Isolated Linux Agent Workspace
agent-sh/agent-workspace-linux
Drives a hidden, agent-owned Linux desktop and browser over MCP for GUI testing and web automation without touching the user's real desktop.
Connects AI agents to remote Windows desktop applications on Amazon WorkSpaces Applications (AppStream 2.0) through the managed Agent Access MCP server, and guides reliable desktop automation.
$ npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/agent-toolkit-for-aws amazon-workspaces-agent-access --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access .claude/skills/amazon-workspaces-agent-access && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "amazon-workspaces-agent-access" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access into .claude/skills/amazon-workspaces-agent-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "amazon-workspaces-agent-access", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-accessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/agent-toolkit-for-aws amazon-workspaces-agent-access --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access .agents/skills/amazon-workspaces-agent-access && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "amazon-workspaces-agent-access" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access into .agents/skills/amazon-workspaces-agent-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "amazon-workspaces-agent-access", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/agent-toolkit-for-aws amazon-workspaces-agent-access --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access .cursor/skills/amazon-workspaces-agent-access && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "amazon-workspaces-agent-access" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access into .cursor/skills/amazon-workspaces-agent-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "amazon-workspaces-agent-access", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/agent-toolkit-for-aws.git --path skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/agent-toolkit-for-aws amazon-workspaces-agent-access --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access .gemini/skills/amazon-workspaces-agent-access && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "amazon-workspaces-agent-access" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access into .gemini/skills/amazon-workspaces-agent-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "amazon-workspaces-agent-access", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/agent-toolkit-for-aws amazon-workspaces-agent-accessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access .github/skills/amazon-workspaces-agent-access && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "amazon-workspaces-agent-access" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access into .github/skills/amazon-workspaces-agent-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "amazon-workspaces-agent-access", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/agent-toolkit-for-aws amazon-workspaces-agent-access --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access .opencode/skills/amazon-workspaces-agent-access && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "amazon-workspaces-agent-access" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access into .opencode/skills/amazon-workspaces-agent-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "amazon-workspaces-agent-access", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
amazon-workspaces-agent-accessConnects AI agents to remote Windows desktop applications on Amazon WorkSpaces Applications (AppStream 2.0) through the managed Agent Access MCP server, and guides reliable desktop automation.
Amazon Workspaces Agent Access is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Connects AI agents to remote Windows desktop applications on Amazon WorkSpaces Applications (AppStream 2.0) through the managed Agent Access MCP server, and guides reliable desktop automation. Covers connecting an agent to the MCP endpoint (SigV4, streaming URL, and Active Directory SAML/Domain Join), BLOCKING vs POLLING connect modes, the computer-use tools (screenshot, click, type, key, scroll), screenshot-budget and action-batching discipline, MCP tool forwarding (forwarded tools), session lifecycle and…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/automation-best-practices.md`, `references/connection-modes.md` and `references/connection-setup.md`).
It sits in Productivity & Automation, covering MCP servers, Desktop control and Red teaming and adversary simulation. It works with Model Context Protocol and Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit bd49cc8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comagentaccess-mcp.us-east-1.api.awsFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Amazon Workspaces Agent Access loads about 2.7k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 254 tokens; SKILL.md has 1,084 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/agent-toolkit-for-aws at commit bd49cc8, republished under its Apache-2.0 licence (© aws). 1,084 words, ~2,736 tokens.
.claude/skills/amazon-workspaces-agent-access/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Domain expertise for connecting AI agents to remote Windows desktops on Amazon WorkSpaces Applications (AppStream 2.0) via the managed Agent Access MCP server, and for driving those desktops reliably.
How it works: Agent Access is MCP-only — there is no AWS CLI/SDK command that calls the desktop tools. Agents connect to https://agentaccess-mcp.{region}.api.aws/mcp over Streamable HTTP, SigV4-signed with service name agentaccess-mcp, and call MCP tools (screenshot, left_click, type_text, ...) to drive the desktop. The AWS CLI/SDK is used only for setup — appstream create-streaming-url, fleet/stack configuration. mcp-proxy-for-aws handles the SigV4 signing.
Recommended setup: use mcp-proxy-for-aws (Python) as the transport; it signs each request and manages the DELETE lifecycle. Any MCP client that supports Streamable HTTP + SigV4 works. When running the AWS CLI/SDK setup steps (create-streaming-url, stack/fleet configuration), the AWS MCP server is recommended for sandboxed execution and audit logging.
This skill can be loaded two ways, and they resolve the skill's own bundled files from different places. Determine how the skill was loaded before reading a reference:
retrieve_skill tool: The skill is not installed on the local filesystem. You MUST fetch each reference via retrieve_skill with the file parameter (e.g. file="references/connection-setup.md"), and use the returned content. Do NOT file_read these paths locally — they do not exist on disk..kiro/skills/amazon-workspaces-agent-access/ or ~/.claude/skills/amazon-workspaces-agent-access/): Read files from the local skill directory using relative paths.This distinction applies only to the skill's own packaged files. User data and session artifacts are always read from and written to the user's working directory. Never fetch or write customer data through retrieve_skill.
