AWS Strands Agents Agentcore
sammcj/agentic-coding
A skill your agent uses when working with AWS Strands Agents SDK or Amazon Bedrock AgentCore platform for building AI agents.
Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework.
$ npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent agentcore-ops-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agentcore-ops-review .claude/skills/agentcore-ops-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "agentcore-ops-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/agentcore-ops-review into .claude/skills/agentcore-ops-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agentcore-ops-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/agentcore-ops-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent agentcore-ops-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/agentcore-ops-review .agents/skills/agentcore-ops-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "agentcore-ops-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/agentcore-ops-review into .agents/skills/agentcore-ops-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agentcore-ops-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent agentcore-ops-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/agentcore-ops-review .cursor/skills/agentcore-ops-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "agentcore-ops-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/agentcore-ops-review into .cursor/skills/agentcore-ops-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agentcore-ops-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/agentcore-ops-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent agentcore-ops-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/agentcore-ops-review .gemini/skills/agentcore-ops-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "agentcore-ops-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/agentcore-ops-review into .gemini/skills/agentcore-ops-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agentcore-ops-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent agentcore-ops-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/agentcore-ops-review .github/skills/agentcore-ops-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "agentcore-ops-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/agentcore-ops-review into .github/skills/agentcore-ops-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agentcore-ops-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent agentcore-ops-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/agentcore-ops-review .opencode/skills/agentcore-ops-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "agentcore-ops-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/agentcore-ops-review into .opencode/skills/agentcore-ops-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agentcore-ops-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
agentcore-ops-reviewComprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework.
Agentcore Ops Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework. Covers four check areas — Runtime Resilience, Gateway Health, Memory & Knowledge Effectiveness, and Resource Utilization & Operational Hygiene — plus runtime observability signals from CloudWatch. Use this skill when a user asks to review, audit, or assess Amazon Bedrock AgentCore workloads, perform an AgentCore operational readiness review, investigate agent runtime failures, audit…
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).
It sits in DevOps & Cloud, covering Agent memory, Cloud architecture and Observability. It works with Amazon Bedrock and Amazon Web Services. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Agentcore Ops Review loads about 4k tokens when it runs, and up to ~9.9k if it reads all its reference files. Until then it costs about 205 tokens; SKILL.md has 1,684 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,684 words, ~4,006 tokens.
.claude/skills/agentcore-ops-review/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.Use this skill when performing an operational review of Amazon Bedrock AgentCore resources, investigating agent runtime failures, auditing memory/knowledge pipeline health, or reviewing gateway resilience and resource hygiene.
This skill provides procedures for a review of AgentCore resources across four check areas mapped to the AWS Well-Architected Framework:
This is a READ-ONLY review. No modifications are made to any resource, and it never invokes an agent (InvokeAgentRuntime), reads no prompts or responses, and makes no other data-plane calls. One exception: for long-term memories the skill calls bedrock-agentcore:ListMemoryRecords (a data-plane API) solely to obtain a record count. That response can include a content field carrying extracted, potentially PII-bearing memory content; the skill uses only the count and never parses, logs, stores, or reproduces content. See "Memory record data handling" below.
The standard AIDevOpsAgentAccessPolicy covers bedrock:* read actions but does NOT include the bedrock-agentcore:* namespace. (Note: bedrock-agentcore-control is the SDK client name, not an IAM prefix — all control-plane actions such as ListAgentRuntimes, GetMemory, and ListGateways authorize under the single service prefix bedrock-agentcore:.) Two modes:
cloudwatch:GetMetricData, cloudwatch:ListMetrics) against namespace AWS/Bedrock-AgentCore. Requires no bedrock-agentcore: additions. When an account isn't using AgentCore, the namespace is simply empty ("no activity detected") — this is not a failure.bedrock-agentcore: control-plane List/Get actions and ec2:DescribeSubnets to enable the runtime/gateway/memory/utilization checks. It also uses one data-plane action, bedrock-agentcore:ListMemoryRecords, for the long-term-memory record count only (see "Memory record data handling" below). See references/iam-policy-linked-account.json.If a required permission is missing, the affected check degrades to a visibility limit (reported as "signal unavailable / check skipped") rather than failing the review or producing a false finding.
