Official agent skill

AWS Routing

by aws in aws/tools-for-devops-agent

Analyze and troubleshoot AWS routing and BGP path selection - how AWS chooses a network path, why traffic takes an unexpected route, and how to steer it.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install AWS Routing

skills CLI
$ npx skills add aws/tools-for-devops-agent --skill aws-routing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/tools-for-devops-agent aws-routing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aws-routing .claude/skills/aws-routing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-routing
GitHub stars
100
Token cost
~1.6k tokens
SKILL.md length
706 words
Files
11 (incl. references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze and troubleshoot AWS routing and BGP path selection - how AWS chooses a network path, why traffic takes an unexpected route, and how to steer it.

  • Works in 7 steps: Establish the path. Identify source,… → Name the route table. Be explicit about… → Apply the evaluation order for that… → …
  • AWS Cloud WAN route evaluation and CNE path selection
  • SKILL.md covers Overview, Verification &…, When to use this skill and What this skill does NOT do, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

AWS Routing is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Analyze and troubleshoot AWS routing and BGP path selection - how AWS chooses a network path, why traffic takes an unexpected route, and how to steer it. Use for AWS Cloud WAN route evaluation and CNE path selection; Direct Connect Gateway (DXGW) path selection and local vs remote region preference; Transit Gateway route tables, ECMP, and peering; VPC route tables and longest-prefix-match; BGP traffic engineering with local-preference communities (7224:7100/7200/7300), AS-path prepending, and MED; DX + VPN…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).

It sits in DevOps & Cloud, covering Backup and disaster recovery. It works with Amazon Web Services. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.

When your agent uses it

  • AWS Cloud WAN route evaluation and CNE path selection
  • Direct Connect Gateway (DXGW) path selection and local vs remote region preference
  • Transit Gateway route tables
  • VPC route tables and longest-prefix-match

Example prompts

  • “traffic is leaving the region”
  • “not using my local Direct Connect”
  • “routing to the wrong VIF/location”
  • “/aws-routing”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Establish the path. Identify source, destination, and every routing construct in between
  2. Name the route table. Be explicit about which table makes each decision (VPC RT, TGW RT,
  3. Apply the evaluation order for that construct (see below).
  4. Identify the deciding attribute (longest prefix, local preference, AS-path, MED, source type).
  5. Flag non-determinism (e.g., ECMP or "deterministically random" tiebreakers) and recommend a
  6. Cite the AWS documentation that supports the behavior.
  7. Provide read-only validation commands the user can run to confirm.

What it can do on your machine

Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Routing loads about 1.6k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 229 tokens; SKILL.md has 706 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~229
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 706 words, ~1,636 tokens.

Download SKILL.mdSave it as .claude/skills/aws-routing/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
aws-routing
description
Analyze and troubleshoot AWS routing and BGP path selection - how AWS chooses a network path, why traffic takes an unexpected route, and how to steer it. Use for AWS Cloud WAN route evaluation and CNE path selection; Direct Connect Gateway (DXGW) path selection and local vs remote region preference; Transit Gateway route tables, ECMP, and peering; VPC route tables and longest-prefix-match; BGP traffic engineering with local-preference communities (7224:7100/7200/7300), AS-path prepending, and MED; DX + VPN redundancy and active/active vs active/passive design; asymmetric routing and failover. Activate on symptoms like "traffic is leaving the region", "not using my local Direct Connect", "routing to the wrong VIF/location", "path is asymmetric", or "how do I make AWS prefer this path". Read-only: analysis, recommendations, and describe/get/list validation commands grounded in public AWS docs.
metadata.version
1.2.3
metadata.author
midakin

Overview

This skill provides routing-first analysis for AWS networking. It reasons about the full traffic path, applies the documented route-evaluation logic for each service, and grounds recommendations in public AWS documentation. It is read-only: it produces analysis, recommendations, and read-only validation commands (describe-*, get-*, list-*) - never mutating actions.

Verification & Anti-Hallucination Directives (Mandatory)

  • Do not generate any fact, citation, or source that is not fully verifiable. If you lack a verified source, state "I cannot verify this" rather than inventing details.
  • State assumptions explicitly before answering.
  • Cross-check each claim against public AWS documentation or the references/ files. Omit claims you cannot confirm.
  • Only cite AWS documentation URLs you have actually retrieved or confirmed. Do not fabricate links.

