Official agent skill

AWS Cleanrooms

by aws in aws/agent-toolkit-for-aws

Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, and CloudWatch logging for custom ML model training and…

OfficialApache-2.0Auto-check passedData & Analytics

Install AWS Cleanrooms

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill aws-cleanrooms -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws aws-cleanrooms --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/analytics-skills/aws-cleanrooms .claude/skills/aws-cleanrooms && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-cleanrooms
GitHub stars
2.8k
Token cost
~427 tokens
SKILL.md length
109 words
Files
3 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, and CloudWatch logging for custom ML model training and…

  • A customer reports permission failures
  • SKILL.md covers Overview, Common tasks and Additional resources
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Log publishing issues in Clean Rooms

What it does

AWS Cleanrooms is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, and CloudWatch logging for custom ML model training and inference jobs. Use when a customer reports permission failures, access errors, or log publishing issues in Clean Rooms.

Its SKILL.md is about 430 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/custom-model-logging-debugging.md` and `references/permission-debugging.md`).

It sits in Data & Analytics, covering Machine learning. It works with Amazon Web Services and Amazon S3. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • A customer reports permission failures
  • Log publishing issues in Clean Rooms

Example prompts

  • “Use the aws-cleanrooms skill to troubleshoot and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys…”
  • “/aws-cleanrooms”

What it can do on your machine

Read from SKILL.md and the folder at commit df2ab44. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Cleanrooms loads about 427 tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 83 tokens; SKILL.md has 109 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~427
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit df2ab44, republished under its Apache-2.0 licence (© aws). 109 words, ~427 tokens.

Download SKILL.mdSave it as .claude/skills/aws-cleanrooms/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
aws-cleanrooms
description
Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, and CloudWatch logging for custom ML model training and inference jobs. Use when a customer reports permission failures, access errors, or log publishing issues in Clean Rooms.
version
1

AWS Clean Rooms

Overview

Domain expertise for troubleshooting AWS Clean Rooms collaborations and custom ML modeling. Covers permission debugging, data access issues, and CloudWatch logging configuration.

Common tasks

Debugging Clean Rooms errors

Determine the failure type:

Access denied or permission error? → See permission debugging procedure. Covers IAM role policies (inline + attached managed), S3 bucket policies, KMS key policies, Lake Formation permissions, and cross-account trust.

Missing CloudWatch logs for custom model jobs? → See custom model logging debugging procedure. Covers Configured Model Algorithm Association privacy configuration, ML Configuration role permissions, and log group verification.

Additional resources

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/specialized-skills/analytics-skills/aws-cleanrooms of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/custom-model-logging-debugging.md
  • references/permission-debugging.md

Open the folder on GitHubat commit df2ab44

Compare with similar skills

AWS Cleanrooms next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Cleanrooms compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Cleanrooms this skillaws/agent-toolkit-for-aws2.8k—~427Automated safety check: PassApache-2.0
Update Quarto in RStudiorstudio/rstudio5.1k—~2.8kAutomated safety check: PassCustom licence
AWS Step Functionsawslabs/agent-plugins915—~1.9kAutomated safety check: PassApache-2.0
Tracking Model Versionsjeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Migrate Glue Devendpoint To Interactive Sessionsaws-samples/aws-glue-samples1.5k—~3.6kAutomated safety check: PassMIT-0
Agentic Kaggle WorkflowFrankS-IntelLab/agentic-kaggle-skill188—~4kAutomated safety check: PassMIT

Similar skills

  • Bumps the pinned Quarto version across the RStudio repository, mirrors the release to the rstudio-buildtools S3 bucket, verifies it and opens a PR, on macOS and Linux.

    5.1k GitHub stars~2.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Step Functions

    awslabs/agent-plugins

    Official

    Build workflows with AWS Step Functions state machines using the JSONata query language.

    915 GitHub stars~1.9k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Tracking Model Versions

    jeremylongshore/tons-of-skills-marketplace

    Build this skill enables AI assistant to track and manage ai/ml model versions using the model-versioning-tracker plugin.

    2.8k GitHub stars~1.3k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Official

    Migrate a legacy AWS Glue development endpoint to a Glue interactive session, following the official AWS migration checklist.

    1.5k GitHub stars~3.6k tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Agentic Kaggle Workflow

    FrankS-IntelLab/agentic-kaggle-skill

    Takes a Kaggle competition from rules and validation design through baselines, ensembling and notebook architecture to a scored submission.

    188 GitHub stars~4k tokensUpdated 3 mo ago
    Data & AnalyticsAuto-check passed
  • Time Series Analytics User

    open-edge-platform/edge-ai-libraries

    Build a new time-series analytics use case on top of the deployed Time Series Analytics microservice — bring it up with Docker Compose (from a repo clone, or by fetching the compose files from…

    169 GitHub stars~3.1k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated yesterday
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated yesterday
    Auto-check: notes

Questions about AWS Cleanrooms

What does AWS Cleanrooms do?

Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, and CloudWatch logging for custom ML model training and…. AWS Cleanrooms is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, and CloudWatch logging for custom ML model training and inference jobs.

When should I use AWS Cleanrooms?

AWS Cleanrooms fits situations like: A customer reports permission failures; log publishing issues in Clean Rooms.

How do I install AWS Cleanrooms in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill aws-cleanrooms -a claude-code`. Or copy the skill folder (skills/specialized-skills/analytics-skills/aws-cleanrooms in aws/agent-toolkit-for-aws) into .claude/skills/aws-cleanrooms in your project. Claude Code loads it when a task matches its description.

How do I install AWS Cleanrooms in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill aws-cleanrooms -a codex`. Or copy the skill folder (skills/specialized-skills/analytics-skills/aws-cleanrooms in aws/agent-toolkit-for-aws) into .agents/skills/aws-cleanrooms in your project. Codex loads it when a task matches its description.

Can I use AWS Cleanrooms in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill aws-cleanrooms -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-cleanrooms, .gemini/skills/aws-cleanrooms, .github/skills/aws-cleanrooms and .opencode/skills/aws-cleanrooms in your project.

What does AWS Cleanrooms need to run?

SKILL.md names no scripts, command-line tools or credentials: AWS Cleanrooms is instructions for the agent only.

Does AWS Cleanrooms access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is AWS Cleanrooms safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Cleanrooms use?

AWS Cleanrooms is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Cleanrooms use?

About 427 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.9k tokens, read only when the agent opens those files.

What are the alternatives to AWS Cleanrooms?

Skills that share tags, products or a category with AWS Cleanrooms: Update Quarto in RStudio (rstudio/rstudio, 5.1k stars), AWS Step Functions (awslabs/agent-plugins, 915 stars), Tracking Model Versions (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Migrate Glue Devendpoint To Interactive Sessions (aws-samples/aws-glue-samples, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Cleanrooms?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,830 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 9, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.