Official agent skill

AWS Fault Injection Service

by aws in aws/agent-toolkit-for-aws

Plans, builds, runs, and analyzes fault injection experiments with AWS Fault Injection Service (AWS FIS) to validate application resilience through chaos engineering.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install AWS Fault Injection Service

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill aws-fault-injection-service -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws aws-fault-injection-service --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/resilience-skills/aws-fault-injection-service .claude/skills/aws-fault-injection-service && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-fault-injection-service
GitHub stars
2.8k
Token cost
~2.2k tokens
SKILL.md length
923 words
Files
6 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Plans, builds, runs, and analyzes fault injection experiments with AWS Fault Injection Service (AWS FIS) to validate application resilience through chaos engineering.

  • Works in 3 steps: Suggest the right experiment — map a… → Build and run experiments — author… → Inform the user — answer conceptual…
  • Tasks that involve Chaos engineering
  • SKILL.md covers Overview, Guardrail — where this skill's…, Start here — route the request and API Reference (READ FIRST…, plus 4 more sections
  • Calls aws

What it does

AWS Fault Injection Service is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Plans, builds, runs, and analyzes fault injection experiments with AWS Fault Injection Service (AWS FIS) to validate application resilience through chaos engineering. Covers experiment templates (actions, targets, stop conditions), the FIS actions catalog and action selection, the scenario library (AZ power interruption, cross-Region connectivity, EC2/EKS/EBS stress), experiment lifecycle and monitoring, logging and reports, multi-account experiments, the experiment IAM role, and blast-radius safety. Applies when…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/fis-actions-reference.md`, `references/fis-api-reference.md` and `references/fis-concepts.md`).

It sits in DevOps & Cloud, covering Chaos engineering. It works with Amazon Web Services, AWS CloudFormation and Model Context Protocol. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Chaos engineering

Example prompts

  • “/aws-fault-injection-service”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Suggest the right experiment — map a user's failure scenario or resilience question to
  2. Build and run experiments — author experiment templates (actions, targets, stop
  3. Inform the user — answer conceptual questions about FIS terminology, safety, pricing,

What it can do on your machine

Read from SKILL.md and the folder at commit 2cb0fa1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Fault Injection Service loads about 2.2k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 258 tokens; SKILL.md has 923 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~258
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit 2cb0fa1, republished under its Apache-2.0 licence (© aws). 923 words, ~2,170 tokens.

Download SKILL.mdSave it as .claude/skills/aws-fault-injection-service/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
aws-fault-injection-service
description
Plans, builds, runs, and analyzes fault injection experiments with AWS Fault Injection Service (AWS FIS) to validate application resilience through chaos engineering. Covers experiment templates (actions, targets, stop conditions), the FIS actions catalog and action selection, the scenario library (AZ power interruption, cross-Region connectivity, EC2/EKS/EBS stress), experiment lifecycle and monitoring, logging and reports, multi-account experiments, the experiment IAM role, and blast-radius safety. Applies when a user mentions AWS FIS or fault injection, asks what experiment to run for a failure mode (AZ, Region, API errors/throttling, instance/pod/DB/cache failure, latency, packet loss), wants to author an experiment template or CLI/CloudFormation, or needs to safely run chaos experiments in pre-production or production. For the broader resilience program across Resilience Hub and ARC, see aws-resilience-lifecycle; for ARC routing controls and zonal shift, see recovery-controller-setup.
version
1

AWS Fault Injection Service (FIS) Experiments

Overview

Domain expertise for AWS Fault Injection Service (AWS FIS) — a managed chaos-engineering service that runs controlled fault injection experiments on real AWS resources so you can observe how an application responds to disruption and improve its resilience.

This skill lets an agent do three things:

  1. Suggest the right experiment — map a user's failure scenario or resilience question to the correct FIS action(s), scenario, or experiment design, and explain the trade-offs.
  2. Build and run experiments — author experiment templates (actions, targets, stop conditions, logging, reports), wire up the experiment IAM role, and drive the run/monitor/stop lifecycle via CLI, SDK, or CloudFormation.
  3. Inform the user — answer conceptual questions about FIS terminology, safety, pricing, supported services, and how FIS fits into a resilience program.

