AWS Cdk Development
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
A skill your agent uses when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change.
$ npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent aws-vpc-dns-investigation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aws-vpc-dns-investigation .claude/skills/aws-vpc-dns-investigation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aws-vpc-dns-investigation" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-vpc-dns-investigation into .claude/skills/aws-vpc-dns-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-vpc-dns-investigation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-vpc-dns-investigationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent aws-vpc-dns-investigation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/aws-vpc-dns-investigation .agents/skills/aws-vpc-dns-investigation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aws-vpc-dns-investigation" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-vpc-dns-investigation into .agents/skills/aws-vpc-dns-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-vpc-dns-investigation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent aws-vpc-dns-investigation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/aws-vpc-dns-investigation .cursor/skills/aws-vpc-dns-investigation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aws-vpc-dns-investigation" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-vpc-dns-investigation into .cursor/skills/aws-vpc-dns-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-vpc-dns-investigation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/aws-vpc-dns-investigation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent aws-vpc-dns-investigation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/aws-vpc-dns-investigation .gemini/skills/aws-vpc-dns-investigation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aws-vpc-dns-investigation" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-vpc-dns-investigation into .gemini/skills/aws-vpc-dns-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-vpc-dns-investigation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent aws-vpc-dns-investigationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/aws-vpc-dns-investigation .github/skills/aws-vpc-dns-investigation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aws-vpc-dns-investigation" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-vpc-dns-investigation into .github/skills/aws-vpc-dns-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-vpc-dns-investigation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent aws-vpc-dns-investigation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/aws-vpc-dns-investigation .opencode/skills/aws-vpc-dns-investigation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aws-vpc-dns-investigation" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/aws-vpc-dns-investigation into .opencode/skills/aws-vpc-dns-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-vpc-dns-investigation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aws-vpc-dns-investigationA skill your agent uses when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change.
AWS Vpc DNS Investigation is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Use this skill when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change. Activate on symptoms such as NXDOMAIN or SERVFAIL from an EC2 instance, a hostname resolving to a public address when a private endpoint was expected, an AWS service endpoint that stopped resolving after a VPC endpoint or Route 53 change, an application reaching the wrong IP, resolution that works from one instance but not another, IPv6 or dualstack resolution differences, a suspected on-premises…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).
It sits in DevOps & Cloud, covering GraphQL and Operations and SOPs. It works with Amazon Web Services and Model Context Protocol. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AWS Vpc DNS Investigation loads about 2k tokens when it runs. Until then it costs about 231 tokens; SKILL.md has 907 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 907 words, ~2,029 tokens.
.claude/skills/aws-vpc-dns-investigation/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Use the tools on the connected aws-vpc-dns-diagnostics MCP server.
Before calling any tool, determine which mode applies:
If the request is ambiguous, ask the operator to clarify. Do not default to Mode A when the input lacks an instance ID, and do not default to Mode B when the operator describes a live symptom.
Regardless of mode, call get_sop with slug A-critical-safety-rules and
follow every rule it contains. These are non-negotiable constraints on how you
interpret results, handle opaque constructs, and report findings.
account_id, region, instance_id, and the failing DNS name.
dns_probe_context — establishes VPC-attribute preconditions: enableDnsSupport,
enableDnsHostnames, address family, DHCP option set. A resolution result means
nothing until you know whether the VPC resolver is answering.dns_probe_compare — runs the allowlisted probe set inside the instance via
SSM. Returns each resolver's answer and the resolver's own identity from
hostname.bind. The VPC DHCP resolver is auto-added for comparison.get_sop — load the pattern runbook matching the observed signature
(see trap-to-SOP mapping below).enableDnsSupport is false: load A-resolver-disabled-precondition. The
VPC resolver is intentionally dark and every probe failure follows from that./etc/resolv.conf (from the probe output) against the
DHCP option set. A mismatch means the instance is not using the VPC-intended
resolver.A-name-category-classification), not by
whether resolvers agree. Two resolvers returning the same wrong answer is still
a failure.| Observed signature | SOP slug |
|---|---|
| Custom resolver answers differently from VPC .2 | A-custom-resolver-divergence |
| FORWARD rule and PHZ both match the name | A-forward-vs-phz-precedence-collision |
| A record works, AAAA fails (or vice versa) | A-address-family-divergence |
| enableDnsSupport is false | A-resolver-disabled-precondition |
| General live comparison procedure | A-mode-a-live-resolver-comparison |
Label every finding as Observed (ground truth from the probe). State which resolver answered and what it returned. When Mode A and Mode B produce different conclusions for the same name, Mode A wins because it is ground truth from inside the subnet.
