Official agent skill

Agentcore Ops Review

by aws in aws/tools-for-devops-agent

Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Agentcore Ops Review

skills CLI
$ npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/tools-for-devops-agent agentcore-ops-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agentcore-ops-review .claude/skills/agentcore-ops-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agentcore-ops-review
GitHub stars
100
Used in
1 other repo
Token cost
~4k tokens
SKILL.md length
1,684 words
Files
13 (incl. references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework.

  • Works in 8 steps: Discover Account and Regions → Runtime Resilience Pillar (Reliability) → Gateway Health (Reliability) → …
  • A user asks to review
  • SKILL.md covers Overview, Data Source Boundaries…, Step 1: Discover Account and… and Step 2: Runtime Resilience…, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Agentcore Ops Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework. Covers four check areas — Runtime Resilience, Gateway Health, Memory & Knowledge Effectiveness, and Resource Utilization & Operational Hygiene — plus runtime observability signals from CloudWatch. Use this skill when a user asks to review, audit, or assess Amazon Bedrock AgentCore workloads, perform an AgentCore operational readiness review, investigate agent runtime failures, audit…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).

It sits in DevOps & Cloud, covering Agent memory, Cloud architecture and Observability. It works with Amazon Bedrock and Amazon Web Services. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.

When your agent uses it

  • A user asks to review
  • Assess Amazon Bedrock AgentCore workloads
  • Perform an AgentCore operational readiness review
  • Investigate agent runtime failures

Example prompts

  • “AgentCore review”
  • “AgentCore best practices audit”
  • “review my AgentCore runtimes”
  • “/agentcore-ops-review”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Discover Account and Regions
  2. Runtime Resilience Pillar (Reliability)
  3. Gateway Health (Reliability)
  4. Memory & Knowledge Effectiveness (Performance Efficiency)
  5. Resource Utilization & Operational Hygiene (Operational Excellence)
  6. Runtime Observability (cross-pillar signals)
  7. Additional Context
  8. Produce Report and Recommendations

What it can do on your machine

Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agentcore Ops Review loads about 4k tokens when it runs, and up to ~9.9k if it reads all its reference files. Until then it costs about 205 tokens; SKILL.md has 1,684 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~205
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,684 words, ~4,006 tokens.

Download SKILL.mdSave it as .claude/skills/agentcore-ops-review/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
agentcore-ops-review
description
Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework. Covers four check areas — Runtime Resilience, Gateway Health, Memory & Knowledge Effectiveness, and Resource Utilization & Operational Hygiene — plus runtime observability signals from CloudWatch. Use this skill when a user asks to review, audit, or assess Amazon Bedrock AgentCore workloads, perform an AgentCore operational readiness review, investigate agent runtime failures, audit memory/knowledge pipeline health, or review gateway resilience and resource hygiene. Triggers on requests like "AgentCore review", "AgentCore best practices audit", "review my AgentCore runtimes", "AgentCore health check", "audit my agent memory pipelines", or "ORR for AgentCore".
metadata.author
pamvas
metadata.version
1.0.1
metadata.aws-devops-agent-skills.agent-t
Chat tasks, Evaluation
metadata.aws-devops-agent-skills.aws-ser
Amazon Bedrock AgentCore
metadata.aws-devops-agent-skills.technic
Machine Learning, GenAI

Bedrock AgentCore Operational Review

Use this skill when performing an operational review of Amazon Bedrock AgentCore resources, investigating agent runtime failures, auditing memory/knowledge pipeline health, or reviewing gateway resilience and resource hygiene.

Overview

This skill provides procedures for a review of AgentCore resources across four check areas mapped to the AWS Well-Architected Framework:

  • Runtime Resilience (Reliability) — Failed/stuck runtimes and endpoints, single-AZ VPC placement, endpoint version drift, DEFAULT-endpoint-only deployments
  • Gateway Health (Reliability) — Gateway status, target redundancy and health, policy engine attachment, target synchronization freshness
  • Memory & Knowledge Effectiveness (Performance Efficiency) — Extraction pipeline errors, empty long-term memory, high ingestion error rate, provisioned-but-never-populated memories
  • Resource Utilization & Operational Hygiene (Operational Excellence) — Idle resources, consolidation opportunities, low overall utilization
  • Runtime Observability (cross-pillar) — Session counts, invocations, throttles, vCPU-hours, GB-hours per runtime

This is a READ-ONLY review. No modifications are made to any resource, and it never invokes an agent (InvokeAgentRuntime), reads no prompts or responses, and makes no other data-plane calls. One exception: for long-term memories the skill calls bedrock-agentcore:ListMemoryRecords (a data-plane API) solely to obtain a record count. That response can include a content field carrying extracted, potentially PII-bearing memory content; the skill uses only the count and never parses, logs, stores, or reproduces content. See "Memory record data handling" below.

