Official agent skill

AWS Vpc DNS Investigation

by aws in aws/tools-for-devops-agent

A skill your agent uses when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install AWS Vpc DNS Investigation

skills CLI
$ npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/tools-for-devops-agent aws-vpc-dns-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aws-vpc-dns-investigation .claude/skills/aws-vpc-dns-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-vpc-dns-investigation
GitHub stars
103
Token cost
~2k tokens
SKILL.md length
907 words
Files
9
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change.

  • Works in 2 steps: Classify the request as Mode A or Mode B → Load safety rules
  • A name is not resolving as expected inside a VPC
  • SKILL.md covers Step 1: Classify the request…, Step 2: Load safety rules, Mode A route: live diagnosis and Mode B route: pre-change…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

AWS Vpc DNS Investigation is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Use this skill when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change. Activate on symptoms such as NXDOMAIN or SERVFAIL from an EC2 instance, a hostname resolving to a public address when a private endpoint was expected, an AWS service endpoint that stopped resolving after a VPC endpoint or Route 53 change, an application reaching the wrong IP, resolution that works from one instance but not another, IPv6 or dualstack resolution differences, a suspected on-premises…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).

It sits in DevOps & Cloud, covering GraphQL and Operations and SOPs. It works with Amazon Web Services and Model Context Protocol. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.

When your agent uses it

  • A name is not resolving as expected inside a VPC
  • Before applying a DNS control-plane change

Example prompts

  • “/aws-vpc-dns-investigation”

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Classify the request as Mode A or Mode B
  2. Load safety rules

What it can do on your machine

Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Vpc DNS Investigation loads about 2k tokens when it runs. Until then it costs about 231 tokens; SKILL.md has 907 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~231
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 907 words, ~2,029 tokens.

Download SKILL.mdSave it as .claude/skills/aws-vpc-dns-investigation/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
aws-vpc-dns-investigation
description
Use this skill when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change. Activate on symptoms such as NXDOMAIN or SERVFAIL from an EC2 instance, a hostname resolving to a public address when a private endpoint was expected, an AWS service endpoint that stopped resolving after a VPC endpoint or Route 53 change, an application reaching the wrong IP, resolution that works from one instance but not another, IPv6 or dualstack resolution differences, a suspected on-premises forwarding or hybrid DNS problem, or a request to check whether enabling private DNS, adding a Resolver rule, associating a private hosted zone, attaching DNS Firewall, or associating a Route 53 Profile would break anything. It drives the aws-vpc-dns-diagnostics MCP server to observe live resolution from inside the subnet and to simulate a proposed change before it is applied.
metadata.author
ddericco
metadata.version
1.0.0
metadata.aws-devops-agent-skills.agent-t
Chat tasks, Incident RCA
metadata.aws-devops-agent-skills.aws-ser
Amazon VPC, Amazon Route 53, Amazon EC2, AWS Systems Manager
metadata.aws-devops-agent-skills.technic
Networking

Investigate VPC DNS Resolution

Use the tools on the connected aws-vpc-dns-diagnostics MCP server.

Step 1: Classify the request as Mode A or Mode B

Before calling any tool, determine which mode applies:

  • Mode A (live diagnosis): The operator reports a resolution symptom from a running instance. They provide an instance ID (or you can identify one). The goal is to observe what actually resolves and compare resolvers.
  • Mode B (pre-change validation): The operator asks whether a proposed DNS change is safe. They provide account, region, VPC, and a change descriptor. No instance is required.

If the request is ambiguous, ask the operator to clarify. Do not default to Mode A when the input lacks an instance ID, and do not default to Mode B when the operator describes a live symptom.

Step 2: Load safety rules

Regardless of mode, call get_sop with slug A-critical-safety-rules and follow every rule it contains. These are non-negotiable constraints on how you interpret results, handle opaque constructs, and report findings.


Mode A route: live diagnosis

Required inputs

account_id, region, instance_id, and the failing DNS name.

