Official agent skill

Authoring Mwaa Workflow

by aws in aws/agent-toolkit-for-aws

Authors and deploys MWAA workflow artifacts: Python Airflow DAGs for provisioned environments or YAML workflow files for Serverless.

OfficialApache-2.0Auto-check passedData & Analytics

Install Authoring Mwaa Workflow

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill authoring-mwaa-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws authoring-mwaa-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aws-data-analytics/skills/authoring-mwaa-workflow .claude/skills/authoring-mwaa-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
authoring-mwaa-workflow
GitHub stars
2.8k
Token cost
~2.8k tokens
SKILL.md length
1,168 words
Files
7 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Authors and deploys MWAA workflow artifacts: Python Airflow DAGs for provisioned environments or YAML workflow files for Serverless.

  • Works in 4 steps: Resolvable target provided? A target… → Both-path keywords present? If the… → Exactly one path keyword? Treat only… → …
  • Write a pipeline
  • SKILL.md covers Guardrail — where this skill's…, Step 0: Route to Path, Paths and Deploy & Test (optional, after…, plus 3 more sections
  • Calls python and aws

What it does

Authoring Mwaa Workflow is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Authors and deploys MWAA workflow artifacts: Python Airflow DAGs for provisioned environments or YAML workflow files for Serverless. Covers operator selection, timeout design, retry strategy, scheduling, failure notifications, idempotency, and MWAA Serverless schema compliance. Deploys the artifact (S3 DAG upload or Serverless CreateWorkflow/UpdateWorkflow), creates an environment inline when approved, and redeploys fixes, then optionally hands off to testing-mwaa-workflow. Triggers on: create a DAG, write a…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/authoring-provisioned-dag.md`, `references/authoring-serverless-workflow.md` and `references/dag-patterns.md`).

It sits in Data & Analytics, covering Data pipelines and ETL, Serverless and File uploads and storage. It works with Apache Airflow, Amazon Web Services, Python and Model Context Protocol. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Write a pipeline
  • Build a workflow
  • Orchestrate tasks
  • Deploy a workflow

Example prompts

  • “Use the authoring-mwaa-workflow skill to author and deploys MWAA workflow artifacts: Python Airflow DAGs for provisioned environments or YAML…”
  • “/authoring-mwaa-workflow”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Resolvable target provided? A target reference is a definitive
  2. Both-path keywords present? If the request contains keywords from
  3. Exactly one path keyword? Treat only deployment-target terms as Path A
  4. No routing signal? "DAG" or "Workflow" alone is ambiguous — it does

What it can do on your machine

Read from SKILL.md and the folder at commit df2ab44. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Authoring Mwaa Workflow loads about 2.8k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 236 tokens; SKILL.md has 1,168 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~236
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit df2ab44, republished under its Apache-2.0 licence (© aws). 1,168 words, ~2,793 tokens.

Download SKILL.mdSave it as .claude/skills/authoring-mwaa-workflow/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
authoring-mwaa-workflow
description
Authors and deploys MWAA workflow artifacts: Python Airflow DAGs for provisioned environments or YAML workflow files for Serverless. Covers operator selection, timeout design, retry strategy, scheduling, failure notifications, idempotency, and MWAA Serverless schema compliance. Deploys the artifact (S3 DAG upload or Serverless CreateWorkflow/UpdateWorkflow), creates an environment inline when approved, and redeploys fixes, then optionally hands off to testing-mwaa-workflow. Triggers on: create a DAG, write a pipeline, build a workflow, orchestrate tasks, Airflow DAG, data pipeline, schedule a job, deploy a DAG, deploy a workflow, YAML workflow. Not applicable to converting or migrating existing DAGs between provisioned and serverless (conversion is out of scope), running or smoke-testing a deployed workflow (handled by testing-mwaa-workflow) or diagnosing a failed run (handled by debugging-mwaa-workflow).
metadata.version
1

Authoring MWAA Workflows

AWS MCP server (optional but recommended): running the AWS CLI commands in this skill through the AWS MCP server gives sandboxed execution and audit logging. Every command here also works with the plain AWS CLI, so the skill does not require the MCP server or any MCP-only tools.