Memory record data handling: bedrock-agentcore:ListMemoryRecords is a data-plane API whose MemoryRecordSummary entries include a required content field — the extracted facts/preferences/summaries a long-term memory has stored, which can contain end-user PII. This skill calls it only to count records for AC-MEM-2 and never reads, parses, logs, stores, transforms, or reproduces the content field. If you prefer zero data-plane access, omit this action from the IAM policy: AC-MEM-2 then degrades to a visibility limit while all other memory checks (which use CloudWatch ingestion metrics) continue to work.
Seam with agentcore-observability-setup: This skill assesses operational posture from existing telemetry; it does not configure or validate observability wiring. Where telemetry is absent, this skill reports a visibility limit and defers the configuration gap to agentcore-observability-setup — that skill owns the observability-wiring finding (Transaction Search, OTEL/ADOT, log delivery, X-Ray resource policy), while this skill reports only the posture consequence. A customer running both should not see two overlapping findings on the same resource.
sts:GetCallerIdentity to determine the account.ce:GetDimensionValues (dimension SERVICE, last 30 days), match "Amazon Bedrock AgentCore".ce:GetCostAndUsage for that service grouped by REGION; select top regions by UnblendedCost.cloudwatch:ListMetrics (namespace AWS/Bedrock-AgentCore) in the customer's primary regions to detect activity.Discover runtimes and enrich each with endpoints and versions:
bedrock-agentcore:ListAgentRuntimes → GetAgentRuntime (status, failureReason, networkConfiguration)bedrock-agentcore:ListAgentRuntimeEndpoints (status, liveVersion, targetVersion, name)bedrock-agentcore:ListAgentRuntimeVersions (to compute latest version + drift)ec2:DescribeSubnets (resolve VPC subnet IDs to AZs — endpoints carry NO AZ data)| Check | Rule | Severity |
|---|---|---|
| AC-RUN-1 | Runtime/endpoint in CREATE_FAILED/UPDATE_FAILED, or stuck in CREATING/UPDATING > 1 hour | Critical |
| AC-RUN-2 | VPC-mode runtime whose subnets all resolve to a single AZ (PUBLIC mode exempt) | High |
| AC-RUN-3 | Live endpoint ≥ 3 versions behind latest runtime version | Medium |
| AC-RUN-4 | Actively-updated runtime (2+ versions) served only by the auto-updating DEFAULT endpoint | Low |
Key fact: Endpoints are a versioning/traffic-routing construct, not a redundancy mechanism. AZ fault tolerance is derived exclusively from the runtime's VPC subnet configuration. If ec2:DescribeSubnets is unavailable, AC-RUN-2 degrades to "AZ distribution unknown".
Discover gateways and their targets:
bedrock-agentcore:ListGateways → GetGateway (status, protocolType, authorizerType, policyEngineConfiguration)bedrock-agentcore:ListGatewayTargets → GetGatewayTarget (status, targetConfiguration, lastSynchronizedAt, credential providers)Target type derived from targetConfiguration.mcp: Lambda, MCP Server, API Gateway, OpenAPI Schema, Smithy Model.
| Risk Level | Condition |
|---|---|
| Critical | Gateway not READY, zero targets, OR all targets unhealthy |
| Warning | Single target (no redundancy), no policy engine attached, some unhealthy targets, OR stale sync (> 7 days) |
| Healthy | Multiple READY targets, policy engine attached, recent synchronization |
Unhealthy target statuses: FAILED, UPDATE_UNSUCCESSFUL, SYNCHRONIZE_UNSUCCESSFUL. Stale sync threshold: lastSynchronizedAt older than 7 days.
Discover memories and their strategies, then query CloudWatch ingestion metrics:
bedrock-agentcore:ListMemories → GetMemory (status, createdAt, configured strategies)bedrock-agentcore:ListMemoryRecords — data-plane call, count only (long-term-strategy memories). Read the returned record count; do not read the content field (see "Memory record data handling")cloudwatch:GetMetricData (namespace AWS/Bedrock-AgentCore): per-memory Invocations/Errors for the Ingestion operation, and Invocations for the CreateEvent operation (30-day window)All rules are strategy-aware — read GetMemory strategies first. Record-count rules apply ONLY to memories with a long-term strategy; short-term-only memories are never flagged as empty.
