Official agent skill

Amazon Ec2 Image Builder

by aws in aws/agent-toolkit-for-aws

Creates and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and container images to ECR.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Amazon Ec2 Image Builder

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill amazon-ec2-image-builder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws amazon-ec2-image-builder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/ec2-skills/amazon-ec2-image-builder .claude/skills/amazon-ec2-image-builder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
amazon-ec2-image-builder
GitHub stars
2.8k
Token cost
~2k tokens
SKILL.md length
919 words
Files
6 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Creates and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and container images to ECR.

  • Tasks that involve Containers
  • SKILL.md covers Overview, Guardrail — where this skill's…, First decision: one-off image… and Related skills — route there…, plus 3 more sections
  • Calls aws

What it does

Amazon Ec2 Image Builder is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Creates and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and container images to ECR. Covers the build IAM role, Amazon-managed and custom components, image recipes, infrastructure and distribution configuration (launch templates, SSM parameters, other Regions), one-off builds, recurring scheduled pipelines for golden AMI automation and OS patching, custom image workflows, and diagnosing failed builds. Applies when creating, automating, or scheduling AMI or container…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/creating-images.md`, `references/custom-workflows.md` and `references/distribution-options.md`).

It sits in DevOps & Cloud, covering Containers. It works with Amazon Web Services, Linux, macOS and Model Context Protocol. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Containers

Example prompts

  • “Use the amazon-ec2-image-builder skill to create and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and…”
  • “/amazon-ec2-image-builder”

What it can do on your machine

Read from SKILL.md and the folder at commit bd49cc8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Amazon Ec2 Image Builder loads about 2k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 178 tokens; SKILL.md has 919 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~178
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit bd49cc8, republished under its Apache-2.0 licence (© aws). 919 words, ~1,998 tokens.

Download SKILL.mdSave it as .claude/skills/amazon-ec2-image-builder/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
amazon-ec2-image-builder
description
Creates and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and container images to ECR. Covers the build IAM role, Amazon-managed and custom components, image recipes, infrastructure and distribution configuration (launch templates, SSM parameters, other Regions), one-off builds, recurring scheduled pipelines for golden AMI automation and OS patching, custom image workflows, and diagnosing failed builds. Applies when creating, automating, or scheduling AMI or container image builds with Image Builder, or when debugging a failed build. Not for launching instances from existing AMIs, AMI lifecycle/retirement, or general EC2 fleet management.
version
1

Amazon EC2 Image Builder

Overview

Domain expertise for building custom AMIs and container images with EC2 Image Builder — from the build IAM role through recipes, pipelines, distribution, and troubleshooting.

Works best with the AWS MCP server — recommended for sandboxed execution and audit logging. All guidance also works with standard AWS CLI access.

Guardrail — where this skill's own files live (MCP vs local install)

This skill can be loaded two ways, and they resolve the skill's own bundled files from different places. Determine how the skill was loaded before reading a reference or running a script:

  • Loaded through the AWS MCP retrieve_skill tool: The skill is not installed on the local filesystem. You MUST fetch each reference or script via retrieve_skill with the file parameter (e.g. file="references/creating-images.md"), and use the returned content. Do NOT file_read these paths locally — they do not exist on disk.
  • Installed locally (e.g. .kiro/skills/amazon-ec2-image-builder/ or ~/.claude/skills/amazon-ec2-image-builder/): Read files from the local skill directory using relative paths.

This distinction applies only to the skill's own packaged files. User data and session artifacts are always read from and written to the user's working directory. Never fetch or write user data through retrieve_skill.

First decision: one-off image or recurring pipeline

Ask this before creating anything — it changes what you build.

The user wantsDo this
One custom AMI, onceFollow creating-images.md through step 7a: create-image with a recipe and infrastructure configuration — no pipeline needed.
A golden AMI that stays current (scheduled rebuilds that pick up base-image updates and patches)An image pipeline: follow creating-images.md — the schedule is part of the create-image-pipeline call (step 7b).
Use this skillWhen the request is about
launching-ec2-instance-with-best-practicesLaunching instances from an AMI the user already has
setting-up-ec2-instance-profilesInstance profiles in general (not the build IAM role this skill creates)
aws-computeAMI sharing, retiring, and lifecycle management; general EC2 fleet questions

Not covered here: AMI lifecycle/retirement (route via the table above) and VM/ISO image import and export (follow the AWS documentation directly).