AWS FIS carries out real actions on real AWS resources. Before running any experiment in production, plan it, run it first in pre-production, and always bound the blast radius with a stop condition. Treat fault injection as a privileged, potentially disruptive operation.

The AWS MCP server is recommended for executing this skill's AWS API calls — it provides sandboxed execution and audit logging — but it is not required; all operations also work with the AWS CLI (aws fis ...) directly.

Guardrail — where this skill's own files live (MCP vs local install)

Before reading a reference file, determine how this skill was loaded:

  • Loaded via the AWS MCP retrieve_skill tool: the skill's reference files are not on the local filesystem. Fetch each one through retrieve_skill with the file parameter (e.g. file="references/fis-concepts.md") — do NOT file_read these paths locally or search the filesystem for them.
  • Installed locally (e.g. .kiro/skills/aws-fault-injection-service/ or ~/.claude/skills/aws-fault-injection-service/): read reference files from the local skill directory using the relative paths shown here.

This applies only to the skill's own reference files; always read and write user or session data in the working directory, never through retrieve_skill.

Start here — route the request

  • "What is FIS / when should I use it / what does X term mean / does it support Y?" → read references/fis-concepts.md.
  • "What experiment/action should I run to test a failure mode?" → read references/fis-actions-reference.md (action selection map + full catalog) and suggest an action or scenario.
  • "Build / create / run an experiment" (template, targets, stop conditions, logging, reports, scenarios, multi-account, monitoring) → follow references/fis-workflow.md exactly.
  • Any AWS CLI or API command for FIS → consult references/fis-api-reference.md FIRST — it is the canonical operation/parameter reference and includes a hallucination-rejection table.
  • IAM role, permissions, trust policy, confused-deputy, blast-radius safety → read references/fis-security.md.

API Reference (READ FIRST before producing any AWS CLI command)

The exact aws fis operation names and template parameters are documented in references/fis-api-reference.md, including a table mapping common wrong API/action names to correct ones. Always consult it before generating commands. Action IDs and resource types evolve — verify with aws fis list-actions and aws fis get-action --id <action-id> rather than trusting memory.

Suggesting experiments (behavioral contract)

When the user describes a failure they want to test rather than a command they want run:

  1. Identify the failure mode (AZ impairment, Region isolation, API errors/throttling, compute/DB/cache loss, latency, packet loss, resource exhaustion).
  2. Map it to a scenario (preferred when one fits — pre-built and AWS-owned) or a specific action using the selection map in references/fis-actions-reference.md.
  3. State the target (resource type + how to scope it) and a stop condition (CloudWatch alarm on your steady-state metric) so the blast radius is bounded.
  4. Recommend running in pre-production first, then production under change management.
  5. Offer to generate the experiment template — then follow references/fis-workflow.md.

Do not invent action IDs, resource types, or parameters. If unsure, say so and verify with aws fis list-actions / aws fis get-action or the FIS documentation.

Show full SKILL.md (317 more words)Show less

Troubleshooting

"Experiment failed immediately / no targets found"

FIS resolves all targets at experiment start; if a target resolves to zero resources, the experiment fails (unless emptyTargetResolutionMode is skip). Check tags, filters, region, and account. Use a target preview before running (see workflow reference).

"Action failed with a permissions error"

The FIS experiment IAM role is missing permissions for the underlying service API (or SSM, or the confused-deputy trust conditions block the assume). See references/fis-security.md.

"Experiment stopped unexpectedly"

A stop condition (CloudWatch alarm) likely fired — this is the guardrail working. Check the experiment's state.reason and the alarm history. A stopped experiment cannot be resumed; start a new one from the template.

"Nitro / instance-type errors on EBS or network faults"

Some actions require Nitro-based instances or the SSM Agent. Verify prerequisites per action in references/fis-actions-reference.md.

Observability companion

For the CloudWatch alarms, dashboards, and metrics that back FIS stop conditions and experiment reports, recommend the AWS Observability skill for alarm/dashboard setup — keep this skill's guidance to how those signals feed experiment safety and post-experiment analysis.

