Logfire Infrastructure
pydantic/skills
Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.
A skill your agent uses when someone wants an Amazon EKS cluster graded against best practices.
$ npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent aws-eks-operations-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aws-eks-operations-review .claude/skills/aws-eks-operations-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aws-eks-operations-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-eks-operations-review into .claude/skills/aws-eks-operations-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-eks-operations-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-eks-operations-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent aws-eks-operations-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/aws-eks-operations-review .agents/skills/aws-eks-operations-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aws-eks-operations-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-eks-operations-review into .agents/skills/aws-eks-operations-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-eks-operations-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent aws-eks-operations-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/aws-eks-operations-review .cursor/skills/aws-eks-operations-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aws-eks-operations-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-eks-operations-review into .cursor/skills/aws-eks-operations-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-eks-operations-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/aws-eks-operations-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent aws-eks-operations-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/aws-eks-operations-review .gemini/skills/aws-eks-operations-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aws-eks-operations-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-eks-operations-review into .gemini/skills/aws-eks-operations-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-eks-operations-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent aws-eks-operations-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/aws-eks-operations-review .github/skills/aws-eks-operations-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aws-eks-operations-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-eks-operations-review into .github/skills/aws-eks-operations-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-eks-operations-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent aws-eks-operations-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/aws-eks-operations-review .opencode/skills/aws-eks-operations-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aws-eks-operations-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-eks-operations-review into .opencode/skills/aws-eks-operations-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-eks-operations-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aws-eks-operations-reviewA skill your agent uses when someone wants an Amazon EKS cluster graded against best practices.
AWS Eks Operations Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Use this skill when someone wants an Amazon EKS cluster graded against best practices. Use it when they ask to review, assess, audit, or grade a cluster; ask for an operations review, security review, operational-readiness or pre-upgrade check, inventory, or CWR; ask whether a cluster is production-ready or safe to upgrade; ask what risks, gaps, or misconfigurations it carries; or describe Kubernetes workloads on AWS without naming EKS. It grades nine pillars — Operations, Resilience, Security, Scalability…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 90 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).
It sits in DevOps & Cloud, covering Container orchestration, Security review and Budgeting and forecasting. It works with Amazon Web Services, Kubernetes and Amazon S3. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AWS Eks Operations Review loads about 3k tokens when it runs, and up to ~155k if it reads all its reference files. Until then it costs about 202 tokens; SKILL.md has 1,465 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,465 words, ~3,048 tokens.
.claude/skills/aws-eks-operations-review/SKILL.md (or your agent's skills folder). This skill also uses 86 other files; get the full folder from GitHub.This skill performs comprehensive graded operational reviews with 288 checks across 9 pillars. For quick health checks during active incidents, use incident investigation skills instead — this review is heavyweight and best suited for proactive assessments.
A full review is heavyweight and may require many read-only tool calls; duration varies with cluster size, API responsiveness, permissions, and telemetry availability. A targeted review grades only the named unit plus required AX evidence. The 49 discovery areas collect evidence; the 288 core rows are grading items across nine pillars plus AWS API/Insights. Per-unit counts and exact ID membership live in references/runtime/check-manifest.md; read them there each run.
use_kubectl: get, describe, logs, version, config current-context, cluster-info, top, and get --raw, one command per tool call. Results stay transient in conversation; never write them to a file, object store, or Amazon S3. Customer-account AWS reads use audited read-only DevOps Agent access, never local AWS CLI/boto3 credentials. Remediations are proposals for human approval, never mutations.Keep in current context only: confirmed identity/scope/window; 49 area statuses and bounded projections; source attempts; gate decisions; selected/completed units; exact verdicts; FAIL evidence, descriptive severity, canonical resource ID, fingerprint, and remediation route; reference-load audit; QA result; next unit. Update after every area/unit and discard raw output. Stop and report evidence/completed work/retry requirement if the Kubernetes tool is unavailable, identity differs from the confirmed target, initial access fails, more than 30% of a discovery phase fails, or mutation/safety is attempted. Later isolated denial/timeout/optional-CRD gaps are N/A unless that threshold is crossed. For production, confirm timing before the broad read sweep. Never fetch Kubernetes Secret values. EKS control-plane hosts/etcd are AWS-managed: use only customer-visible APIs, logs, metrics, and Kubernetes behavior.
