Cloud Architect
Jeffallan/claude-skills
Designs cloud architectures, migration plans, cost optimization recommendations and disaster recovery strategies across AWS, Azure and GCP.
AWS Backup coverage and data protection posture review. An agent skill from aws/tools-for-devops-agent.
$ npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent aws-backup-coverage-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aws-backup-coverage-review .claude/skills/aws-backup-coverage-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aws-backup-coverage-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-backup-coverage-review into .claude/skills/aws-backup-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-backup-coverage-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-backup-coverage-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent aws-backup-coverage-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/aws-backup-coverage-review .agents/skills/aws-backup-coverage-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aws-backup-coverage-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-backup-coverage-review into .agents/skills/aws-backup-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-backup-coverage-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent aws-backup-coverage-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/aws-backup-coverage-review .cursor/skills/aws-backup-coverage-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aws-backup-coverage-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-backup-coverage-review into .cursor/skills/aws-backup-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-backup-coverage-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/aws-backup-coverage-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent aws-backup-coverage-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/aws-backup-coverage-review .gemini/skills/aws-backup-coverage-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aws-backup-coverage-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-backup-coverage-review into .gemini/skills/aws-backup-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-backup-coverage-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent aws-backup-coverage-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/aws-backup-coverage-review .github/skills/aws-backup-coverage-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aws-backup-coverage-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-backup-coverage-review into .github/skills/aws-backup-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-backup-coverage-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent aws-backup-coverage-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/aws-backup-coverage-review .opencode/skills/aws-backup-coverage-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aws-backup-coverage-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-backup-coverage-review into .opencode/skills/aws-backup-coverage-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-backup-coverage-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aws-backup-coverage-reviewAWS Backup coverage and data protection posture review. An agent skill from aws/tools-for-devops-agent.
AWS Backup Coverage Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. AWS Backup coverage and data protection posture review. Determines which backup-eligible resources are protected by AWS Backup and which are not, across all enabled Regions of an account, then evaluates backup plan frequency and retention, cross-Region and cross-account copies, vault encryption and Vault Lock, and per-Region resource type opt-in. Uses read-only control-plane API calls and produces a rated report with a coverage matrix and prioritized remediation. Use when a user asks about backup coverage…
Its SKILL.md is about 6.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 158 other files, including reference files and assets (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).
It sits in DevOps & Cloud, covering Backup and disaster recovery and Privacy and GDPR. It works with Amazon Web Services. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AWS Backup Coverage Review loads about 6.8k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 255 tokens; SKILL.md has 3,636 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 3,636 words, ~6,842 tokens.
.claude/skills/aws-backup-coverage-review/SKILL.md (or your agent's skills folder). This skill also uses 151 other files; get the full folder from GitHub.Perform a structured, read-only coverage and posture review of AWS Backup in one account across all enabled Regions. The review answers one question precisely — which backup-eligible resources are actually recoverable, and which are not — then explains why each gap exists and how to close it.
The only acceptable output of this skill is the full report defined in the Final Delivery Contract below. A conversational prose summary of the findings — however accurate, however well organised — is a failed run.
Every response must contain, in order: Scope (including Regions swept and not swept), Coverage Rating with a coverage percentage, Executive Summary, Coverage Matrix, Findings & Recommendations, a Check Coverage Matrix with all 23 rows, and Next Steps.
Three failure modes to avoid specifically, because all three feel natural in a chat:
If you cannot complete a section, render it with the explicit status values defined
below (AccessDenied, ToolingFailure, NotEnumerated) — never drop it.
Self-check before responding. Count the rows in your Check Coverage Matrix. If
the count is not exactly 23, or if the response contains no ## Coverage Rating
heading and no coverage percentage, the response is incomplete — fix it before
sending. Then verify the protected count and the coverage percentage are identical
everywhere they appear — Coverage Rating, headline, and the by-type table. A report
that states two different coverage figures is wrong regardless of which is correct.
Activate this skill when the user asks to:
Do NOT activate for restoring data or recovery execution, backup/restore job
failure triage, backup storage cost optimization, or RDS-native automated
backups and manual snapshots taken outside AWS Backup. For Amazon S3 bucket
versioning, replication, and Object Lock posture, storage-s3-resiliency-expertise
is the correct skill.