Tool sequence (in order)
  1. dns_probe_context — establishes VPC-attribute preconditions: enableDnsSupport, enableDnsHostnames, address family, DHCP option set. A resolution result means nothing until you know whether the VPC resolver is answering.
  2. dns_probe_compare — runs the allowlisted probe set inside the instance via SSM. Returns each resolver's answer and the resolver's own identity from hostname.bind. The VPC DHCP resolver is auto-added for comparison.
  3. get_sop — load the pattern runbook matching the observed signature (see trap-to-SOP mapping below).
Interpretation rules
  • If enableDnsSupport is false: load A-resolver-disabled-precondition. The VPC resolver is intentionally dark and every probe failure follows from that.
  • Compare the instance's /etc/resolv.conf (from the probe output) against the DHCP option set. A mismatch means the instance is not using the VPC-intended resolver.
  • Judge answers by name category (load A-name-category-classification), not by whether resolvers agree. Two resolvers returning the same wrong answer is still a failure.
Mode A trap-to-SOP mapping
Observed signatureSOP slug
Custom resolver answers differently from VPC .2A-custom-resolver-divergence
FORWARD rule and PHZ both match the nameA-forward-vs-phz-precedence-collision
A record works, AAAA fails (or vice versa)A-address-family-divergence
enableDnsSupport is falseA-resolver-disabled-precondition
General live comparison procedureA-mode-a-live-resolver-comparison
Reporting format for Mode A

Label every finding as Observed (ground truth from the probe). State which resolver answered and what it returned. When Mode A and Mode B produce different conclusions for the same name, Mode A wins because it is ground truth from inside the subnet.


Mode B route: pre-change validation

Required inputs

account_id, region, vpc_id, and a change descriptor (structured dict with type and type-specific fields). No instance required.

Tool sequence (in order)
  1. dns_simulate_effective_config — returns the VPC's effective DNS config: the union of directly attached resources and anything inherited through an associated Route 53 Profile, each construct tagged by source.
  2. dns_simulate_change — applies the proposed change symbolically and returns a per-name impact report (before/after, delta, traps, severity, volume).
  3. get_sop — load runbooks for any traps reported in the impact table (see trap-to-SOP mapping below).
Show full SKILL.md (403 more words)Show less
Interpretation rules
  • Never recommend applying a change without simulating it first. A broad FORWARD rule, enabling private DNS on an interface endpoint, or a Profile association can silently redirect names that currently resolve correctly.
  • The candidate set is limited to API-derived names (PHZ records, rule domains, VPCE apexes, Firewall domain lists) or operator-supplied names. It is not exhaustive. State the coverage boundary.
  • If the operator supplies volumes (from Resolver Query Logs), names are ranked by traffic. This is enrichment; absence does not invalidate the simulation.
Mode B trap-to-SOP mapping
Trap label in impact reportSOP slug
VPCE-shadow-NXDOMAINB-vpce-shadow-nxdomain
broad-FORWARD-sweepB-broad-forward-sweep
flag-AND-mismatchB-flag-and-mismatch
DNS-Firewall-blockB-dns-firewall-block
profile-union-shiftB-profile-propagation-timing
General pre-change procedureB-mode-b-pre-change-validation
Reporting format for Mode B

Label every finding as Predicted (symbolic, not ground truth). State the candidate-set size, its source (API-derived or operator-supplied), and that names outside this set were not evaluated. Include the propagation timing caveat for Profile changes.


Cross-account opacity

Call get_sop with slug C-cross-account-opaque-constructs when the effective config or impact report contains opaque markers. Cross-account constructs shared via RAM or a Route 53 Profile may be enumerable but their contents are not readable from the consumer account. Report them as "present but unknown content" rather than treating them as absent or inferring past them.

Limitations

Call get_sop with slug C-limitations-and-boundaries and state the relevant boundaries to the operator. Key constraints:

  • All tools are read-only. Do not modify, delete, or create DNS resources.
  • Mode A requires SSM reachability (ssm, ssmmessages, ec2messages VPC endpoints and an instance role with AmazonSSMManagedInstanceCore).
  • Mode B candidate sets are not exhaustive. The "no impacts" conclusion applies only within the tested set.
  • Opaque constructs cannot be resolved from this account.
  • Resolver Query Log ingestion is not implemented; volumes must be supplied by the operator.

Final response requirements

Every response produced by this skill must include:

  1. Each finding labelled Observed (Mode A) or Predicted (Mode B).
  2. When both modes were used, state "Mode A wins" for any conflict.
  3. The candidate-set coverage: how many names, what source, what was not tested.
  4. Any opaque constructs and their impact on the conclusion.
  5. Recommended next steps or the specific change to apply (never apply it).