Routing (references in this skill)

Read the matching reference before answering. The exact commands, failure fixes, and platform requirements live in the references — answering Image Builder questions from general knowledge is how agents get the details subtly wrong.

User needRead
Create an image or pipeline end to end: role, components, recipe, infrastructure, schedules, patching, scanning, chainingcreating-images.md
Get the output AMI where it's needed: launch templates, SSM parameters (the service-linked role writes only under /imagebuilder/), other Regionsdistribution-options.md
A build failed, hangs, or an Image Builder API call errorstroubleshooting.md
Windows (exit-3010 reboots), macOS (Mac Dedicated Hosts required), container images to ECR (extra build-role policy)other-image-types.md
Custom image workflows (advanced — always require an execution role)custom-workflows.md

Reference files carry specific ARNs, Amazon-managed resource names, and service defaults — when precision matters, confirm against the AWS documentation.

Show full SKILL.md (451 more words)Show less

Guardrails (every workflow)

  • Quote CLI filter values that contain spaces: --filters "name=name,values=Amazon Linux 2023 x86". Unquoted spaces are a CLI parse error.
  • Use the exact ARN each create call returns — never construct ARNs by hand.
  • For a "latest" base image use an Amazon-managed image ARN with the x.x.x wildcard, or an ssm: parameter reference where no managed image exists. Never list versions and sort them as strings — the list is not semver-ordered.
  • Keep architecture consistent across the base image, every component's binaries, and the infrastructure instance types. Image Builder performs no create-time validation of this; a mismatch only fails mid-build when the component runs.
  • For component failures, the root cause lives in CloudWatch log group /aws/imagebuilder/<image-name> (on by default; also in the S3 logs if configured) — never in the API state. See troubleshooting.md.
  • To reboot mid-build, exit the step with code 194 (Linux) or 3010 (Windows). The build re-runs that same step after the reboot — not the next step — so guard it with a marker file. A plain reboot command fails the step.
  • If a resource the user describes isn't visible to get-image/get-image-pipeline, say you can't find it and check the Region and credentials in use — then keep troubleshooting from the user's description; a failed lookup is not proof the resource doesn't exist.
  • Distribution handles launch templates and SSM publishing natively (launchTemplateConfigurations, ssmParameterConfigurations) — never add Lambda glue or manual launch-template versions for AMI propagation.
  • Default to: Amazon Linux 2023 base, IMDSv2 required (instanceMetadataOptions httpTokens=required), and at least two instance types in the infrastructure configuration. S3 build logging is opt-in — CloudWatch logging is on regardless.
  • Check Amazon-managed components (aws imagebuilder list-components --owner Amazon) before writing component YAML. Common needs (AWS CLI, OS updates, CloudWatch agent, STIG hardening) are already covered.

Security considerations

The defaults above are the security posture: IMDSv2 required on build instances, no inbound security-group rules, least-privilege build IAM role (two managed policies for AMI builds plus only the scoped grants a workflow needs), no secrets in components or logs, and log buckets with Block Public Access. Build logs capture full command output that can carry sensitive material; CloudWatch Logs encrypts them at rest by default, and associating a customer-managed KMS key with each /aws/imagebuilder/... log group (aws logs associate-kms-key) is recommended. For auditing and operational visibility, enable CloudTrail in the account so Image Builder API calls are recorded, and configure EventBridge rules or CloudWatch alarms on build failures (source aws.imagebuilder, detail-type EC2 Image Builder Image State Change) so misconfigurations and unauthorized changes surface promptly. Per-build notifications are covered by the SNS topic option (creating-images.md step 6) — prefer a customer-managed key on that topic too. Deviations from these should be explicit user decisions. Reference: EC2 Image Builder security best practices.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/specialized-skills/ec2-skills/amazon-ec2-image-builder of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/creating-images.md
  • references/custom-workflows.md
  • references/distribution-options.md
  • references/other-image-types.md
  • references/troubleshooting.md