Work these steps in order; never start a step before the previous one is recorded in the ledger.
Confirm cluster, region, account, context, environment, namespace scope, event window, and production sweep approval. If targets are ambiguous, stop for selection.
Collect available topology, dependencies, recent investigations, alarms, and environment facts with provenance. They prioritize work but never replace discovery or grading evidence.
Run cheap read probes (version -o json, current context, cluster info, nodes), cross-check S0, and apply stop rules. Load references/docs/minimum-rbac.md only for an access-policy question or denial.
Load references/runtime/discovery-manifest.md, then use use_kubectl to execute references/kubectl-discovery-commands.md (1–27) and references/kubectl-discovery-commands-deep-dive.md (28–49) in order. Every area gets one complete|partial|n/a status. Reuse only named transient fetches with matching identity/scope/provenance and run each dependent extraction; CRD-specific probes stay separate. Apply fleet tiers and the independent 500+ pod rule, which prohibits whole-cluster pod JSON. Retain bounded projections only in conversation; never store results in Amazon S3 or a file.
Load references/runtime/inventory-schema.md. When telemetry applies, load references/runtime/metrics-thresholds.md and attempt required 7-day node/pod utilization, restarts, EC2 health, EKS request, log-pattern, alarm, and CloudTrail signals. Missing telemetry yields N/A plus the visibility finding. Keep a bounded in-context snapshot only.
Load references/runtime/router.md and references/runtime/cluster-gates.md; record every decision, then drop both. Named requests grade named units; full/CWR grades all nine pillars plus AX. Upgrade/migration or Extended Support fires the Upgrade unit and k8s-deprecated-apis.md; Windows fires when windows_nodes>0; Hybrid when hybrid_nodes>0; AI/ML when GPU or Neuron nodes exist; the manifest owns their exact IDs and counts. Otherwise record an explicit false-gate line and do not load the conditional. Auto Mode, IPv6, Fargate, CNI, mixed-OS, and EKS Anywhere gates change applicability, never membership.
Load references/runtime/grading-guards.md once. For each routed unit: load only its canonical definition; grade every ID with evidence and applicable guards; commit exact rows/totals/finding inputs to the ledger before the next unit; then identify FAIL IDs. Only after FAIL verdicts exist, consult references/remediations/index.md, load the mapped shard/playbook, and complete each finding. Load a decision tree only after its Pending/OOM/latency/429 signal and before asserting cause. Fingerprint = SHA256(account_id|region|cluster_name|check_id|canonical_resource_id). Drop unit/remediation/raw data before continuing. If AWS reads fail, AX rows are N/A; load references/docs/minimum-rbac.md for the required IAM actions; if telemetry fails, dependent rows are N/A; if control-plane logging is disabled, record the visibility FAIL and still attempt public metrics.
Load control-plane-health/metric-sources.md, detect sources, record/drop. If logging is enabled, sequentially load/run/record/drop queries-cp01-cp09.md, queries-cp10-cp13.md, and queries-cp14-cp18.md; load queries-cp19-cp25-diagnostics.md only for a matching signal. Always attempt public control-plane metrics, then load thresholds.md and pillars/control-plane.md to grade all 20 rows. Use procedures.md or decision-trees/api-latency-429.md only for unhealthy/ambiguous results; load only failed signal-family remediation and FAIL-only alert copy. Empty query results remain unknown until source, stream, delay, filters, and window are verified.
Load references/runtime/qa-checklist.md, references/runtime/check-manifest.md, and, for full/CWR, references/runtime/common-checks-coverage.md. Reconcile 49 area statuses; load audit; exact selected IDs/counts; namespaces; conditionals/gates; source attempts/fallbacks; every FAIL block; alarms; the eight mandatory report sections and their order; and direct-response/no-file compliance. Complete QA in context. On failure, repair the named state/ID/reference and rerun; do not finalize.