Data Source Boundaries (IMPORTANT — IAM footprint)

The standard AIDevOpsAgentAccessPolicy covers bedrock:* read actions but does NOT include the bedrock-agentcore:* namespace. (Note: bedrock-agentcore-control is the SDK client name, not an IAM prefix — all control-plane actions such as ListAgentRuntimes, GetMemory, and ListGateways authorize under the single service prefix bedrock-agentcore:.) Two modes:

  1. Runtime-observability-only mode — relies exclusively on CloudWatch metrics (cloudwatch:GetMetricData, cloudwatch:ListMetrics) against namespace AWS/Bedrock-AgentCore. Requires no bedrock-agentcore: additions. When an account isn't using AgentCore, the namespace is simply empty ("no activity detected") — this is not a failure.
  2. Full control-plane mode — adds read-only bedrock-agentcore: control-plane List/Get actions and ec2:DescribeSubnets to enable the runtime/gateway/memory/utilization checks. It also uses one data-plane action, bedrock-agentcore:ListMemoryRecords, for the long-term-memory record count only (see "Memory record data handling" below). See references/iam-policy-linked-account.json.

If a required permission is missing, the affected check degrades to a visibility limit (reported as "signal unavailable / check skipped") rather than failing the review or producing a false finding.

Memory record data handling: bedrock-agentcore:ListMemoryRecords is a data-plane API whose MemoryRecordSummary entries include a required content field — the extracted facts/preferences/summaries a long-term memory has stored, which can contain end-user PII. This skill calls it only to count records for AC-MEM-2 and never reads, parses, logs, stores, transforms, or reproduces the content field. If you prefer zero data-plane access, omit this action from the IAM policy: AC-MEM-2 then degrades to a visibility limit while all other memory checks (which use CloudWatch ingestion metrics) continue to work.

Seam with agentcore-observability-setup: This skill assesses operational posture from existing telemetry; it does not configure or validate observability wiring. Where telemetry is absent, this skill reports a visibility limit and defers the configuration gap to agentcore-observability-setup — that skill owns the observability-wiring finding (Transaction Search, OTEL/ADOT, log delivery, X-Ray resource policy), while this skill reports only the posture consequence. A customer running both should not see two overlapping findings on the same resource.

Step 1: Discover Account and Regions

  1. Call sts:GetCallerIdentity to determine the account.
  2. Discover AgentCore-active regions:
    • Query Cost Explorer: ce:GetDimensionValues (dimension SERVICE, last 30 days), match "Amazon Bedrock AgentCore".
    • Then ce:GetCostAndUsage for that service grouped by REGION; select top regions by UnblendedCost.
    • If no AgentCore spend is found, fall back to probing cloudwatch:ListMetrics (namespace AWS/Bedrock-AgentCore) in the customer's primary regions to detect activity.
  3. If no AgentCore activity is detected in any region, stop: "No AgentCore usage detected in the last 30 days."

Step 2: Runtime Resilience Pillar (Reliability)

Discover runtimes and enrich each with endpoints and versions:

  • bedrock-agentcore:ListAgentRuntimes → GetAgentRuntime (status, failureReason, networkConfiguration)
  • bedrock-agentcore:ListAgentRuntimeEndpoints (status, liveVersion, targetVersion, name)
  • bedrock-agentcore:ListAgentRuntimeVersions (to compute latest version + drift)
  • ec2:DescribeSubnets (resolve VPC subnet IDs to AZs — endpoints carry NO AZ data)
CheckRuleSeverity
AC-RUN-1Runtime/endpoint in CREATE_FAILED/UPDATE_FAILED, or stuck in CREATING/UPDATING > 1 hourCritical
AC-RUN-2VPC-mode runtime whose subnets all resolve to a single AZ (PUBLIC mode exempt)High
AC-RUN-3Live endpoint ≥ 3 versions behind latest runtime versionMedium
AC-RUN-4Actively-updated runtime (2+ versions) served only by the auto-updating DEFAULT endpointLow

Key fact: Endpoints are a versioning/traffic-routing construct, not a redundancy mechanism. AZ fault tolerance is derived exclusively from the runtime's VPC subnet configuration. If ec2:DescribeSubnets is unavailable, AC-RUN-2 degrades to "AZ distribution unknown".