AWS Backup Audit Manager's BACKUP_RESOURCES_PROTECTED_BY_BACKUP_PLAN control
requires AWS Config recording, a framework, and a report plan that has already run.
Many accounts have none of that, so this skill computes the answer on demand from
read-only APIs, treating AWS Config as an optimization rather than a prerequisite.
use_aws
tool under the assumed role in the target account. No credentials or profile
are requested from the user.Coverage is not binary. Every eligible resource resolves to exactly one of six states. Getting this distinction right is the whole value of the review — a resource can sit inside a backup plan and still be unrecoverable.
| State | Meaning | Severity |
|---|---|---|
Protected | Has at least one recovery point, and the newest is within the plan's expected interval | ✅ |
Stale | Has recovery points, but the newest is older than the plan schedule allows | ⚠️ HIGH |
SelectedNotProtected | Matched by a backup selection but has zero recovery points — the plan has never successfully run for it | ❌ CRITICAL |
Unprotected | Eligible, matched by no selection, zero recovery points | ❌ CRITICAL |
OptInBlocked | Matched by a selection, but its resource type is not opted in for that Region, so AWS Backup will never protect it | ❌ CRITICAL |
OrphanedRecoveryPoint | Appears in ListProtectedResources but the resource itself no longer exists in the account | ⚠️ MEDIUM |
OrphanedRecoveryPoint is resolved from the opposite direction to the other five.
ListProtectedResources keeps returning a resource long after it is deleted, so
every entry it returns must be cross-checked against the live inventory. An
entry with no matching live resource is an orphaned recovery point: it is a
retention and cost issue, not a coverage gap. Never count it as Protected, never
count it as Stale, and never include it in the coverage numerator or denominator —
a deleted resource needs no protection. Report it, with the age of its newest
recovery point, so long-abandoned recovery points in unused Regions become visible.
OptInBlocked is the most commonly missed real finding, because the AWS Backup
console shows the plan and selection as correctly configured.
Never ask the user for the account or the Region list. Resolve silently:
sts:GetCallerIdentity.ec2:DescribeRegions with AllRegions=false (enabled Regions only).Region sweep discipline. Sweep every enabled Region unless the user
narrowed the scope. Do not shortcut to a handful of "likely" Regions — an
unprotected resource in an unswept Region is the exact thing this review exists to
find, and a Region looks empty only after it has been queried. A cheap probe
(ListProtectedResources plus one or two inventory calls) is enough to eliminate a
Region; drop it from further work once it returns nothing.
If any enabled Region was not swept, the report's Scope table must list it under "Regions not swept", and the Coverage Rating must be capped at Medium, because the denominator is incomplete. Never present a coverage percentage as account-wide when Regions were skipped.
If the user names a resource type AWS Backup does not support, state that plainly and continue with the supported types rather than aborting.
Work through these in order; each step depends on the one before it.
config:DescribeConfigurationRecorderStatus. If a recorder exists and
recording is true → Config fast path (one config:SelectResourceConfig
query per Region).Describe/List calls).fs_write to a
scratch path). This is the account-wide inventory; on a large sweep it will not
survive in context to Step 8, so it must exist on disk. Render the Coverage
Matrix from this file, not from memory.status field in the
collected data.
AccessDenied → present the permissions audit below.ToolingFailure → present the tooling notice below.If any check returned AccessDenied, present:
⚠️ The role is missing read permissions for some checks.
Check Missing action Status <check id and name><iam:Action>AccessDenied Coverage cannot be stated accurately without these — an unreadable resource type is not the same as an unprotected one.
How would you like to proceed?
- Stop here (recommended). Add the missing permissions and re-run.
- Continue with reduced accuracy. Affected resource types will be reported as
Unknown, excluded from the coverage percentage, and the Coverage Rating will be capped at Medium.
Wait for the user's response. Do NOT proceed by default.
If any check returned ToolingFailure, present:
⚠️ Tooling infrastructure failure — some checks could not reach the AWS API.
Check Status <check id and name>ToolingFailure How would you like to proceed?
- Stop here and retry later (recommended).
- Continue with partial data. Report will note the gaps; rating capped at Medium.
Wait for the user's response. Do NOT proceed by default.