| Check | Rule | Severity |
|---|---|---|
| AC-MEM-1 | Long-term memory with CloudWatch ingestion Errors > 0 | High |
| AC-MEM-2 | Long-term memory with < 10 records (escalates to High if 0 records AND > 7 days old) | Medium→High |
| AC-MEM-3 | Ingestion error rate > 20% (Errors / Invocations) | High |
| AC-MEM-4 | Provisioned but never populated: zero CreateEvent activity AND > 7 days old | Medium |
Safety rule: CreateEvent activity is queried for EVERY memory (short-term memories receive events too). When the CloudWatch signal is unreadable, event count is None (not 0), so AC-MEM-4 is skipped rather than firing a false "never populated" finding.
Enumerate all provisionable resource types and collect a 30-day activity signal:
ListAgentRuntimes, ListMemories, ListGateways, ListBrowsers, ListCodeInterpreters, ListWorkloadIdentitiescloudwatch:GetMetricData (Invocations, AWS/Bedrock-AgentCore) keyed by per-type dimension (AgentRuntimeId, MemoryId, GatewayId)| Check | Rule | Severity |
|---|---|---|
| AC-UTIL-1 | Idle resource: zero activity over 30-day window, > 7 days old | Medium |
| AC-UTIL-2 | Consolidation: duplicate configs in a region, OR regions holding resources with < 5% of total activity (3+ regions) | Informational→Medium |
| AC-UTIL-3 | Overall utilization < 60% (active / assessable, excluding recently-created) | Informational |
For the AC-UTIL-1 idle signal, prefer the real-time ActiveSessionCount gauge (a currently-running-sessions gauge, filterable by the Service dimension) where available; fall back to the cumulative SessionCount / Invocations counters over the 30-day window when ActiveSessionCount is not present.
Framing: AgentCore runtime billing is consumption-based — idle time is free. Frame findings as operational hygiene and security surface (unmanaged IAM roles, stale config), NOT wasted spend. Exception: memories holding stored long-term records DO accrue storage cost — call this out in the finding.
Classification safety: A resource is only classified Idle when its activity signal is complete for the full window. Types with no queryable per-resource metric (Browser, CodeInterpreter, WorkloadIdentity), and every resource when the CloudWatch call fails, are classified Active (partial) — never Idle. Resources younger than 7 days are RecentlyCreated and excluded from both idle flagging and the utilization ratio.
For each runtime, collect CloudWatch metrics from namespace AWS/Bedrock-AgentCore:
| Metric | Dimensions | Period | Statistic |
|---|---|---|---|
| CPUUsed-vCPUHours | Resource (ARN), Service=AgentCore.Runtime, Name | 3600s | Sum |
| MemoryUsed-GBHours | Resource (ARN), Service=AgentCore.Runtime, Name | 3600s | Sum |
| SessionCount | Resource (ARN), Operation=InvokeAgentRuntime, Name | 300s | Sum |
| Invocations | Resource (ARN), Operation=InvokeAgentRuntime, Name | 300s | Sum |
| Throttles | Resource (ARN), Operation=InvokeAgentRuntime, Name | 300s | Sum |
SessionCount is a cumulative counter of new sessions per period. Where a real-time view is needed, ActiveSessionCount is a gauge of currently-running sessions (filterable by the Service dimension).
Discover resources first via cloudwatch:ListMetrics (namespace AWS/Bedrock-AgentCore), extract unique Resource ARN + Name dimensions, then batch GetMetricData per resource.
Derived signals:
Throttles / Invocations × 100Throttles > 0, else "Healthy"health:DescribeEvents filtered for Bedrock/AgentCore service, last 14 days.Produce an artifact with the structure defined in references/report-template.md.