Step 3: Gateway Health (Reliability)

Discover gateways and their targets:

  • bedrock-agentcore:ListGateways → GetGateway (status, protocolType, authorizerType, policyEngineConfiguration)
  • bedrock-agentcore:ListGatewayTargets → GetGatewayTarget (status, targetConfiguration, lastSynchronizedAt, credential providers)

Target type derived from targetConfiguration.mcp: Lambda, MCP Server, API Gateway, OpenAPI Schema, Smithy Model.

Risk LevelCondition
CriticalGateway not READY, zero targets, OR all targets unhealthy
WarningSingle target (no redundancy), no policy engine attached, some unhealthy targets, OR stale sync (> 7 days)
HealthyMultiple READY targets, policy engine attached, recent synchronization

Unhealthy target statuses: FAILED, UPDATE_UNSUCCESSFUL, SYNCHRONIZE_UNSUCCESSFUL. Stale sync threshold: lastSynchronizedAt older than 7 days.

Step 4: Memory & Knowledge Effectiveness (Performance Efficiency)

Discover memories and their strategies, then query CloudWatch ingestion metrics:

  • bedrock-agentcore:ListMemories → GetMemory (status, createdAt, configured strategies)
  • bedrock-agentcore:ListMemoryRecords — data-plane call, count only (long-term-strategy memories). Read the returned record count; do not read the content field (see "Memory record data handling")
  • cloudwatch:GetMetricData (namespace AWS/Bedrock-AgentCore): per-memory Invocations/Errors for the Ingestion operation, and Invocations for the CreateEvent operation (30-day window)

All rules are strategy-aware — read GetMemory strategies first. Record-count rules apply ONLY to memories with a long-term strategy; short-term-only memories are never flagged as empty.

CheckRuleSeverity
AC-MEM-1Long-term memory with CloudWatch ingestion Errors > 0High
AC-MEM-2Long-term memory with < 10 records (escalates to High if 0 records AND > 7 days old)Medium→High
AC-MEM-3Ingestion error rate > 20% (Errors / Invocations)High
AC-MEM-4Provisioned but never populated: zero CreateEvent activity AND > 7 days oldMedium

Safety rule: CreateEvent activity is queried for EVERY memory (short-term memories receive events too). When the CloudWatch signal is unreadable, event count is None (not 0), so AC-MEM-4 is skipped rather than firing a false "never populated" finding.

Show full SKILL.md (691 more words)Show less

Step 5: Resource Utilization & Operational Hygiene (Operational Excellence)

Enumerate all provisionable resource types and collect a 30-day activity signal:

  • Inventory: ListAgentRuntimes, ListMemories, ListGateways, ListBrowsers, ListCodeInterpreters, ListWorkloadIdentities
  • Activity: cloudwatch:GetMetricData (Invocations, AWS/Bedrock-AgentCore) keyed by per-type dimension (AgentRuntimeId, MemoryId, GatewayId)
CheckRuleSeverity
AC-UTIL-1Idle resource: zero activity over 30-day window, > 7 days oldMedium
AC-UTIL-2Consolidation: duplicate configs in a region, OR regions holding resources with < 5% of total activity (3+ regions)Informational→Medium
AC-UTIL-3Overall utilization < 60% (active / assessable, excluding recently-created)Informational

For the AC-UTIL-1 idle signal, prefer the real-time ActiveSessionCount gauge (a currently-running-sessions gauge, filterable by the Service dimension) where available; fall back to the cumulative SessionCount / Invocations counters over the 30-day window when ActiveSessionCount is not present.

Framing: AgentCore runtime billing is consumption-based — idle time is free. Frame findings as operational hygiene and security surface (unmanaged IAM roles, stale config), NOT wasted spend. Exception: memories holding stored long-term records DO accrue storage cost — call this out in the finding.

Classification safety: A resource is only classified Idle when its activity signal is complete for the full window. Types with no queryable per-resource metric (Browser, CodeInterpreter, WorkloadIdentity), and every resource when the CloudWatch call fails, are classified Active (partial) — never Idle. Resources younger than 7 days are RecentlyCreated and excluded from both idle flagging and the utilization ratio.

