AWS AI ML
aws/agent-toolkit-for-aws
Selects, deploys, and customizes AI models on Amazon SageMaker.
A skill your agent uses when diagnosing IAM and access failures for Bedrock and SageMaker.
$ npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent aiml-access-diagnostics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aiml-access-diagnostics .claude/skills/aiml-access-diagnostics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aiml-access-diagnostics" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aiml-access-diagnostics into .claude/skills/aiml-access-diagnostics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aiml-access-diagnostics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/aiml-access-diagnosticsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent aiml-access-diagnostics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/aiml-access-diagnostics .agents/skills/aiml-access-diagnostics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aiml-access-diagnostics" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aiml-access-diagnostics into .agents/skills/aiml-access-diagnostics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aiml-access-diagnostics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent aiml-access-diagnostics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/aiml-access-diagnostics .cursor/skills/aiml-access-diagnostics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aiml-access-diagnostics" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aiml-access-diagnostics into .cursor/skills/aiml-access-diagnostics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aiml-access-diagnostics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/aiml-access-diagnostics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent aiml-access-diagnostics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/aiml-access-diagnostics .gemini/skills/aiml-access-diagnostics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aiml-access-diagnostics" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aiml-access-diagnostics into .gemini/skills/aiml-access-diagnostics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aiml-access-diagnostics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent aiml-access-diagnosticsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/aiml-access-diagnostics .github/skills/aiml-access-diagnostics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aiml-access-diagnostics" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aiml-access-diagnostics into .github/skills/aiml-access-diagnostics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aiml-access-diagnostics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent aiml-access-diagnostics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/aiml-access-diagnostics .opencode/skills/aiml-access-diagnostics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aiml-access-diagnostics" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aiml-access-diagnostics into .opencode/skills/aiml-access-diagnostics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aiml-access-diagnostics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aiml-access-diagnosticsA skill your agent uses when diagnosing IAM and access failures for Bedrock and SageMaker.
Aiml Access Diagnostics is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Use this skill when diagnosing IAM and access failures for Bedrock and SageMaker. It traces the authorization chain — caller identity, iam:PassRole, trust policy, role permissions, resource policies, SCPs — to name the denying hop and propose a scoped policy. Read-only. Use when a Bedrock or SageMaker call fails on permissions: InvokeModel or Converse AccessDeniedException, CreateTrainingJob or CreateEndpoint AccessDenied, "is not authorized to perform", "not authorized to perform: iam:PassRole", or an execution…
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).
It sits in Backend & APIs, covering File uploads and storage. It works with Amazon SageMaker. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Aiml Access Diagnostics loads about 4.9k tokens when it runs, and up to ~26k if it reads all its reference files. Until then it costs about 260 tokens; SKILL.md has 2,573 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 2,573 words, ~4,884 tokens.
.claude/skills/aiml-access-diagnostics/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.Diagnose why an AI/ML service call was denied. Walk the authorization chain hop by hop, name the hop that denied the call, and propose a scoped IAM policy for human review. Read-only throughout.
Work through these steps in order. Each is detailed in its own section below.
The report is the deliverable. Conversation around it is not.
| Service | Coverage |
|---|---|
| Amazon Bedrock | Full — including non-IAM denial causes |
| Amazon SageMaker | Full — including PassRole and execution-role chains |
| Other AI/ML services | Not supported in this version. State this plainly and stop. |
If the request concerns an unsupported service, say so and do not attempt a partial diagnosis from the generic chain alone. The value of this skill is in the service-specific knowledge; without it the output would be a guess.
references/access-chain-model.mdreferences/data-collection.mdreferences/finding-logic.mdreferences/report-format.mdreferences/svc-bedrock.md,
references/svc-sagemaker.mdClassify before calling any tool. Two things must be established first.
Determine the AI/ML service from the error text, API name, or resource ARN. If it is not Bedrock or SageMaker, stop and report it as unsupported.
| Evidence available | Route |
|---|---|
| User pasted an error message | Observed — parse it, then corroborate with CloudTrail |
| No error text, but a principal and action are named | Observed — locate the event in CloudTrail |
| Neither | Stop. Ask for the error message, or the principal ARN plus the API call that failed. |
This skill diagnoses failures. It does not audit permissions speculatively. If there is no failure to explain, say so and stop rather than producing a posture review.
sts:GetCallerIdentity to determine the account and the identity the agent
itself is operating as. Record it — the report must state whose view this is.User: <arn> is not authorized to perform: <action> on resource: <arn> carry all
three.references/finding-logic.md.Policy documents are the primary evidence. Every hop except the organization SCP
decision is decidable by reading the policies that govern it. CloudTrail and the policy
simulator are corroboration, and the diagnosis must stand without either — in this runtime
both are frequently unavailable, which is a characteristic of the environment rather than a
permission gap. See references/data-collection.md.