Author production-grade workflow artifacts for Amazon MWAA. Routes to one of two paths: Python DAG (provisioned) or YAML workflow (Serverless).

Execution note — poll in discrete steps: whenever you wait for an AWS operation to reach a terminal or ready state, issue one status check per call and decide in your own loop whether to check again. Never block a single command or script on the wait (no while+sleep until done), regardless of the operation or how long it takes.

Guardrail — where this skill's own files live (MCP vs local install)

This skill can be loaded two ways, and they resolve the skill's own bundled files from different places. Determine how the skill was loaded before reading a reference:

  • Loaded through the AWS MCP retrieve_skill tool: The skill is not installed on the local filesystem. You MUST fetch each reference via retrieve_skill with the file parameter (e.g. file="references/authoring-provisioned-dag.md") and read the returned content. Do NOT file_read these paths locally — they do not exist on disk.
  • Installed locally (e.g. .kiro/skills/authoring-mwaa-workflow/ or ~/.claude/skills/authoring-mwaa-workflow/): Read the files from the local skill directory using relative paths.

This distinction applies only to the skill's own packaged files. User data and session artifacts are always read from and written to the user's working directory. Never fetch or write customer data through retrieve_skill.

Step 0: Route to Path

Evaluate in this order:

  1. Resolvable target provided? A target reference is a definitive routing signal regardless of other keywords:
    • A provisioned environment (ARN like arn:aws:airflow:<region>:<account>:environment/<name>, or a name resolvable via aws mwaa get-environment) → go to Path A.
    • A Serverless workflow ARN (arn:aws:airflow-serverless:<region>:<account>:workflow/<name>) → go to Path B.
  2. Both-path keywords present? If the request contains keywords from both paths and no resolvable target, disambiguate by intent:
    • PythonOperator is supported on Serverless, so an operator-level python cue (PythonOperator, python_callable, "Python function/task") alongside a Path B signal (yaml, serverless, workflow ARN) is NOT ambiguous → go to Path B.
    • Conversion context ("convert my Python DAG to serverless") → this skill does not apply; conversion is out of scope.
    • A genuine provisioned cue (Python DAG, provisioned) alongside a Serverless cue with no target → ask the clarifying question.
  3. Exactly one path keyword? Treat only deployment-target terms as Path A signals: provisioned, Python DAG, or "a .py for my environment" → go to Path A. yaml or serverless → go to Path B. Operator-level Python mentions are not Path A signals.
  4. No routing signal? "DAG" or "Workflow" alone is ambiguous — it does NOT indicate a path. Ask: is the target MWAA provisioned (Python DAG) or MWAA Serverless (YAML)?

Paths

Follow the reference for the path you routed to (you do not need the other path's reference):

After the routed path's Write step, continue with Deploy & Test below.

Deploy & Test (optional, after Write)

Authoring owns all deployment and redeployment. Detail in references/deploying-mwaa.md.

Show full SKILL.md (639 more words)Show less
Steps
  1. Ask — present options based on whether the artifact has a schedule. Frame the question using path-appropriate language:

    • Provisioned: "deploy this DAG to an environment" (DAGs are uploaded to an environment's S3 bucket).
    • Serverless: "deploy this workflow" (workflows are standalone resources — never say "deploy to an environment").

    If the DAG/workflow has a schedule:

    • Deploy and test — deploy, unpause, trigger a run now
    • Deploy and unpause — deploy, unpause, let it run on schedule (no immediate trigger)
    • Deploy only — upload to S3, leave paused

    If the DAG/workflow has no schedule (manual-trigger only):

    • Deploy and test — deploy, trigger a run now
    • Deploy only — upload to S3, leave paused (no "unpause" option — nothing to schedule)

    The user may also decline all options.