One rating for the account, from the roll-up rules in the coverage logic reference:
| Rating | Criteria |
|---|---|
High | No CRITICAL findings, no OptInBlocked resources, coverage ≥ 95% of eligible resources, and every plan meets the frequency and retention thresholds |
Medium | No CRITICAL findings, coverage ≥ 80%, or any check capped by AccessDenied / ToolingFailure |
Low | Any CRITICAL finding, or coverage < 80% |
Indeterminate | The eligible inventory could not be established at all |
AccessDenied and ToolingFailure never lower the score. They cap the
rating at Medium. A permissions gap is not a coverage gap.
| Severity | Definition | SLA |
|---|---|---|
| CRITICAL | Data is unrecoverable, or believed protected when it is not | Fix within 24–48 hours |
| HIGH | Recovery is possible but materially degraded or at risk | Fix within 1 week |
| MEDIUM | Notable hardening or durability gap | Plan within 30 days |
| LOW | Minor optimization | Address when convenient |
| INFO | Observation, no action required | N/A |
Emoji map: CRITICAL → ❌ · HIGH → ⚠️ · MEDIUM → ⚠️ · LOW → ℹ️ · INFO → ℹ️ ·
pass → ✅ · unverifiable → 🚫
This defines how to deliver the full report the Output Contract already mandates; it does not restate that the report is the only acceptable output.
Delegating the account sweep to a research subagent is allowed, but the subagent
returns data, never the final answer. A subagent may not receive this skill's
references/ or assets/ files, so it cannot be trusted to render the report.
ToolingFailure for every resource type it was asked to cover,
not evidence those types are absent. Record it as ToolingFailure, name what
failed, and either re-collect that group directly or disclose it in the tooling
notice. Never treat a missing subagent return as "zero resources."The report's required sections, tables and validation rules are defined in the
report template — re-load it at Step 8, immediately
before rendering, even if it was read earlier in the run. If the runtime offers no
working-file tool (fs_write or equivalent), keep the sweep small enough to hold the
per-resource inventory in context — split into more, narrower Region groups — rather
than dropping the Coverage Matrix; the per-resource rows are required output, not an
optimization.
aws-backup-coverage-review-<account-id>-<YYYY-MM-DD>.md. If the runtime does
not support persisted artifacts, skip artifact creation and rely on step 3.A request that names specific Regions or resource types — "are my EBS volumes protected in us-east-1?", "check RDS backups in eu-west-1" — narrows what is swept, never what is rendered.
The one exception. If the full report for a scope that already covers the question was rendered earlier in this same conversation, answer the follow-up directly from it instead of re-rendering it. Repeating an identical report minutes later serves nobody.
This applies only when all three hold:
Say which earlier review the answer comes from, so the user can tell a grounded slice from a fresh opinion. This exception never applies to the first coverage-related response in a conversation — that is always the full report.
StartBackupJob, StartRestoreJob, StartCopyJob, or StartReportJob. See
the allowlist and hard denials in the
data collection reference.NotConfigured with AccessDenied. The first is a finding;
the second is a blind spot. They render differently and only the first affects
the rating.ListProtectedResources or ListRecoveryPointsByResource.SAP HANA on Amazon EC2 cannot be enumerated by this skill — list it as NotEnumerated, never as
covered. VirtualMachine is only unenumerable where a hypervisor is registered:
zero hypervisors from backup-gateway:ListHypervisors means zero resources, so
record it as having none rather than as a blind spot. Claiming a gap that does not
exist misstates the review's completeness as surely as missing one.ListBackupPlans returning zero plans is a
valid, high-severity finding, not a ToolingFailure.## Adjacent Observations section, clearly marked as outside the 23 checks. Never let them
displace a required section or silently become a finding row.ListBuckets but protected per Region. Resolve each
bucket's Region with GetBucketLocation and evaluate it against that Region's
opt-in setting. Never attribute the whole bucket list to one Region's opt-in
state — S3 can be opted in for one Region and out for another in the same
account.| Quirk | Consequence |
|---|---|
ListBackupPlans returns plan metadata only, not rules | Call GetBackupPlan per plan to read schedules, lifecycle, and copy actions |
ListBackupSelections returns selection metadata only | Call GetBackupSelection per selection to read tags, ARNs, and conditions |
ListProtectedResources, ListBackupPlans, ListRecoveryPointsByBackupVault, ListBackupJobs, ListBackupVaults all paginate | Follow NextToken to exhaustion; MaxResults caps at 1000 |
DescribeRegionSettings is per Region and has no pagination | Must be called once per Region; a missing key means the type defaults to opted in |
ListProtectedResources includes resources whose recovery points are EXPIRED or DELETING | Cross-check LastBackupTime before calling a resource protected |