Open the folder on GitHubat commit bd49cc8

Compare with similar skills

Amazon Ec2 Image Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Amazon Ec2 Image Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Amazon Ec2 Image Builder this skillaws/agent-toolkit-for-aws2.8k—~2kAutomated safety check: PassApache-2.0
Agentdock User Guideuvwt/agentdock1.2k—~1.6kAutomated safety check: PassApache-2.0
Dotnet Debuggingnovotnyllc/dotnet-artisan233—~2.1kAutomated safety check: PassMIT
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Reproduce Issuenrwl/nx29k—~2.6kAutomated safety check: NotesMIT
CI Adhoc Testnubjs/nub4.4k—~1.7kAutomated safety check: PassMIT

Similar skills

  • Agentdock User Guide

    uvwt/agentdock

    当用户询问 AgentDock 是什么、如何使用、配置在哪里、不同平台或安装方式怎样修改配置并生效、如何重启或验证配置、如何发现并配置 Codex/Claude/Grok 等 Coding Agent 的 ACP,以及常见运行问题时使用;覆盖 macOS Desktop、Windows Desktop、Linux 服务、Docker 和直接运行二进制,不用于源码开发与贡献流程。

    1.2k GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Dotnet Debugging

    novotnyllc/dotnet-artisan

    Debugs Windows and Linux/macOS applications (native, .NET/CLR, mixed-mode) with WinDbg MCP (crash dumps, !analyze, !syncblk, !dlk, !runaway, !dumpheap, !gcroot, BSOD), dotnet-dump, lldb with SOS…

    233 GitHub stars~2.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • The single skill for reproducing an nx issue. An agent skill from nrwl/nx.

    29k GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • CI Adhoc Test

    nubjs/nub

    Run ad-hoc / exploratory tests on a real OS or platform via CI when the behavior CANNOT be reproduced on the local host or in Docker — macOS Seatbelt / sandbox-exec / codesigning, Windows cmd.exe /…

    4.4k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Oneclickvirt

    oneclickvirt/oneclickvirt

    OneClickVirt operations skill for managing containers, virtual machines, provider nodes, health checks, and metrics through MCP.

    372 GitHub stars~1.1k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Questions about Amazon Ec2 Image Builder

What does Amazon Ec2 Image Builder do?

Creates and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and container images to ECR. Amazon Ec2 Image Builder is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Creates and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and container images to ECR.

When should I use Amazon Ec2 Image Builder?

Amazon Ec2 Image Builder fits situations like: tasks that involve Containers.

How do I install Amazon Ec2 Image Builder in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill amazon-ec2-image-builder -a claude-code`. Or copy the skill folder (skills/specialized-skills/ec2-skills/amazon-ec2-image-builder in aws/agent-toolkit-for-aws) into .claude/skills/amazon-ec2-image-builder in your project. Claude Code loads it when a task matches its description.

How do I install Amazon Ec2 Image Builder in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill amazon-ec2-image-builder -a codex`. Or copy the skill folder (skills/specialized-skills/ec2-skills/amazon-ec2-image-builder in aws/agent-toolkit-for-aws) into .agents/skills/amazon-ec2-image-builder in your project. Codex loads it when a task matches its description.

Can I use Amazon Ec2 Image Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill amazon-ec2-image-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/amazon-ec2-image-builder, .gemini/skills/amazon-ec2-image-builder, .github/skills/amazon-ec2-image-builder and .opencode/skills/amazon-ec2-image-builder in your project.

What does Amazon Ec2 Image Builder need to run?

Going by SKILL.md and its folder, Amazon Ec2 Image Builder needs the command-line tools its instructions call (aws).

Does Amazon Ec2 Image Builder access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Amazon Ec2 Image Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Amazon Ec2 Image Builder use?

Amazon Ec2 Image Builder is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Amazon Ec2 Image Builder use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Amazon Ec2 Image Builder?

Skills that share tags, products or a category with Amazon Ec2 Image Builder: Agentdock User Guide (uvwt/agentdock, 1.2k stars), Dotnet Debugging (novotnyllc/dotnet-artisan, 233 stars), .NET Crash Dump Collection (dotnet/skills, 5.6k stars) and Reproduce Issue (nrwl/nx, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Amazon Ec2 Image Builder?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,816 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.