For each finding with severity Warning/Medium or higher, create a recommendation with:
[Check ID] [Check name] — [Resource identifier]Boundaries are deliberate and non-overlapping:
agentcore-observability-setup — sets up/validates observability wiring. This skill consumes that telemetry for posture assessment and defers observability-configuration gaps to it (see the seam described in Data Source Boundaries).agentcore-runtime-diag (queued submission — referenced for scope, not yet published) — reactive triage of a single failing invocation. This skill is proactive, estate-wide posture; it does not diagnose individual call failures or evaluate authorizer/credential correctness. Gateway checks here are redundancy/staleness/health only, not auth evaluation.aiml-access-diagnostics (published) — generic AI/ML AccessDenied chain via iam:SimulatePrincipalPolicy. Not overlapping — this skill makes no IAM-simulation calls.bedrock-adoption-readiness (published) — foundation-model workload readiness (IAM governance, ZDR, quotas, observability). Different resource surface — this skill reviews the AgentCore agent runtime / memory / gateway layer, not foundation-model inference.| Error | Action |
|---|---|
AccessDenied on bedrock-agentcore:* | Log as visibility limit "signal unavailable — check skipped", continue in observability-only mode |
AccessDenied on ec2:DescribeSubnets | AC-RUN-2 degrades to "AZ distribution unknown" |
| CloudWatch returns no data | Report "no activity detected" for that resource; classify utilization as Active (partial), never Idle |
| No AgentCore usage anywhere | Stop early: "No AgentCore usage detected" |
| Throttled by AWS API | Retry with exponential backoff (3 attempts) |
| Check raises an exception | Isolate the failure — degrade that check to a visibility limit and continue the others |
GetMetricData requests where possible.ListMemoryRecords for record count (count only; content is never read).© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 12 other files (references) in skills/agentcore-ops-review of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aws/tools-for-devops-agent, which our catalogue first saw on October 8, 2026.
Agentcore Ops Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Agentcore Ops Review this skillaws/tools-for-devops-agent | 100 | 1 repos | ~4k | Automated safety check: Pass | Apache-2.0 | |
| AWS Strands Agents Agentcoresammcj/agentic-coding | 162 | 1 repos | ~3k | Automated safety check: Pass | Apache-2.0 | |
| AWS Agentic AIsickn33/agentic-awesome-skills | 47k | 1 repos | ~3.2k | Automated safety check: Pass | MIT | |
| AWS Agentic AIzxkane/aws-skills | 367 | 1 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Hcls Deploy Agentaws-samples/amazon-bedrock-agents-healthcare-lifesciences | 274 | — | ~813 | Automated safety check: Pass | MIT-0 | |
| AWS Harnesshoodini/ai-agents-skills | 281 | — | ~4.2k | Automated safety check: Notes | None |
sammcj/agentic-coding
A skill your agent uses when working with AWS Strands Agents SDK or Amazon Bedrock AgentCore platform for building AI agents.
sickn33/agentic-awesome-skills
AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.
zxkane/aws-skills
AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.
aws-samples/amazon-bedrock-agents-healthcare-lifesciences
A skill your agent uses when a developer wants to deploy an HCLS agent to Amazon Bedrock AgentCore, configure Gateway tools as MCP endpoints, set up authentication with Cognito, configure memory, or…
hoodini/ai-agents-skills
Build a new AI agent on AWS and deploy it easily, OR wrap and deploy an agent you already have, using the Amazon Bedrock AgentCore harness.
majiayu000/claude-skill-registry
AWS Bedrock AgentCore comprehensive expert for deploying and managing all AgentCore services.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
Works with
Categories
Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework. Agentcore Ops Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Comprehensive operational review procedures for Amazon Bedrock AgentCore resources aligned with the AWS Well-Architected Framework.
Agentcore Ops Review fits situations like: A user asks to review; assess Amazon Bedrock AgentCore workloads; perform an AgentCore operational readiness review; investigate agent runtime failures.
Run `npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a claude-code`. Or copy the skill folder (skills/agentcore-ops-review in aws/tools-for-devops-agent) into .claude/skills/agentcore-ops-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a codex`. Or copy the skill folder (skills/agentcore-ops-review in aws/tools-for-devops-agent) into .agents/skills/agentcore-ops-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill agentcore-ops-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agentcore-ops-review, .gemini/skills/agentcore-ops-review, .github/skills/agentcore-ops-review and .opencode/skills/agentcore-ops-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Agentcore Ops Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Agentcore Ops Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Agentcore Ops Review: AWS Strands Agents Agentcore (sammcj/agentic-coding, 162 stars), AWS Agentic AI (sickn33/agentic-awesome-skills, 47k stars), AWS Agentic AI (zxkane/aws-skills, 367 stars) and Hcls Deploy Agent (aws-samples/amazon-bedrock-agents-healthcare-lifesciences, 274 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 100 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.