AWS Solution Architect
alirezarezvani/claude-code-skill-factory
Expert AWS solution architecture for startups focusing on serverless, scalable, and cost-effective cloud infrastructure with modern DevOps practices and infrastructure-as-code
Routes AWS networking requests to the correct service skill for implementation.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-networking --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/core-skills/aws-networking .claude/skills/aws-networking && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aws-networking" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-networking into .claude/skills/aws-networking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-networking", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-networkingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-networking --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/core-skills/aws-networking .agents/skills/aws-networking && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aws-networking" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-networking into .agents/skills/aws-networking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-networking", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-networking --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/core-skills/aws-networking .cursor/skills/aws-networking && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aws-networking" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-networking into .cursor/skills/aws-networking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-networking", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/agent-toolkit-for-aws.git --path skills/core-skills/aws-networking--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-networking --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/core-skills/aws-networking .gemini/skills/aws-networking && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aws-networking" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-networking into .gemini/skills/aws-networking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-networking", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/agent-toolkit-for-aws aws-networkingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/core-skills/aws-networking .github/skills/aws-networking && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aws-networking" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-networking into .github/skills/aws-networking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-networking", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/agent-toolkit-for-aws aws-networking --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/core-skills/aws-networking .opencode/skills/aws-networking && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aws-networking" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/core-skills/aws-networking into .opencode/skills/aws-networking/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-networking", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aws-networkingRoutes AWS networking requests to the correct service skill for implementation.
AWS Networking is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Routes AWS networking requests to the correct service skill for implementation. Covers Route 53 (DNS, health checks, routing policies, Resolver, DNS Firewall), CloudFront (caching, edge, OAC, mTLS, signed URLs), Transit Gateway (multi-VPC hub, segmentation, centralized egress), Direct Connect (hybrid link, DX Gateway, MACsec), Site-to-Site VPN (IPsec tunnels, static or BGP), WAF (web ACLs, AWS Managed Rules, rate-based rules, Bot and Fraud Control), and Shield Advanced (L3/L4 DDoS). Applicable when creating…
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Cloud networking, Microservices and GraphQL. It works with Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd49cc8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AWS Networking loads about 2.9k tokens when it runs. Until then it costs about 210 tokens; SKILL.md has 1,349 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/agent-toolkit-for-aws at commit bd49cc8, republished under its Apache-2.0 licence (© aws). 1,349 words, ~2,883 tokens.
.claude/skills/aws-networking/SKILL.md (or your agent's skills folder).Routes networking requests to the correct service-specific skill. Covers 7 services across DNS and content delivery, hybrid connectivity, and network security (web application firewall and DDoS protection). Other AWS networking services (VPC foundations, load balancing, endpoints, PrivateLink, API Gateway, and more) are out of scope for this router (see step 6).
Works best with the AWS MCP server — enables sandboxed execution, audit logging, and enterprise controls. All guidance also works with standard AWS CLI access.