When to use this skill

Activate when the user asks about:

  • Cloud WAN route evaluation / Core Network Edge (CNE) path selection
  • Direct Connect Gateway path selection, local-region preference, or LP communities
  • Transit Gateway route evaluation, ECMP, or peering routing
  • VPC route tables and longest-prefix-match behavior
  • BGP traffic engineering (communities, AS-path prepending, MED)
  • DX + VPN redundancy, active/active vs active/passive, or failover design
  • Why traffic is taking an unexpected path

What this skill does NOT do

This skill is read-only and advisory. It will not:

  • Design or apply infrastructure changes. It does not create, modify, or delete AWS resources, and it does not run mutating CLI/API calls (create-*, modify-*, associate-*, delete-*, put-*, update-*) or write Infrastructure-as-Code to be deployed. Any change it describes is a recommendation for you to review and implement yourself.
  • Configure BGP or push routing policy. It explains which communities, AS-path, or MED settings to use, but it does not apply them to VIFs, route tables, or Cloud WAN policy documents.
  • Execute anything against a live account beyond read-only validation. Commands it provides are limited to describe-*, get-*, and list-* for confirming state.
  • Guarantee production outcomes. It recommends non-production testing and blue/green rollout; it does not perform the cutover or validate the result for you.
  • Provide compliance, security, or contractual sign-off, or make claims it cannot ground in public AWS documentation or the references/ files.

For designing and applying changes, hand the recommendation to a change-capable workflow (with appropriate review, approvals, and testing).

How to analyze a routing problem

  1. Establish the path. Identify source, destination, and every routing construct in between (VPC route table → TGW/Cloud WAN CNE → DXGW → VIF → on-prem, or the relevant subset).
  2. Name the route table. Be explicit about which table makes each decision (VPC RT, TGW RT, CNE RT, DXGW internal selection).
  3. Apply the evaluation order for that construct (see below).
  4. Identify the deciding attribute (longest prefix, local preference, AS-path, MED, source type).
  5. Flag non-determinism (e.g., ECMP or "deterministically random" tiebreakers) and recommend a deterministic alternative.
  6. Cite the AWS documentation that supports the behavior.
  7. Provide read-only validation commands the user can run to confirm.
Show full SKILL.md (235 more words)Show less

Key evaluation rules

Cloud WAN (per CNE)

Longest prefix match → static → VPC-propagated (same region) → unequal AS-path/MED (shortest wins) → equal AS-path & MED source preference: DXGW-propagated → Cloud WAN Connect → S2S VPN → other (TGW peering, remote CNEs; identical from 2+ sources = deterministically random).

Direct Connect (private/transit VIF, outbound AWS→on-prem)

Longest prefix match → local preference → AS_PATH length → MED → ECMP (equal AS_PATH and BGP attributes). LP communities 7224:7300/7200/7100 (High/Medium/Low) set local preference and are evaluated before AS-path. DXGW prefers the local associated-region DX by default.

Direction & tooling guidance
  • AWS → on-prem (egress): control with DX LP communities.
  • On-prem → AWS (ingress): control with the customer router's local-pref/weight/MED.
  • AS-path prepending: within a region only - unreliable across regions because DXGW local-region LP overrides it. LP communities: work within-region and cross-region.

Reference material

Detailed mechanics, patterns, and caveats are in references/:

  • cloudwan-dx-routing-patterns.md - Cloud WAN route evaluation, DXGW path selection, community traffic-engineering patterns, regional inspection, multi-region egress
  • dx-routing-patterns.md - DX BGP mechanics, BFD, MED, ASN ranges, VIF considerations, CloudHub, when VIFs can talk, active/active vs active/passive
  • tgw-routing-patterns.md - TGW route evaluation, ECMP limits, DX/VPN caveats, failover, peering
  • vpn-dx-redundancy-patterns.md - VPN + DX redundancy, route preference, ECMP limits, asymmetry
  • networking-strategic-questions.md - discovery questions per service

Output expectations

  • Explain the route-evaluation logic step by step.
  • Name the specific route table involved.
  • Give the end-to-end traffic path.
  • Compare options with tradeoffs (determinism, complexity, failover) when multiple solutions exist.
  • Include read-only AWS CLI validation commands.
  • Recommend testing in a non-production environment and blue/green for migrations.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in skills/aws-routing of aws/tools-for-devops-agent.