ListProtectedResources is Region-scoped to the calling Region | Iterate Regions; do not assume it is global |
GetBackupVaultAccessPolicy returns ResourceNotFoundException when no policy exists | Classify as NotConfigured, not an error |
GetBackupVaultNotifications also raises ResourceNotFoundException when none are configured, with the misleading message Failed reading notifications from database for Backup vault | Classify as NotConfigured. This is the normal response for an unconfigured vault, not a ToolingFailure — do not retry it |
ListBackupSelections returns results under the key BackupSelectionsList | Reading a differently-named key yields a silent empty list, which makes every resource look Unprotected instead of SelectedNotProtected |
| A selection can reference a literal ARN for a resource that no longer exists | The plan then protects nothing through that entry while still looking healthy. Caught by check 3.6's dangling-ARN sub-check and by check 5.2 |
Aurora, Neptune, and DocumentDB all surface via rds:DescribeDBClusters | Separate them by the Engine field before mapping to AWS Backup resource types |
| Backup resource type names are not CloudFormation type names | EBS, not AWS::EC2::Volume. Map explicitly per the data collection reference |
Some read-only calls are cancelled as Cancelled mutative operation, independently of IAM | The state is unknown, so the check is ToolingFailure and yields no finding — never report a feature absent because the call listing it was cancelled. Known cases and affected checks are in the data collection reference |
© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 151 other files (references, assets) in skills/aws-backup-coverage-review of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
AWS Backup Coverage Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AWS Backup Coverage Review this skillaws/tools-for-devops-agent | 102 | — | ~6.8k | Automated safety check: Pass | Apache-2.0 | |
| Cloud ArchitectJeffallan/claude-skills | 12k | — | ~1.9k | Automated safety check: Pass | MIT | |
| AWS Rdssickn33/agentic-awesome-skills | 47k | 2 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Rdsitsmostafa/aws-agent-skills | 1.2k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Backup Recoverysickn33/agentic-awesome-skills | 47k | 2 repos | ~3k | Automated safety check: Warn | MIT | |
| Frappe Ops BackupImpertio-Studio/Frappe_Claude_Skill_Package | 188 | — | ~2.9k | Automated safety check: Notes | MIT |
Jeffallan/claude-skills
Designs cloud architectures, migration plans, cost optimization recommendations and disaster recovery strategies across AWS, Azure and GCP.
sickn33/agentic-awesome-skills
Provision and manage RDS databases. An agent skill from sickn33/agentic-awesome-skills.
itsmostafa/aws-agent-skills
AWS RDS relational database service for managed databases. An agent skill from itsmostafa/aws-agent-skills.
sickn33/agentic-awesome-skills
Implement backup and recovery strategies. An agent skill from sickn33/agentic-awesome-skills.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when configuring backups, restoring sites, encrypting backup files, scheduling automated backups, or planning disaster recovery.
aws/agent-toolkit-for-aws
Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private, public, and transit virtual interfaces…
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
Works with
Categories
AWS Backup coverage and data protection posture review. An agent skill from aws/tools-for-devops-agent. AWS Backup Coverage Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. AWS Backup coverage and data protection posture review.
AWS Backup Coverage Review fits situations like: A user asks about backup coverage; unbacked-up resources; AWS Backup audit; data protection gaps.
Run `npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a claude-code`. Or copy the skill folder (skills/aws-backup-coverage-review in aws/tools-for-devops-agent) into .claude/skills/aws-backup-coverage-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a codex`. Or copy the skill folder (skills/aws-backup-coverage-review in aws/tools-for-devops-agent) into .agents/skills/aws-backup-coverage-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill aws-backup-coverage-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-backup-coverage-review, .gemini/skills/aws-backup-coverage-review, .github/skills/aws-backup-coverage-review and .opencode/skills/aws-backup-coverage-review in your project.
SKILL.md names no scripts, command-line tools or credentials: AWS Backup Coverage Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AWS Backup Coverage Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.8k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AWS Backup Coverage Review: Cloud Architect (Jeffallan/claude-skills, 12k stars), AWS Rds (sickn33/agentic-awesome-skills, 47k stars), Rds (itsmostafa/aws-agent-skills, 1.2k stars) and Backup Recovery (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 102 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.