Load references/runtime/report-contract.md only now; it is the sole delivery authority and outranks any other report-format skill or remembered layout. Emit the entire review as one complete Markdown message with these headings, in this exact order, none omitted, renamed, reordered, or deferred:
# EKS Operations Review — {cluster} header block; 2. ## 1. Executive summary; 3. ## 2. Cluster snapshot; 4. ## 3. Prioritized action plan — every FAIL, Critical→Low; 5. ## 4. Detailed findings — one block per FAIL; 6. ## 5. Scorecards — every selected ID with verdict and bounded evidence; 7. ## 6. Recommended alarms — required for IDR/CWR, otherwise one skipped line; 8. ## 7. What was not assessed — every N/A ID with its exact reason; 9. ## 8. Appendix — scope, discovery coverage, source attempts, gates, reference-load audit, QA PASS.Sections 1–7 are the review; the appendix is bookkeeping, never a substitute. A section with nothing to report still appears with an explicit None line. Never split the review across messages or deliverables; when the runtime assembles one cumulative artifact by ordered appends, its final state must contain every section. Customer-facing text excludes internal tools, employee aliases, and internal incident severity numbers.
pending-pods.md, oomkilled.md, or api-latency-429.md only after its matching signal.queries-cp19-cp25-diagnostics.md only for a matching Control Plane signal.Under context pressure, finish the current area/unit, update the ledger, compress PASS/N/A detail, and discard raw output. Compression shortens evidence text only; S8 sections 1–7 are never dropped, merged, or postponed. If safe continuation is impossible, emit a conversational checkpoint with the last completed state/unit, exact completed/unassessed coverage, QA state, and next unit. Resume from the incomplete state only when the conversation still retains the ledger; otherwise recollect required evidence. If more than 30% of discovery failed, investigate access, permissions, throttling, or scope before retrying.
Do not finalize partial discovery, substitute AX1 for Control Plane, interpret missing sources as health, load false-gate conditionals, load remediation early, render before QA, or emit an appendix-only report body. Every FAIL must quote evidence/source/window, explain impact and descriptive severity, include human-approved mapped steps and an authoritative AWS/Kubernetes link, and preserve fingerprint/resource ID. Unmapped facts are Observations.
© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 86 other files (references) in skills/aws-eks-operations-review of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
AWS Eks Operations Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AWS Eks Operations Review this skillaws/tools-for-devops-agent | 102 | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Logfire Infrastructurepydantic/skills | 140 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Cloud Devopsdavila7/claude-code-templates | 32k | 4 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Eks Cost Intelligenceaws-samples/appmod-blueprints | 115 | — | ~3.8k | Automated safety check: Warn | MIT-0 | |
| Kubeshark KFL2 Filter Referencekubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Provider Bug Reviewmondoohq/mql | 412 | — | ~2.9k | Automated safety check: Pass | Custom licence |
pydantic/skills
Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
aws-samples/appmod-blueprints
Run a live EKS cluster cost efficiency assessment — analyze spending across 6 dimensions (compute efficiency, Spot/Graviton adoption, networking, storage, observability, idle resources), calculate a…
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
Works with
Categories
A skill your agent uses when someone wants an Amazon EKS cluster graded against best practices. AWS Eks Operations Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Use this skill when someone wants an Amazon EKS cluster graded against best practices.
AWS Eks Operations Review fits situations like: someone wants an Amazon EKS cluster graded against best practices; they ask to review; grade a cluster; ask for an operations review.
Run `npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a claude-code`. Or copy the skill folder (skills/aws-eks-operations-review in aws/tools-for-devops-agent) into .claude/skills/aws-eks-operations-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a codex`. Or copy the skill folder (skills/aws-eks-operations-review in aws/tools-for-devops-agent) into .agents/skills/aws-eks-operations-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill aws-eks-operations-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-eks-operations-review, .gemini/skills/aws-eks-operations-review, .github/skills/aws-eks-operations-review and .opencode/skills/aws-eks-operations-review in your project.
SKILL.md names no scripts, command-line tools or credentials: AWS Eks Operations Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AWS Eks Operations Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 152k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AWS Eks Operations Review: Logfire Infrastructure (pydantic/skills, 140 stars), Cloud Devops (davila7/claude-code-templates, 32k stars), Eks Cost Intelligence (aws-samples/appmod-blueprints, 115 stars) and Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 102 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.