Prerequisites

Requires the aws-vpc-dns-diagnostics MCP server registered in the Agent Space with its tools allowlisted. The server is at mcp/aws-vpc-dns-diagnostics-mcp/. If the server is not registered or SSM is unreachable, report that as the blocker rather than guessing at the resolution path.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files in skills/aws-vpc-dns-investigation of aws/tools-for-devops-agent.

  • SKILL.md
  • .skilleval.yaml
  • CHANGELOG.md
  • README.md
  • evals/benchmark.json
  • evals/eval_queries.json
  • evals/evals.json
  • evals/report.json
  • evals/trigger_report.json

Open the folder on GitHubat commit ddda70b

Compare with similar skills

AWS Vpc DNS Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Vpc DNS Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Vpc DNS Investigation this skillaws/tools-for-devops-agent103—~2kAutomated safety check: PassApache-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Spotinfoalexei-led/spotinfo164—~1.8kAutomated safety check: PassApache-2.0
Install Boltmcpboltmcp/boltmcp371—~2.3kAutomated safety check: PassNone
Unraiddinglebear-ai/unraid135—~5.4kAutomated safety check: NotesMIT

Similar skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Spotinfo

    alexei-led/spotinfo

    Query Spot/preemptible VM prices, savings and interruption risk across AWS, GCP and Azure with the spotinfo CLI.

    164 GitHub stars~1.8k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Install Boltmcp

    boltmcp/boltmcp

    A skill your agent uses when asked to help install or uninstall BoltMCP

    371 GitHub stars~2.3k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Unraid

    dinglebear-ai/unraid

    This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…

    135 GitHub stars~5.4k tokensUpdated 7 days ago
    DevOps & CloudAuto-check: notes
  • Infra Sync

    agentic-community/mcp-gateway-registry

    Keep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry.

    968 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from aws/tools-for-devops-agent

All 31 skills in this repo
  • Aiml GPU Training Cluster Investigation

    aws/tools-for-devops-agent

    Official

    A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.

    103 GitHub stars~5.4k tokensUpdated yesterday
    Auto-check passed
  • AWS Health Events

    aws/tools-for-devops-agent

    Official

    ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

    103 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check passed
  • Database Migration Service Expertise

    aws/tools-for-devops-agent

    Official

    AWS Database Migration Service (DMS) operational review and troubleshooting skill.

    103 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    103 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    103 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Sagemaker AI Ops Review

    aws/tools-for-devops-agent

    Official

    Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.

    103 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about AWS Vpc DNS Investigation

What does AWS Vpc DNS Investigation do?

A skill your agent uses when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change. AWS Vpc DNS Investigation is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Use this skill when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change.

When should I use AWS Vpc DNS Investigation?

AWS Vpc DNS Investigation fits situations like: A name is not resolving as expected inside a VPC; before applying a DNS control-plane change.

How do I install AWS Vpc DNS Investigation in Claude Code?

Run `npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a claude-code`. Or copy the skill folder (skills/aws-vpc-dns-investigation in aws/tools-for-devops-agent) into .claude/skills/aws-vpc-dns-investigation in your project. Claude Code loads it when a task matches its description.

How do I install AWS Vpc DNS Investigation in Codex?

Run `npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a codex`. Or copy the skill folder (skills/aws-vpc-dns-investigation in aws/tools-for-devops-agent) into .agents/skills/aws-vpc-dns-investigation in your project. Codex loads it when a task matches its description.

Can I use AWS Vpc DNS Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-vpc-dns-investigation, .gemini/skills/aws-vpc-dns-investigation, .github/skills/aws-vpc-dns-investigation and .opencode/skills/aws-vpc-dns-investigation in your project.

What does AWS Vpc DNS Investigation need to run?

SKILL.md names no scripts, command-line tools or credentials: AWS Vpc DNS Investigation is instructions for the agent only.

Does AWS Vpc DNS Investigation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AWS Vpc DNS Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Vpc DNS Investigation use?

AWS Vpc DNS Investigation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Vpc DNS Investigation use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AWS Vpc DNS Investigation?

Skills that share tags, products or a category with AWS Vpc DNS Investigation: AWS Cdk Development (zxkane/aws-skills, 367 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Spotinfo (alexei-led/spotinfo, 164 stars) and Install Boltmcp (boltmcp/boltmcp, 371 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Vpc DNS Investigation?

aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 103 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 9, 2026.

Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.