  • SKILL.md
  • .skilleval.yaml
  • CHANGELOG.md
  • README.md
  • evals/eval_queries.json
  • evals/evals.json
  • references/cloudwan-dx-routing-patterns.md
  • references/dx-routing-patterns.md
  • references/networking-strategic-questions.md
  • references/tgw-routing-patterns.md
  • references/vpn-dx-redundancy-patterns.md

Open the folder on GitHubat commit ddda70b

Compare with similar skills

AWS Routing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Routing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Routing this skillaws/tools-for-devops-agent100—~1.6kAutomated safety check: PassApache-2.0
Cloud ArchitectJeffallan/claude-skills12k—~1.9kAutomated safety check: PassMIT
AWS Rdssickn33/agentic-awesome-skills47k2 repos~3.3kAutomated safety check: PassMIT
Rdsitsmostafa/aws-agent-skills1.2k—~2.4kAutomated safety check: PassMIT
Frappe Ops BackupImpertio-Studio/Frappe_Claude_Skill_Package187—~2.9kAutomated safety check: NotesMIT
Directconnectaws/agent-toolkit-for-aws2.8k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Cloud Architect

    Jeffallan/claude-skills

    Designs cloud architectures, migration plans, cost optimization recommendations and disaster recovery strategies across AWS, Azure and GCP.

    12k GitHub stars~1.9k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • AWS Rds

    sickn33/agentic-awesome-skills

    Provision and manage RDS databases. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.3k tokens
    DevOps & CloudAuto-check passed
  • Rds

    itsmostafa/aws-agent-skills

    AWS RDS relational database service for managed databases. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~2.4k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Frappe Ops Backup

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when configuring backups, restoring sites, encrypting backup files, scheduling automated backups, or planning disaster recovery.

    187 GitHub stars~2.9k tokensUpdated 21 days ago
    DevOps & CloudAuto-check: notes
  • Directconnect

    aws/agent-toolkit-for-aws

    Official

    Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private, public, and transit virtual interfaces…

    2.8k GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Recovery Controller Setup

    aws/agent-toolkit-for-aws

    Official

    Configures AWS Application Recovery Controller (ARC) for operational resilience: routing controls with safety rules for cross-Region failover, and zonal shift / zonal autoshift for AZ-impairment…

    2.8k GitHub stars~998 tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from aws/tools-for-devops-agent

All 31 skills in this repo
  • Sagemaker AI Ops Review

    aws/tools-for-devops-agent

    Official

    Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.

    100 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Aiml GPU Training Cluster Investigation

    aws/tools-for-devops-agent

    Official

    A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.

    100 GitHub stars~5.4k tokensUpdated today
    Auto-check passed
  • AWS Health Events

    aws/tools-for-devops-agent

    Official

    ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

    100 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Database Migration Service Expertise

    aws/tools-for-devops-agent

    Official

    AWS Database Migration Service (DMS) operational review and troubleshooting skill.

    100 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    100 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    100 GitHub stars~4.8k tokensUpdated today
    Auto-check passed

Categories

Questions about AWS Routing

What does AWS Routing do?

Analyze and troubleshoot AWS routing and BGP path selection - how AWS chooses a network path, why traffic takes an unexpected route, and how to steer it. AWS Routing is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Analyze and troubleshoot AWS routing and BGP path selection - how AWS chooses a network path, why traffic takes an unexpected route, and how to steer it.

When should I use AWS Routing?

AWS Routing fits situations like: AWS Cloud WAN route evaluation and CNE path selection; direct Connect Gateway (DXGW) path selection and local vs remote region preference; transit Gateway route tables; VPC route tables and longest-prefix-match.

How do I install AWS Routing in Claude Code?

Run `npx skills add aws/tools-for-devops-agent --skill aws-routing -a claude-code`. Or copy the skill folder (skills/aws-routing in aws/tools-for-devops-agent) into .claude/skills/aws-routing in your project. Claude Code loads it when a task matches its description.

How do I install AWS Routing in Codex?

Run `npx skills add aws/tools-for-devops-agent --skill aws-routing -a codex`. Or copy the skill folder (skills/aws-routing in aws/tools-for-devops-agent) into .agents/skills/aws-routing in your project. Codex loads it when a task matches its description.

Can I use AWS Routing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill aws-routing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-routing, .gemini/skills/aws-routing, .github/skills/aws-routing and .opencode/skills/aws-routing in your project.

What does AWS Routing need to run?

SKILL.md names no scripts, command-line tools or credentials: AWS Routing is instructions for the agent only.

Does AWS Routing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AWS Routing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Routing use?

AWS Routing is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Routing use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.

What are the alternatives to AWS Routing?

Skills that share tags, products or a category with AWS Routing: Cloud Architect (Jeffallan/claude-skills, 12k stars), AWS Rds (sickn33/agentic-awesome-skills, 47k stars), Rds (itsmostafa/aws-agent-skills, 1.2k stars) and Frappe Ops Backup (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Routing?

aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 100 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.

Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.