings with…

    275 GitHub stars~11k tokensUpdated 4 days ago
    Auto-check passed
  • Migration Readiness

    aws-samples/sample-well-architected-skills-and-steering

    Official

    Assess a workload's readiness to migrate to AWS by analyzing existing code, dependencies, configurations, and infrastructure to produce evidence-backed findings covering the 7 Rs, risks, and a…

    275 GitHub stars~3.3k tokensUpdated 4 days ago
    Auto-check passed
  • Wafr Facilitator

    aws-samples/sample-well-architected-skills-and-steering

    Official

    Help a facilitator run a conversational Well-Architected Framework Review (WAFR) with a customer — generates tailored facilitator questions, probing follow-ups, and "things to look out for" per WA…

    275 GitHub stars~5.2k tokensUpdated 4 days ago
    Auto-check: warnings

Questions about Wa Guardrails

What does Wa Guardrails do?

Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…. Wa Guardrails is an agent skill from aws-samples/sample-well-architected-skills-and-steering, published by the product's own GitHub organization. Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) — plus an optional governance steering doc, so a workload stays aligned with Well-Architected best practices over time instead of being assessed once.

When should I use Wa Guardrails?

Wa Guardrails fits situations like: the user wants to enforce best practices in CI; prevent insecure; non-compliant configurations from shipping; detect configuration drift.

How do I install Wa Guardrails in Claude Code?

Run `npx skills add aws-samples/sample-well-architected-skills-and-steering --skill wa-guardrails -a claude-code`. Or copy the skill folder (skills/wa-guardrails in aws-samples/sample-well-architected-skills-and-steering) into .claude/skills/wa-guardrails in your project. Claude Code loads it when a task matches its description.

How do I install Wa Guardrails in Codex?

Run `npx skills add aws-samples/sample-well-architected-skills-and-steering --skill wa-guardrails -a codex`. Or copy the skill folder (skills/wa-guardrails in aws-samples/sample-well-architected-skills-and-steering) into .agents/skills/wa-guardrails in your project. Codex loads it when a task matches its description.

Can I use Wa Guardrails in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/sample-well-architected-skills-and-steering --skill wa-guardrails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wa-guardrails, .gemini/skills/wa-guardrails, .github/skills/wa-guardrails and .opencode/skills/wa-guardrails in your project.

What does Wa Guardrails need to run?

SKILL.md names no scripts, command-line tools or credentials: Wa Guardrails is instructions for the agent only.

Does Wa Guardrails access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wa Guardrails safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wa Guardrails use?

Wa Guardrails is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wa Guardrails use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Wa Guardrails?

Skills that share tags, products or a category with Wa Guardrails: Cloud Security (borghei/Claude-Skills, 891 stars), GCP To AWS (aws/agent-toolkit-for-aws, 2.8k stars), Hardening Cloud Posture (trilwu/secskills, 157 stars) and Investigation Cost Guardrail (aws/tools-for-devops-agent, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wa Guardrails?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/sample-well-architected-skills-and-steering, which has 275 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 6, 2026.

Source: aws-samples/sample-well-architected-skills-and-steering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.