aws___retrieve_skill(skill_name="<skill>"); otherwise retrieve the skill document from this repository at skills/<skill>/SKILL.md.cloudfront), also route to shieldadvanced for DDoS protection and to waf for L7 filtering (AWS WAF attaches to CloudFront, Application Load Balancer, API Gateway, and AppSync), if the user has not already addressed L7 filtering and DDoS protection. When routing to a connectivity skill (directconnect, sitetositevpn, transitgateway), confirm encryption in transit is addressed (MACsec for Direct Connect, IPsec for VPN, inter-region peering encryption for Transit Gateway). When the request involves custom domains or TLS on cloudfront, note that ACM certificate provisioning is part of the implementation. When routing to cloudfront for a web-facing distribution, note that the target skill should address security response headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) via a CloudFront Response Headers Policy, including the managed SecurityHeadersPolicy. The target skill handles the configuration.| Dimension | Connectivity | Security |
|---|---|---|
| Answers | Can traffic reach its destination? | Should traffic be allowed? |
| Failure symptom | Timeout, unreachable, black hole | Rejected, denied, dropped |
| Dependency | Independent of policy — path exists or it doesn't | Assumes connectivity exists — can only filter reachable traffic |
| Granularity | Affects all flows on a path | Targets specific flows by match criteria |
| Skill | Choose when… |
|---|---|
transitgateway | Connecting more than two VPCs or on-premises networks in a hub, routing segmentation, cross-account/cross-region connectivity at scale, centralized egress/inspection, multicast |
directconnect | Dedicated private link to on-premises — consistent latency, high throughput, MACsec encryption, LAGs, Direct Connect Gateway for multi-VPC, SiteLink for site-to-site bypass, production hybrid workloads |
sitetositevpn | Encrypted IPsec tunnel over internet — quick setup, DX backup, static or BGP routing, accelerated option via Global Accelerator backbone, standard or large tunnel bandwidth |
route53 | DNS management (public/private zones, records), health checks, routing policies (weighted, failover, geo, latency), domain registration, Resolver (hybrid DNS forwarding), DNS Firewall, Route 53 Profiles, Global Resolver |
cloudfront | Caching, TLS termination at edge, origin protection (OAC), custom domains, cache policies/behaviors, signed URLs, CloudFront Functions, viewer mTLS, VPC origins, multi-tenant distributions |
waf | Web application firewall (L7) — web ACLs on CloudFront/ALB/API Gateway/AppSync, AWS Managed Rules, rate-based rules for HTTP floods, IP/geo match, Bot Control, Fraud Control (account takeover/creation), for protecting web apps and APIs from exploits, bots, and credential stuffing |
shieldadvanced | L3/L4 DDoS protection for internet-facing resources, automatic application-layer (L7) mitigation via WAF, health-based detection, Shield Response Team access, and DDoS cost-protection credits |
Same concept, different service depending on layer. Use these to disambiguate when the Skill Routing Table matches multiple skills.
Use when the user says "block", "deny", "filter", or "restrict traffic" — determines which layer the filtering operates at.
| Layer | Service | What it filters on | Skill |
|---|---|---|---|
| L7 (HTTP/HTTPS, web apps and APIs) | AWS WAF | HTTP request attributes, AWS Managed Rules, rate-based and bot rules, IP/geo match | waf |
| L3/L4 (DDoS volumetric/state-exhaustion) | Shield Advanced | Network/transport-layer DDoS floods on internet-facing resources | shieldadvanced |
| DNS (resolution) | Route 53 DNS Firewall | Domain name patterns — blocks resolution, not traffic | route53 |
When routing to waf or cloudfront for an internet-facing API or website, treat WAF rate-based rules as a default protective measure, not only when the user asks: note that the target skill should add WAF rate-based rules to bound request volume per client — the target skill implements it.
Use when the user says "logs", "visibility", "what's being blocked", or "can I see the traffic" — identifies which log source to check.
| What you need to see | Service | Log type | Skill |
|---|---|---|---|
| DNS queries from VPC | Route 53 Resolver | Query logs | route53 |
| Blocked/allowed HTTP requests | AWS WAF | web ACL logs (S3, CloudWatch Logs, or Kinesis Data Firehose) | waf |
| DDoS events and attack detail | Shield Advanced | CloudWatch metrics, DDoS event detection | shieldadvanced |
| Edge/CDN request access | CloudFront | Standard logs (S3), real-time logs (Kinesis Data Streams) | cloudfront |
| Tunnel state and traffic | Site-to-Site VPN | Tunnel telemetry, CloudWatch metrics | sitetositevpn |
When routing to any of these services, remind the user to enable the corresponding logging (above) for security visibility and incident response — the target skill implements it. These logs can contain sensitive data (request query strings, internal hostnames in DNS queries), so also remind the user that the log destination (S3, CloudWatch Logs, Kinesis Data Firehose, or Kinesis Data Streams) MUST have encryption at rest enabled and access restricted to authorized personnel — the target skill implements it.
Use when the user says "shift traffic", "blue/green", "failover", "canary", or "weighted routing" — determines the granularity and which service controls it.