  2. Deploy:

    • Provisioned: upload the DAG to the environment's SourceBucketArn/ DagS3Path. Run post-deploy verification (see deploying-mwaa.md) to confirm the scheduler parsed the new file without import errors or dag_id conflicts. If no environment exists and the user approves, create one inline (plan-validate-execute + explicit confirmation), then poll CREATING -> AVAILABLE (~20-40 min). The user may instead supply an existing environment.
    • Serverless: CreateWorkflow (new) or UpdateWorkflow (redeploy); the YAML is validated synchronously here. If the workflow uses PythonOperator/BashOperator, first build and upload the code package to S3 and pass it via --code (see references/serverless-code-packaging.md and references/deploying-mwaa.md). The user may instead supply an existing ARN.
    • Redeploy (fix loop): the same upload / UpdateWorkflow path, reused when testing-mwaa-workflow delegates an ARTIFACT or ENVIRONMENT fix.
  3. If "Deploy and unpause" selected — deploy per step 2, then unpause. Do not trigger a run or invoke testing-mwaa-workflow.

  4. If "Deploy and test" selected — deploy per step 2, unpause if applicable, then invoke testing-mwaa-workflow with the resolved target (env name + dag_id, or workflow ARN). That hand-off is testing's delegated invocation mode.

HARD GATE: If testing is requested — whether upfront ("deploy and test") or later in the conversation ("test it", "run it", "try it") — you MUST invoke testing-mwaa-workflow. Do NOT trigger, monitor, or verify DAG runs manually. "Deploy and unpause" is NOT a test request — it is a deploy-only action.

  • Production safety: create-environment, update-environment, create-workflow, and update-workflow mutate state — confirm each with its impact stated. Warn on prod-named targets.

Troubleshooting

ErrorCauseFix
dagrun_timeout kills DAG early< timeout set in service calledRaise dagrun_timeout or lower service timeout
YAML validation rejects workflowWrong type or paramUse timedelta format; check allowlist
Operator not found in ServerlessNot allowlistedUse a supported operator, PythonOperator/BashOperator, or Lambda
Serverless run: cannot extract code / corrupt envBad code packageFiles at zip root, no __pycache__, ≤250 MB; repackage
Serverless Python task ImportErrorMissing dep or wrong-platform wheelBundle as manylinux2014_x86_64 / Py3.12 wheel; don't bundle pre-installed packages
Template variable undefinedVersion mismatchCheck vars for exact Airflow version

References

Security Considerations

  • State-mutating operations (create/update-environment, create/update-workflow, S3 DAG upload) require explicit confirmation with impact stated; warn on prod-named targets (see the Deploy HARD-GATE).
  • Least-privilege IAM: the A5 check adds only the exact Action/Resource pairs the artifact needs — never *FullAccess or service:*.
  • No hardcoded secrets/endpoints: use Airflow Variables/Connections backed by Secrets Manager or SSM Parameter Store; never emit credentials in DAG code or CLI examples.
  • Serverless code packages ship only the user's own modules plus pinned, platform-matched wheels — no unreviewed third-party binaries.
  • Data protection: keep sensitive data out of SNS/CloudWatch notification payloads and logs; rely on their encryption.
  • Secure defaults for inline-created resources: encrypt and lock down any S3/MWAA/SNS/CloudWatch resource this skill creates — see deploying-mwaa.md "Secure defaults".
  • AWS security best practices: verify the security posture against the MWAA User Guide's Security best practices page (and the MWAA Serverless equivalent) at runtime — AWS updates them over time; see deploying-mwaa.md "Secure defaults".