Collect in this order:
requestParameters — the passed RoleArn and any VpcConfig,
neither of which appears in the error string.references/svc-bedrock.md for the Bedrock grant event names. Without CloudTrail,
propagation cannot be ruled out; say so rather than ruling it out.AllowedByOrganizations at hop 6. It cannot evaluate trust policies at
all, and at hop 2 it is measurably wrong on correctly configured callers unless
iam:PassedToService is supplied.Where a policy read and simulation disagree, the policy read wins, except for
AllowedByOrganizations.
If a collection step fails, record its status, distinguishing an unreadable policy from an operation the runtime does not permit. Never infer a configuration you could not read, and never infer one operation's availability from another's failure.
Traverse the six hops in the order defined in
references/access-chain-model.md. Stop descending once a hop produces a definitive
DENIED_BY, but still collect and report the remaining hops as context where the
data is already in hand.
The most common outcome is that the caller's permissions are fine and the service role's permissions are not. Do not conclude at hop 1 simply because it passed.
Load the matching references/svc-*.md and evaluate the non-IAM denial causes it
lists. For Bedrock these include model subscription state, AWS Marketplace
permissions, and propagation timing — none of which are IAM policy gaps, and all of
which produce AccessDeniedException.
A diagnosis that checks only IAM and reports "your permissions are correct" while one of these is the true cause is the primary failure mode of this skill. Rule them out explicitly.
Every hop gets exactly one token from this closed set. Definitions and assignment rules
are in references/finding-logic.md. Never invent a token, and never write a verdict as
free prose in place of one.
| Verdict | Meaning |
|---|---|
DENIED_BY | This hop denied the call, with evidence |
WOULD_ALSO_DENY | This hop would deny too, but an earlier hop is the operative cause |
ALLOWED_BUT_UNVERIFIABLE | Evidence suggests allow, but something outside our view could still deny |
CANNOT_DETERMINE | Required evidence was unavailable — names what was missing |
NOT_APPLICABLE | The call shape does not include this hop |
NOT_EVALUATED | An earlier hop denied and this hop's evidence was not collected |
Never collapse ALLOWED_BUT_UNVERIFIABLE into an allow. Readable policies indicating
an allow is not proof the live call succeeds.
Use WOULD_ALSO_DENY rather than contradicting yourself. If a hop below the root cause
independently shows a denial, mark it as such. A hop whose finding says the call will fail
must never appear in the chain table as allowing it.
Produce a policy document for human review. Two categories of permission, labelled distinctly and never merged:
| Category | Source | Label in report |
|---|---|---|
| Hop-1 permissions | The action and resource from the observed CloudTrail failure | "Derived from the observed failure" |
| Hop-2 permissions | Curated per-service minimums from references/svc-*.md | "Commonly required — not observed; verify against your workload" |
The simulator does not generate policies. It attributes decisions. Do not present simulator output as a suggested policy.
Render per references/report-format.md, run the pre-render validation, then deliver.
Every step degrades gracefully. A single failed read never aborts the diagnosis — log it, mark the affected hop, and continue with what remains.
| Condition | Cause | Action |
|---|---|---|
iam:SimulatePrincipalPolicy refused by the runtime | The environment does not permit this operation. It is not an IAM gap — the action sits inside the agent's permission guardrail and can be granted in IAM while remaining uncallable. | Proceed on policy reads, which decide hops 1 through 5 regardless. Emit the runtime-restriction notice. Never report it as "not granted" and never recommend a policy change, CloudFormation template, or role edit — no such fix exists. Note only that AllowedByOrganizations could not be computed. |
cloudtrail:LookupEvents refused or deferred by the runtime | Same — classified as requiring operator approval despite being read-only | Proceed on the user-supplied error text and policy reads. Emit the runtime-restriction notice. Do not stall waiting for approval, do not retry in a loop, and do not report it as a permission gap. State that the event was not corroborated and that propagation could not be ruled out. |
AccessDenied on any other read | The agent's IAM genuinely lacks that permission | Mark the affected hop CANNOT_DETERMINE, naming the operation, and emit the agent-IAM-gap notice — this one a grant would fix. Continue. |
| One read refused | Says nothing about other operations | Still attempt every other read the hops require. Never infer a second operation's availability from the first one's failure. |
| No CloudTrail event found | Delivery lag of up to ~15 minutes, or wrong region or time window | Proceed using the user-supplied error text. State that the event was not corroborated. Do not conclude the call never happened. |
| Neither error text nor CloudTrail event | Nothing to diagnose | Stop. Ask for the error message, or the principal ARN plus the failed API call. |
| Target role cannot be identified | RoleArn absent from the event and no Describe available | Mark hops 2 through 4 CANNOT_DETERMINE. Do not diagnose hop 1 alone and imply the chain is clear. |
| Service is not Bedrock or SageMaker | Out of scope for this version | Stop and report it as unsupported. Do not attempt a generic diagnosis. |