Security Considerations

FIS runs real, potentially destructive actions. Key points (full guidance in references/fis-security.md):

  • Least privilege: scope the experiment role to only the actions and target ARNs each experiment needs — never *. Scope the human/CI principals allowed to call fis:StartExperiment.
  • Confused-deputy protection: the experiment role's trust policy MUST condition on aws:SourceAccount and aws:SourceArn (scoped to the experiment ARN pattern).
  • Bounded blast radius: always attach a CloudWatch-alarm stop condition; start with narrow targets (COUNT(1) / low PERCENT) and pre-production before production.
  • No sensitive data in string fields: experiment/template descriptions, tags, and logs surface in CloudTrail, CloudWatch Logs, S3 reports, and (multi-account) target-account Health dashboards — never embed PII, secrets, or sensitive architecture detail.
  • Encrypt logs/reports: experiment logs and PDF reports reveal resilience posture — use SSE-KMS on the S3 buckets, enforce TLS, and consider S3 Object Lock on report buckets.
  • Further reading: FIS Security and the AWS Well-Architected Reliability Pillar.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/specialized-skills/resilience-skills/aws-fault-injection-service of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/fis-actions-reference.md
  • references/fis-api-reference.md
  • references/fis-concepts.md
  • references/fis-security.md
  • references/fis-workflow.md

Open the folder on GitHubat commit 2cb0fa1

Compare with similar skills

AWS Fault Injection Service next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Fault Injection Service compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Fault Injection Service this skillaws/agent-toolkit-for-aws2.8k—~2.2kAutomated safety check: PassApache-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
AWS Sst Developmentzxkane/aws-skills367—~2.7kAutomated safety check: WarnMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Spotinfoalexei-led/spotinfo164—~1.8kAutomated safety check: PassApache-2.0
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0

Similar skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • AWS Sst Development

    zxkane/aws-skills

    SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

    367 GitHub stars~2.7k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: warnings
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Spotinfo

    alexei-led/spotinfo

    Query Spot/preemptible VM prices, savings and interruption risk across AWS, GCP and Azure with the spotinfo CLI.

    164 GitHub stars~1.8k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Install Boltmcp

    boltmcp/boltmcp

    A skill your agent uses when asked to help install or uninstall BoltMCP

    371 GitHub stars~2.3k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated yesterday
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about AWS Fault Injection Service

What does AWS Fault Injection Service do?

Plans, builds, runs, and analyzes fault injection experiments with AWS Fault Injection Service (AWS FIS) to validate application resilience through chaos engineering. AWS Fault Injection Service is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Plans, builds, runs, and analyzes fault injection experiments with AWS Fault Injection Service (AWS FIS) to validate application resilience through chaos engineering.

When should I use AWS Fault Injection Service?

AWS Fault Injection Service fits situations like: tasks that involve Chaos engineering.

How do I install AWS Fault Injection Service in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill aws-fault-injection-service -a claude-code`. Or copy the skill folder (skills/specialized-skills/resilience-skills/aws-fault-injection-service in aws/agent-toolkit-for-aws) into .claude/skills/aws-fault-injection-service in your project. Claude Code loads it when a task matches its description.

How do I install AWS Fault Injection Service in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill aws-fault-injection-service -a codex`. Or copy the skill folder (skills/specialized-skills/resilience-skills/aws-fault-injection-service in aws/agent-toolkit-for-aws) into .agents/skills/aws-fault-injection-service in your project. Codex loads it when a task matches its description.

Can I use AWS Fault Injection Service in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill aws-fault-injection-service -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-fault-injection-service, .gemini/skills/aws-fault-injection-service, .github/skills/aws-fault-injection-service and .opencode/skills/aws-fault-injection-service in your project.

What does AWS Fault Injection Service need to run?

Going by SKILL.md and its folder, AWS Fault Injection Service needs the command-line tools its instructions call (aws).

Does AWS Fault Injection Service access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is AWS Fault Injection Service safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Fault Injection Service use?

AWS Fault Injection Service is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Fault Injection Service use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to AWS Fault Injection Service?

Skills that share tags, products or a category with AWS Fault Injection Service: AWS Cdk Development (zxkane/aws-skills, 367 stars), AWS Sst Development (zxkane/aws-skills, 367 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars) and Spotinfo (alexei-led/spotinfo, 164 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Fault Injection Service?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,835 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 9, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.