These are HTTP headers / metadata on the MCP connection — not tool parameters, and there is no connect_to_desktop tool. Do not invent tools or parameters; the desktop tools are exactly those in tools-reference.md.
Connect mode. Selected by the X-Amzn-AgentAccess-Connect-Mode HTTP header (value BLOCKING, the default, or POLLING) — sent on the MCP request alongside the streaming-URL/SAML auth. It is NOT a JSON tool argument.
❌ WRONG (common hallucination): calling a connect_to_desktop tool with a connection_mode: "POLLING" parameter, or a session_id/application_id/user_id argument. None of those exist.
✅ RIGHT: set the X-Amzn-AgentAccess-Connect-Mode: POLLING header. Then tools/list initially returns only the connection_status tool; the agent calls connection_status repeatedly until its returned state is CONNECTED, and only then does tools/list return the full desktop tool set (screenshot, left_click, ...). (details: connection-modes.md)
# Correct POLLING usage — the mode is an HTTP header on the MCP connection:
async with aws_iam_streamablehttp_client(
endpoint="https://agentaccess-mcp.us-east-1.api.aws/mcp", # use YOUR fleet's region
aws_service="agentaccess-mcp", aws_region="us-east-1", # region must match the fleet (else 400)
headers={
"X-Amzn-AgentAccess-Streaming-Session-Url": streaming_url,
"X-Amzn-AgentAccess-Connect-Mode": "POLLING", # header, not a tool arg
},
) as (read, write, _):
async with ClientSession(read, write) as session:
await session.initialize()
# tools/list now returns ONLY connection_status until the desktop is up:
while json.loads((await session.call_tool("connection_status", {})).content[0].text)["state"] != "CONNECTED":
await asyncio.sleep(2)
tools = await session.list_tools() # now the full desktop tool setStreaming session (non-domain-joined) is the X-Amzn-AgentAccess-Streaming-Session-Url header. Domain-joined fleets instead pass the SAML assertion + stack ARN via MCP _meta keys aws.agentaccess/workspacesApplicationsSamlAssertion and aws.agentaccess/workspacesApplicationsStackArn. (details: connection-setup.md)
Expire-on-delete is the X-Amzn-AgentAccess-Expire-Streaming-Session-On-Delete header (true/false; default false). Expiry happens on the client's explicit HTTP DELETE — mcp-proxy-for-aws sends it automatically on clean close. (details: session-lifecycle.md)
Forwarded tools are namespaced by server: forwarded___<server-name>___<tool-name> (e.g. forwarded___filesystem___read_file) — not forwarded___<tool-name>. (details: tool-forwarding.md)
COMPUTER_INPUT requires COMPUTER_VISION to also be ENABLED in the stack's AgentAccessConfig. (details: enabling-agent-access.md)
| User need | Read |
|---|---|
Enable agent access on a stack (AgentAccessConfig: COMPUTER_INPUT/COMPUTER_VISION/FORWARD_MCP_TOOLS, screen resolution/format, prerequisites) — the admin setup step before any agent can connect | enabling-agent-access.md |
| Connect an agent to the MCP server — endpoint, SigV4, streaming URL (non-domain-joined), or Active Directory SAML/Domain Join | connection-setup.md |
Choose BLOCKING vs POLLING; poll connection_status until the desktop is ready | connection-modes.md |
| The computer-use tool set (mouse, keyboard, screenshot) and their parameters | tools-reference.md |
| Automate reliably — screenshot budget, action batching, trusting UI actions, coordinate planning, dialog recovery | automation-best-practices.md |
Expose your own MCP servers on the fleet as forwarded___<server>___<tool> tools; prefer forwarded tools for file/web tasks | tool-forwarding.md |
| Session lifecycle — cleanup, expire-on-delete, idle timeout, one-agent-per-session | session-lifecycle.md |
Debug an error (exact string → cause → fix): dcv session not ready, client_disconnected, 400/401/403, Unknown tool | troubleshooting.md |
agentaccess-mcp; the desktop session runs with those credentials. Grant only the specific agentaccess-mcp actions the agent calls (e.g. InvokeMcp, GetScreenshot, LeftClick, TypeText) and scope them with the agentaccess-mcp:StackArn condition key — avoid a blanket agentaccess-mcp:* or Resource: *. Prefer IAM roles over long-lived users. (Full action list + example: connection-setup.md → IAM permissions.)COMPUTER_VISION captures whatever is on the desktop — treat screenshots as potentially containing PII or secrets. If screenshot storage is enabled, the S3 bucket must enforce encryption at rest and in transit and least-privilege access: grant the AppStream service principal only what it needs and the connecting agent only s3:PutObject (see enabling-agent-access.md).COMPUTER_INPUT, COMPUTER_VISION, and FORWARD_MCP_TOOLS are independent — do not enable input/forwarding on stacks that only need vision.FORWARD_MCP_TOOLS, and scope the CallForwardedTool IAM action by agentaccess-mcp:StackArn (see tool-forwarding.md).UserControlMode: VIEW_STOP lets an observer watch the live session and stop the agent. Treat agent-driven desktop actions as capable of arbitrary UI operations.agentaccess-mcp data events enabled, encrypt it with SSE-KMS, and add CloudWatch alarms for anomalous patterns (e.g. high screenshot volume, unexpected TypeText, repeated auth failures). If screenshot storage is enabled, turn on S3 server access logging for the bucket.type_text can enter secrets (passwords, tokens); these may then appear in screenshots, screenshot-storage S3, and CloudTrail data events. Avoid typing long-lived secrets into the desktop where possible, and restrict who can read those sinks.Note: Regional endpoints, feature availability, and quotas change. When precision matters, confirm against the current Agent Access MCP server documentation. The references focus on the values and gotchas that are easy to get wrong.
© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (references) in skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access of aws/agent-toolkit-for-aws.
Open the folder on GitHubat commit bd49cc8
Amazon Workspaces Agent Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Amazon Workspaces Agent Access this skillaws/agent-toolkit-for-aws | 2.8k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Isolated Linux Agent Workspaceagent-sh/agent-workspace-linux | 185 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Windows CLIsbroenne/mcp-windows | 105 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Linux Desktop Controlagent-sh/computer-use-linux | 661 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Browser MCP Agentantibrow/anti-detect-browser-skills | 914 | 1 repos | ~4.2k | Automated safety check: Warn | MIT | |
| Altic Studioaltic-dev/altic-mcp | 172 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 |
agent-sh/agent-workspace-linux
Drives a hidden, agent-owned Linux desktop and browser over MCP for GUI testing and web automation without touching the user's real desktop.
sbroenne/mcp-windows
Guidance for driving Windows desktop automation from the wincli command-line tool - the token-efficient entry point that mirrors the Windows MCP server.
agent-sh/computer-use-linux
Lets an agent observe and operate a local Linux desktop through the computer-use-linux MCP server or Pi tools: accessibility trees, screenshots, windows and input.
antibrow/anti-detect-browser-skills
Give an AI agent its own real browser over MCP tool calls - launch, navigate, click, fill, screenshot, extract text, run JS - with a kernel-level real-device fingerprint and a persistent profile, so…
altic-dev/altic-mcp
macOS automation skill for AppleScript actions and Chrome browser control via MCP CDP tools.
QwenLM/qwen-code-examples
Control the local desktop using the computer MCP tool from computer-use-mcp.
aws/agent-toolkit-for-aws
Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.
aws/agent-toolkit-for-aws
A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.
aws/agent-toolkit-for-aws
Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.
aws/agent-toolkit-for-aws
Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.
aws/agent-toolkit-for-aws
Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…
aws/agent-toolkit-for-aws
A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.
Connects AI agents to remote Windows desktop applications on Amazon WorkSpaces Applications (AppStream 2.0) through the managed Agent Access MCP server, and guides reliable desktop automation. Amazon Workspaces Agent Access is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization.0) through the managed Agent Access MCP server, and guides reliable desktop automation.
Amazon Workspaces Agent Access fits situations like: debugging an agent that drives a remote Windows desktop; GUI application via WorkSpaces Applications / AppStream — including dcv session not ready; clientdisconnected; 400 signing-region.
Run `npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a claude-code`. Or copy the skill folder (skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access in aws/agent-toolkit-for-aws) into .claude/skills/amazon-workspaces-agent-access in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a codex`. Or copy the skill folder (skills/specialized-skills/end-user-computing-skills/amazon-workspaces-agent-access in aws/agent-toolkit-for-aws) into .agents/skills/amazon-workspaces-agent-access in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill amazon-workspaces-agent-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/amazon-workspaces-agent-access, .gemini/skills/amazon-workspaces-agent-access, .github/skills/amazon-workspaces-agent-access and .opencode/skills/amazon-workspaces-agent-access in your project.
SKILL.md names no scripts, command-line tools or credentials: Amazon Workspaces Agent Access is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and agentaccess-mcp.us-east-1.api.aws. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Amazon Workspaces Agent Access is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Amazon Workspaces Agent Access: Isolated Linux Agent Workspace (agent-sh/agent-workspace-linux, 185 stars), Windows CLI (sbroenne/mcp-windows, 105 stars), Linux Desktop Control (agent-sh/computer-use-linux, 661 stars) and Browser MCP Agent (antibrow/anti-detect-browser-skills, 914 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,816 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.
Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.