account_id, region, vpc_id, and a change descriptor (structured dict with type
and type-specific fields). No instance required.
dns_simulate_effective_config — returns the VPC's effective DNS config: the
union of directly attached resources and anything inherited through an
associated Route 53 Profile, each construct tagged by source.dns_simulate_change — applies the proposed change symbolically and returns a
per-name impact report (before/after, delta, traps, severity, volume).get_sop — load runbooks for any traps reported in the impact table
(see trap-to-SOP mapping below).volumes (from Resolver Query Logs), names are ranked
by traffic. This is enrichment; absence does not invalidate the simulation.| Trap label in impact report | SOP slug |
|---|---|
| VPCE-shadow-NXDOMAIN | B-vpce-shadow-nxdomain |
| broad-FORWARD-sweep | B-broad-forward-sweep |
| flag-AND-mismatch | B-flag-and-mismatch |
| DNS-Firewall-block | B-dns-firewall-block |
| profile-union-shift | B-profile-propagation-timing |
| General pre-change procedure | B-mode-b-pre-change-validation |
Label every finding as Predicted (symbolic, not ground truth). State the candidate-set size, its source (API-derived or operator-supplied), and that names outside this set were not evaluated. Include the propagation timing caveat for Profile changes.
Call get_sop with slug C-cross-account-opaque-constructs when the effective
config or impact report contains opaque markers. Cross-account constructs shared
via RAM or a Route 53 Profile may be enumerable but their contents are not
readable from the consumer account. Report them as "present but unknown content"
rather than treating them as absent or inferring past them.
Call get_sop with slug C-limitations-and-boundaries and state the relevant
boundaries to the operator. Key constraints:
Every response produced by this skill must include:
Requires the aws-vpc-dns-diagnostics MCP server registered in the Agent Space
with its tools allowlisted. The server is at mcp/aws-vpc-dns-diagnostics-mcp/.
If the server is not registered or SSM is unreachable, report that as the blocker
rather than guessing at the resolution path.
© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files in skills/aws-vpc-dns-investigation of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
AWS Vpc DNS Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AWS Vpc DNS Investigation this skillaws/tools-for-devops-agent | 103 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| AWS Cdk Developmentzxkane/aws-skills | 367 | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| Spotinfoalexei-led/spotinfo | 164 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Install Boltmcpboltmcp/boltmcp | 371 | — | ~2.3k | Automated safety check: Pass | None | |
| Unraiddinglebear-ai/unraid | 135 | — | ~5.4k | Automated safety check: Notes | MIT |
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
alexei-led/spotinfo
Query Spot/preemptible VM prices, savings and interruption risk across AWS, GCP and Azure with the spotinfo CLI.
boltmcp/boltmcp
A skill your agent uses when asked to help install or uninstall BoltMCP
dinglebear-ai/unraid
This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…
agentic-community/mcp-gateway-registry
Keep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry.
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
Categories
A skill your agent uses when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change. AWS Vpc DNS Investigation is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Use this skill when a name is not resolving as expected inside a VPC, or before applying a DNS control-plane change.
AWS Vpc DNS Investigation fits situations like: A name is not resolving as expected inside a VPC; before applying a DNS control-plane change.
Run `npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a claude-code`. Or copy the skill folder (skills/aws-vpc-dns-investigation in aws/tools-for-devops-agent) into .claude/skills/aws-vpc-dns-investigation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a codex`. Or copy the skill folder (skills/aws-vpc-dns-investigation in aws/tools-for-devops-agent) into .agents/skills/aws-vpc-dns-investigation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill aws-vpc-dns-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-vpc-dns-investigation, .gemini/skills/aws-vpc-dns-investigation, .github/skills/aws-vpc-dns-investigation and .opencode/skills/aws-vpc-dns-investigation in your project.
SKILL.md names no scripts, command-line tools or credentials: AWS Vpc DNS Investigation is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AWS Vpc DNS Investigation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with AWS Vpc DNS Investigation: AWS Cdk Development (zxkane/aws-skills, 367 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Spotinfo (alexei-led/spotinfo, 164 stars) and Install Boltmcp (boltmcp/boltmcp, 371 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 103 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 9, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.