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/aws-data-analytics/skills/authoring-mwaa-workflow of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/authoring-provisioned-dag.md
  • references/authoring-serverless-workflow.md
  • references/dag-patterns.md
  • references/deploying-mwaa.md
  • references/serverless-code-packaging.md
  • references/yaml-schema.md

Open the folder on GitHubat commit df2ab44

Compare with similar skills

Authoring Mwaa Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Authoring Mwaa Workflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Authoring Mwaa Workflow this skillaws/agent-toolkit-for-aws2.8k—~2.8kAutomated safety check: PassApache-2.0
Ingesting Dataancoleman/ai-design-components526—~1.9kAutomated safety check: PassMIT
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT
Neon Functionsneondatabase/agent-skills100—~12kAutomated safety check: NotesApache-2.0
AWS Lambda Durable Functionsawslabs/agent-plugins915—~2.3kAutomated safety check: PassApache-2.0
Airflow Pluginsastronomer/agents451—~6kAutomated safety check: NotesApache-2.0

Similar skills

  • Ingesting Data

    ancoleman/ai-design-components

    Data ingestion patterns for loading data from cloud storage, APIs, files, and streaming sources into databases.

    526 GitHub stars~1.9k tokensUpdated 10 mo ago
    Data & AnalyticsAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Neon Functions

    neondatabase/agent-skills

    Official

    Long-running, serverless Node.js HTTP functions deployed onto your Neon branch, with DATABASEURL injected automatically and compute that runs next to your data.

    100 GitHub stars~12k tokensUpdated today
    Backend & APIsAuto-check: notes
  • AWS Lambda Durable Functions

    awslabs/agent-plugins

    Official

    Build resilient, long-running, multi-step applications with AWS Lambda durable functions with automatic state persistence, retry logic, and orchestration for long-running executions.

    915 GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Airflow Plugins

    astronomer/agents

    Builds Airflow 3.1+ plugins that embed FastAPI apps, custom UI pages, React components, middleware, macros, and operator links directly into the Airflow UI.

    451 GitHub stars~6k tokensUpdated yesterday
    Data & AnalyticsAuto-check: notes
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Questions about Authoring Mwaa Workflow

What does Authoring Mwaa Workflow do?

Authors and deploys MWAA workflow artifacts: Python Airflow DAGs for provisioned environments or YAML workflow files for Serverless. Authoring Mwaa Workflow is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Authors and deploys MWAA workflow artifacts: Python Airflow DAGs for provisioned environments or YAML workflow files for Serverless.

When should I use Authoring Mwaa Workflow?

Authoring Mwaa Workflow fits situations like: write a pipeline; build a workflow; orchestrate tasks; deploy a workflow.

How do I install Authoring Mwaa Workflow in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill authoring-mwaa-workflow -a claude-code`. Or copy the skill folder (plugins/aws-data-analytics/skills/authoring-mwaa-workflow in aws/agent-toolkit-for-aws) into .claude/skills/authoring-mwaa-workflow in your project. Claude Code loads it when a task matches its description.

How do I install Authoring Mwaa Workflow in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill authoring-mwaa-workflow -a codex`. Or copy the skill folder (plugins/aws-data-analytics/skills/authoring-mwaa-workflow in aws/agent-toolkit-for-aws) into .agents/skills/authoring-mwaa-workflow in your project. Codex loads it when a task matches its description.

Can I use Authoring Mwaa Workflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill authoring-mwaa-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/authoring-mwaa-workflow, .gemini/skills/authoring-mwaa-workflow, .github/skills/authoring-mwaa-workflow and .opencode/skills/authoring-mwaa-workflow in your project.

What does Authoring Mwaa Workflow need to run?

Going by SKILL.md and its folder, Authoring Mwaa Workflow needs the command-line tools its instructions call (python and aws). Our summary lists: Python 3.

Does Authoring Mwaa Workflow access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Authoring Mwaa Workflow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Authoring Mwaa Workflow use?

Authoring Mwaa Workflow is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Authoring Mwaa Workflow use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Authoring Mwaa Workflow?

Skills that share tags, products or a category with Authoring Mwaa Workflow: Ingesting Data (ancoleman/ai-design-components, 526 stars), AWS Serverless Eda (zxkane/aws-skills, 367 stars), Neon Functions (neondatabase/agent-skills, 100 stars) and AWS Lambda Durable Functions (awslabs/agent-plugins, 915 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Authoring Mwaa Workflow?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,830 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 9, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.