Step 6: Runtime Observability (cross-pillar signals)

For each runtime, collect CloudWatch metrics from namespace AWS/Bedrock-AgentCore:

MetricDimensionsPeriodStatistic
CPUUsed-vCPUHoursResource (ARN), Service=AgentCore.Runtime, Name3600sSum
MemoryUsed-GBHoursResource (ARN), Service=AgentCore.Runtime, Name3600sSum
SessionCountResource (ARN), Operation=InvokeAgentRuntime, Name300sSum
InvocationsResource (ARN), Operation=InvokeAgentRuntime, Name300sSum
ThrottlesResource (ARN), Operation=InvokeAgentRuntime, Name300sSum

SessionCount is a cumulative counter of new sessions per period. Where a real-time view is needed, ActiveSessionCount is a gauge of currently-running sessions (filterable by the Service dimension).

Discover resources first via cloudwatch:ListMetrics (namespace AWS/Bedrock-AgentCore), extract unique Resource ARN + Name dimensions, then batch GetMetricData per resource.

Derived signals:

  • Throttle rate = Throttles / Invocations × 100
  • Health status = "Throttling Detected" when Throttles > 0, else "Healthy"
  • Only report runtimes with any activity (CPU-hours, GB-hours, invocations, or session count > 0).

Step 7: Additional Context

  1. Health Events: health:DescribeEvents filtered for Bedrock/AgentCore service, last 14 days.
  2. Documentation: Cross-reference findings against AgentCore best-practices docs for remediation links.

Step 8: Produce Report and Recommendations

Produce an artifact with the structure defined in references/report-template.md.

For each finding with severity Warning/Medium or higher, create a recommendation with:

  • Title: [Check ID] [Check name] — [Resource identifier]
  • Summary: Current state, expected state, business/operational impact, remediation steps, and a TAM conversation starter.

Boundaries are deliberate and non-overlapping:

  • agentcore-observability-setup — sets up/validates observability wiring. This skill consumes that telemetry for posture assessment and defers observability-configuration gaps to it (see the seam described in Data Source Boundaries).
  • agentcore-runtime-diag (queued submission — referenced for scope, not yet published) — reactive triage of a single failing invocation. This skill is proactive, estate-wide posture; it does not diagnose individual call failures or evaluate authorizer/credential correctness. Gateway checks here are redundancy/staleness/health only, not auth evaluation.
  • aiml-access-diagnostics (published) — generic AI/ML AccessDenied chain via iam:SimulatePrincipalPolicy. Not overlapping — this skill makes no IAM-simulation calls.
  • bedrock-adoption-readiness (published) — foundation-model workload readiness (IAM governance, ZDR, quotas, observability). Different resource surface — this skill reviews the AgentCore agent runtime / memory / gateway layer, not foundation-model inference.

Error Handling

ErrorAction
AccessDenied on bedrock-agentcore:*Log as visibility limit "signal unavailable — check skipped", continue in observability-only mode
AccessDenied on ec2:DescribeSubnetsAC-RUN-2 degrades to "AZ distribution unknown"
CloudWatch returns no dataReport "no activity detected" for that resource; classify utilization as Active (partial), never Idle
No AgentCore usage anywhereStop early: "No AgentCore usage detected"
Throttled by AWS APIRetry with exponential backoff (3 attempts)
Check raises an exceptionIsolate the failure — degrade that check to a visibility limit and continue the others

Important Notes

  • ALL API calls with pagination (NextToken) MUST be paginated to completion.
  • Cost Explorer queries run against us-east-1 (global endpoint).
  • Findings are only produced when the underlying signal is complete — incomplete signals become visibility limits, never false positives.
  • Batch CloudWatch GetMetricData requests where possible.
  • This is a READ-ONLY review — no modifications, and no data-plane calls other than ListMemoryRecords for record count (count only; content is never read).

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (references) in skills/agentcore-ops-review of aws/tools-for-devops-agent.

  • SKILL.md
  • .skilleval.yaml
  • CHANGELOG.md
  • README.md
  • evals/eval_queries.json
  • evals/evals.json
  • evals/files/agentcore-context.json
  • references/iam-policy-linked-account.json
  • references/iam-policy-management-account.json
  • references/iam-policy-observability-only.json
  • references/iam-policy.json
  • references/pillar-checks.md
  • references/report-template.md

Open the folder on GitHubat commit ddda70b

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aws/tools-for-devops-agent, which our catalogue first saw on October 8, 2026.