| Account is not in an Organization | No SCP applies | Mark hop 6 NOT_APPLICABLE. This is not a failure. |
| Simulation contradicts a policy read | Simulation is a model and has known blind spots — trust policies, and iam:PassRole conditions | Follow the policy read. State the divergence and which one the verdict followed. Do not mark the hop CANNOT_DETERMINE on this basis alone. |
| CloudTrail shows a denial the policies read as allowing | The cause lies outside the readable policies — a session policy, a conditional SCP, or a service-side gate | Mark the hop CANNOT_DETERMINE and surface the divergence — it is itself the finding. |
| Request is a permissions audit with no failure | Out of scope; this skill is reactive | Say so and stop. Do not produce a posture review. |
references/report-format.md. If the runtime supports
persisted artifacts, also write it as
aiml-access-diagnosis-<service>-<YYYY-MM-DD>.md; if not, skip the artifact.references/data-collection.md may be called. Never call any Put*, Attach*,
Create*, Update*, or Delete* action. Never apply a proposed policy. Note that
write prevention is ultimately enforced by the DevOps Agent permission guardrail and the
agent role's IAM permissions, not by this instruction — but the instruction is binding
regardless.CANNOT_DETERMINE naming the gap.CANNOT_DETERMINE, not an inherited answer.AllowedByOrganizations at hop 6, which policy reading cannot compute.cloudtrail:LookupEvents and
iam:SimulatePrincipalPolicy are refused by this runtime while permitted in IAM.
Reporting either as "not granted", or proposing a policy or CloudFormation change to
obtain them, is a false remediation. This skill requires no IAM changes.iam:PassRole and the
role's trust policy allowing the service principal are different problems with
nearly identical symptoms.references/access-chain-model.md — the six-hop chain, precedence, and traversal rulesreferences/data-collection.md — API allowlist, error classification, output schemareferences/finding-logic.md — verdict rules and body templatesreferences/report-format.md — report structure and pre-render validationreferences/svc-bedrock.md — Bedrock roles, actions, and non-IAM denial causesreferences/svc-sagemaker.md — SageMaker PassRole, trust policy, and execution-role minimums© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files (references) in skills/aiml-access-diagnostics of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
Aiml Access Diagnostics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Aiml Access Diagnostics this skillaws/tools-for-devops-agent | 100 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| AWS AI MLaws/agent-toolkit-for-aws | 2.8k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Dataset Transformationawslabs/agent-plugins | 915 | 2 repos | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| Stripe Projectsfossasia/eventyay | 1.7k | 5 repos | ~2k | Automated safety check: Notes | Apache-2.0 | |
| FoundatioFoundatioFx/Foundatio | 2.1k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Spatialduckdb/duckdb-skills | 600 | 1 repos | ~1k | Automated safety check: Notes | MIT |
aws/agent-toolkit-for-aws
Selects, deploys, and customizes AI models on Amazon SageMaker.
awslabs/agent-plugins
Generates code that transforms datasets between ML schemas for model training or evaluation.
fossasia/eventyay
A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.
FoundatioFx/Foundatio
A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.
duckdb/duckdb-skills
Answer questions about spatial data using DuckDB. An agent skill from duckdb/duckdb-skills.
ab604/claude-code-r-skills
R object-oriented programming guide for S7, S3, S4, and vctrs.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
Works with
Categories
A skill your agent uses when diagnosing IAM and access failures for Bedrock and SageMaker. Aiml Access Diagnostics is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Use this skill when diagnosing IAM and access failures for Bedrock and SageMaker.
Aiml Access Diagnostics fits situations like: diagnosing IAM and access failures for Bedrock and SageMaker; sageMaker call fails on permissions: InvokeModel; converse AccessDeniedException; createTrainingJob.
Run `npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a claude-code`. Or copy the skill folder (skills/aiml-access-diagnostics in aws/tools-for-devops-agent) into .claude/skills/aiml-access-diagnostics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a codex`. Or copy the skill folder (skills/aiml-access-diagnostics in aws/tools-for-devops-agent) into .agents/skills/aiml-access-diagnostics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill aiml-access-diagnostics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aiml-access-diagnostics, .gemini/skills/aiml-access-diagnostics, .github/skills/aiml-access-diagnostics and .opencode/skills/aiml-access-diagnostics in your project.
SKILL.md names no scripts, command-line tools or credentials: Aiml Access Diagnostics is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Aiml Access Diagnostics is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 22k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Aiml Access Diagnostics: AWS AI ML (aws/agent-toolkit-for-aws, 2.8k stars), Dataset Transformation (awslabs/agent-plugins, 915 stars), Stripe Projects (fossasia/eventyay, 1.7k stars) and Foundatio (FoundatioFx/Foundatio, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 100 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.