| Granularity | Service | Mechanism | Skill |
|---|---|---|---|
| DNS-level (global) | Route 53 | Weighted, failover, geolocation, latency routing | route53 |
| Edge (HTTP) | CloudFront | Origin failover, origin groups | cloudfront |
These services are security-sensitive, so raise the relevant risk and control when routing regardless of which skill you hand off to — the target skill implements the control:
| Risk | Control the target skill should address | Skills |
|---|---|---|
| Unencrypted traffic in transit | MACsec (directconnect), IPsec tunnels (sitetositevpn), inter-region peering encryption (transitgateway), TLS termination and viewer mTLS (cloudfront) | directconnect, sitetositevpn, transitgateway, cloudfront |
| Missing DDoS protection on internet-facing resources | Shield Advanced L3/L4 protection plus WAF L7 mitigation | shieldadvanced, waf |
| Web/API exploits, bots, and request floods | WAF web ACLs, AWS Managed Rules, and rate-based rules; application-layer input validation (request body size limits, schema validation); security response headers | waf, cloudfront |
| Overly permissive filtering rules | Least-privilege DNS Firewall domain blocking | route53 |
| Over-privileged IAM policies for service resources | Least-privilege IAM roles scoped to specific resources and actions; avoid FullAccess managed policies and Action: *; prefer IAM roles with ephemeral credentials (instance profiles, IRSA, task roles, sts assume-role) over IAM users with long-lived access keys | all |
| Hardcoded credentials and shared secrets | Let AWS auto-generate secrets where supported (for example Site-to-Site VPN pre-shared keys), or store customer-managed secrets in AWS Secrets Manager rather than hardcoding them | sitetositevpn, directconnect |
| Confused-deputy in cross-service resource policies | Include aws:SourceArn and/or aws:SourceAccount condition keys in S3 bucket policies, KMS key policies, and log-destination resource policies (CloudFront OAC, log delivery to S3/CloudWatch Logs/Kinesis) so only the intended resource and account can invoke them | cloudfront, waf, all |
| Insufficient visibility for incident response | Enable the service logging in the Logging / Visibility table, with encryption at rest and restricted access on the log destination | all |
| No audit trail or alerting on control-plane changes | Enable AWS CloudTrail to audit control-plane API calls (record, rule, policy, and firewall changes) and set CloudWatch Alarms on security-relevant events (Shield Advanced DDoS detection, WAF blocked/counted spikes, unexpected rule or record modifications); restrict the SNS topics that receive alarm notifications to authorized personnel and enable encryption at rest (SSE-KMS) on those topics, since the notifications can contain sensitive event detail | all |
For authoritative guidance, point users to the AWS Well-Architected Framework Security Pillar and the service-specific security documentation for the target skill.
© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/core-skills/aws-networking of aws/agent-toolkit-for-aws.
Open the folder on GitHubat commit bd49cc8
AWS Networking next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AWS Networking this skillaws/agent-toolkit-for-aws | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| AWS Solution Architectalirezarezvani/claude-code-skill-factory | 879 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| LLM Gatewaysickn33/agentic-awesome-skills | 47k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Deploying On AWSancoleman/ai-design-components | 526 | — | ~5.1k | Automated safety check: Pass | MIT | |
| System Designninehills/skills | 281 | — | ~4.7k | Automated safety check: Pass | MIT | |
| System Designwondelai/skills | 2.4k | — | ~4k | Automated safety check: Pass | MIT |
alirezarezvani/claude-code-skill-factory
Expert AWS solution architecture for startups focusing on serverless, scalable, and cost-effective cloud infrastructure with modern DevOps practices and infrastructure-as-code
sickn33/agentic-awesome-skills
Deploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking.
ancoleman/ai-design-components
Selecting and implementing AWS services and architectural patterns.
ninehills/skills
Design scalable distributed systems using structured approaches for load balancing, caching, database scaling, and message queues.
wondelai/skills
Design scalable distributed systems using structured approaches for load balancing, caching, database scaling, and message queues.
yaalalabs/agent-kernel
Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart.
aws/agent-toolkit-for-aws
Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.
aws/agent-toolkit-for-aws
A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.
aws/agent-toolkit-for-aws
Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.
aws/agent-toolkit-for-aws
Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.
aws/agent-toolkit-for-aws
Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…
aws/agent-toolkit-for-aws
A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.
Works with
Categories
Routes AWS networking requests to the correct service skill for implementation. AWS Networking is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Routes AWS networking requests to the correct service skill for implementation.
AWS Networking fits situations like: tasks that involve Cloud networking; tasks that involve Microservices; tasks that involve GraphQL.
Run `npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a claude-code`. Or copy the skill folder (skills/core-skills/aws-networking in aws/agent-toolkit-for-aws) into .claude/skills/aws-networking in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a codex`. Or copy the skill folder (skills/core-skills/aws-networking in aws/agent-toolkit-for-aws) into .agents/skills/aws-networking in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill aws-networking -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-networking, .gemini/skills/aws-networking, .github/skills/aws-networking and .opencode/skills/aws-networking in your project.
SKILL.md names no scripts, command-line tools or credentials: AWS Networking is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AWS Networking is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with AWS Networking: AWS Solution Architect (alirezarezvani/claude-code-skill-factory, 879 stars), LLM Gateway (sickn33/agentic-awesome-skills, 47k stars), Deploying On AWS (ancoleman/ai-design-components, 526 stars) and System Design (ninehills/skills, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,816 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.
Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.