Compare with similar skills

Agentcore Ops Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agentcore Ops Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agentcore Ops Review this skillaws/tools-for-devops-agent1001 repos~4kAutomated safety check: PassApache-2.0
AWS Strands Agents Agentcoresammcj/agentic-coding1621 repos~3kAutomated safety check: PassApache-2.0
AWS Agentic AIsickn33/agentic-awesome-skills47k1 repos~3.2kAutomated safety check: PassMIT
AWS Agentic AIzxkane/aws-skills3671 repos~2.5kAutomated safety check: PassMIT
Hcls Deploy Agentaws-samples/amazon-bedrock-agents-healthcare-lifesciences274—~813Automated safety check: PassMIT-0
AWS Harnesshoodini/ai-agents-skills281—~4.2kAutomated safety check: NotesNone

Similar skills

  • AWS Strands Agents Agentcore

    sammcj/agentic-coding

    A skill your agent uses when working with AWS Strands Agents SDK or Amazon Bedrock AgentCore platform for building AI agents.

    162 GitHub starsUsed in 1 repo~3k tokens
    DevOps & CloudAuto-check passed
  • AWS Agentic AI

    sickn33/agentic-awesome-skills

    AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.

    47k GitHub starsUsed in 1 repo~3.2k tokens
    DevOps & CloudAuto-check passed
  • AWS Agentic AI

    zxkane/aws-skills

    AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.

    367 GitHub starsUsed in 1 repo~2.5k tokens
    Agent WorkflowsAuto-check passed
  • Hcls Deploy Agent

    aws-samples/amazon-bedrock-agents-healthcare-lifesciences

    Official

    A skill your agent uses when a developer wants to deploy an HCLS agent to Amazon Bedrock AgentCore, configure Gateway tools as MCP endpoints, set up authentication with Cognito, configure memory, or…

    274 GitHub stars~813 tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • AWS Harness

    hoodini/ai-agents-skills

    Build a new AI agent on AWS and deploy it easily, OR wrap and deploy an agent you already have, using the Amazon Bedrock AgentCore harness.

    281 GitHub stars~4.2k tokensUpdated 2 mo ago
    Backend & APIsAuto-check: notes
  • AWS Agentic AI

    majiayu000/claude-skill-registry

    AWS Bedrock AgentCore comprehensive expert for deploying and managing all AgentCore services.

    666 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed

More from aws/tools-for-devops-agent

All 31 skills in this repo
  • Sagemaker AI Ops Review

    aws/tools-for-devops-agent

    Official

    Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.

    100 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Aiml GPU Training Cluster Investigation

    aws/tools-for-devops-agent

    Official

    A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.

    100 GitHub stars~5.4k tokensUpdated today
    Auto-check passed
  • AWS Health Events

    aws/tools-for-devops-agent

    Official

    ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

    100 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Database Migration Service Expertise

    aws/tools-for-devops-agent

    Official

    AWS Database Migration Service (DMS) operational review and troubleshooting skill.

    100 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    100 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    100 GitHub stars~4.8k tokensUpdated today
    Auto-check passed

Questions about Agentcore Ops Review

What does Agentcore Ops Review do?

Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework. Agentcore Ops Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework.

When should I use Agentcore Ops Review?

Agentcore Ops Review fits situations like: A user asks to review; assess Amazon Bedrock AgentCore workloads; perform an AgentCore operational readiness review; investigate agent runtime failures.

How do I install Agentcore Ops Review in Claude Code?

Run `npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a claude-code`. Or copy the skill folder (skills/agentcore-ops-review in aws/tools-for-devops-agent) into .claude/skills/agentcore-ops-review in your project. Claude Code loads it when a task matches its description.

How do I install Agentcore Ops Review in Codex?

Run `npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a codex`. Or copy the skill folder (skills/agentcore-ops-review in aws/tools-for-devops-agent) into .agents/skills/agentcore-ops-review in your project. Codex loads it when a task matches its description.

Can I use Agentcore Ops Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agentcore-ops-review, .gemini/skills/agentcore-ops-review, .github/skills/agentcore-ops-review and .opencode/skills/agentcore-ops-review in your project.

What does Agentcore Ops Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Agentcore Ops Review is instructions for the agent only.

Does Agentcore Ops Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Agentcore Ops Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Agentcore Ops Review use?

Agentcore Ops Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agentcore Ops Review use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.

What are the alternatives to Agentcore Ops Review?

Skills that share tags, products or a category with Agentcore Ops Review: AWS Strands Agents Agentcore (sammcj/agentic-coding, 162 stars), AWS Agentic AI (sickn33/agentic-awesome-skills, 47k stars), AWS Agentic AI (zxkane/aws-skills, 367 stars) and Hcls Deploy Agent (aws-samples/amazon-bedrock-agents-healthcare-lifesciences, 274 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agentcore Ops Review?

aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 100 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.

Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.