Official agent skill

Bedrock Operation Review

by aws in aws/tools-for-devops-agent

Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Bedrock Operation Review

skills CLI
$ npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/tools-for-devops-agent bedrock-operation-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bedrock-operation-review .claude/skills/bedrock-operation-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bedrock-operation-review
GitHub stars
103
Token cost
~5.4k tokens
SKILL.md length
1,925 words
Files
12 (incl. references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices.

  • Works in 5 steps: Identify Target Scope → Discover Bedrock Resources → Collect CloudWatch Metrics (namespace… → …
  • A user asks to review
  • SKILL.md covers When to Use, Step 1: Identify Target Scope, Step 2: Discover Bedrock… and Step 3: Collect CloudWatch…, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bedrock Operation Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices. Use this skill when a user asks to review, audit, or assess Amazon Bedrock workloads for best-practices compliance, security posture, performance, cost optimization, service quotas, or resilience. Triggers on requests like "Bedrock review", "Bedrock best practices audit", "GenAI operational assessment", "review my Bedrock account", "Bedrock health check", "Bedrock cost optimization review", or "ORR for…

Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).

It sits in DevOps & Cloud, covering Cloud architecture. It works with Amazon Bedrock and Amazon Web Services. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.

When your agent uses it

  • A user asks to review
  • Assess Amazon Bedrock workloads for best-practices compliance
  • Security posture
  • Cost optimization

Example prompts

  • “Bedrock review”
  • “Bedrock best practices audit”
  • “GenAI operational assessment”
  • “/bedrock-operation-review”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify Target Scope
  2. Discover Bedrock Resources
  3. Collect CloudWatch Metrics (namespace AWS/Bedrock)
  4. Analyze Against Best Practices
  5. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • aws.amazon.com
    • repost.aws

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bedrock Operation Review loads about 5.4k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 138 tokens; SKILL.md has 1,925 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~5.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,925 words, ~5,448 tokens.

Download SKILL.mdSave it as .claude/skills/bedrock-operation-review/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
bedrock-operation-review
description
Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices. Use this skill when a user asks to review, audit, or assess Amazon Bedrock workloads for best-practices compliance, security posture, performance, cost optimization, service quotas, or resilience. Triggers on requests like "Bedrock review", "Bedrock best practices audit", "GenAI operational assessment", "review my Bedrock account", "Bedrock health check", "Bedrock cost optimization review", or "ORR for Bedrock".
metadata.author
smnixon
metadata.version
1.0.0
metadata.aws-devops-agent-skills.agent-t
Chat tasks, Evaluation
metadata.aws-devops-agent-skills.aws-ser
Amazon Bedrock
metadata.aws-devops-agent-skills.technic
Machine Learning, GenAI

Amazon Bedrock Operational Review

Conduct a comprehensive operational review of Amazon Bedrock workloads aligned with the AWS Well-Architected Framework and Amazon Bedrock best practices.

This skill uses the AWS Bedrock, Bedrock Agent, CloudWatch, Service Quotas, and EC2 APIs only — all data is collected through native AWS control-plane APIs and CloudWatch metrics. It performs no data-plane model invocations and reads no prompt or response content.

When to Use

Activate this skill when the user asks to:

  • Review, audit, or assess an Amazon Bedrock workload
  • Check Bedrock best-practices compliance
  • Evaluate Bedrock security, performance, cost, quotas, or resilience
  • Perform a Bedrock operational readiness review (ORR)
  • Investigate Bedrock configuration drift, throttling, or cost drivers

Step 1: Identify Target Scope

Ask the user which accounts and regions to review. Accept:

  • Specific account IDs and regions
  • "all regions" for a given account
  • A specific pillar or set of checks (e.g. "just cost optimization")

If no scope is given, default to all configured account regions and all pillars. Default the analysis window to the last 7 days unless the user specifies a range (historical windows older than ~2 weeks may have reduced CloudWatch resolution).

Step 2: Discover Bedrock Resources

Per account/region, begin by checking whether the account actually uses Bedrock in this region. Do not use bedrock.ListFoundationModels as an activity signal — it returns the regional model catalog available to the account and is generally non-empty in every supported region regardless of usage, so it is treated as catalog data only (see ListFoundationModels).

Instead, determine activity from account-owned resources and AWS/Bedrock metrics:

  • Account-owned resources: bedrockagent.ListAgents, bedrockagent.ListKnowledgeBases, bedrock.ListGuardrails, bedrock.ListCustomModels, bedrock.ListProvisionedModelThroughputs, bedrock.ListInferenceProfiles (application-scoped), and bedrock.ListModelCustomizationJobs.
  • Invocation activity: cloudwatch.ListMetrics for the AWS/Bedrock namespace.

If no account-owned Bedrock resources exist AND CloudWatch shows no AWS/Bedrock metrics for the region, record "No Bedrock activity detected — skipping pillar analysis" for that region and move on. Do not generate empty findings tables for inactive regions.

For regions where Bedrock is active, collect the full resource inventory:

bedrock.ListFoundationModels                   # catalog reference only: model
                                               # availability + lifecycle status
                                               # (NOT an account-activity signal)
bedrock.ListGuardrails / GetGuardrail          # configured guardrails
bedrock.GetModelInvocationLoggingConfiguration
bedrock.ListInferenceProfiles / GetInferenceProfile
bedrock.ListPromptRouters / GetPromptRouter
bedrock.ListProvisionedModelThroughputs / GetProvisionedModelThroughput
bedrock.ListCustomModels / GetCustomModel
bedrock.ListModelCustomizationJobs / GetModelCustomizationJob
bedrockagent.ListAgents / GetAgent             # agents (draft version)
bedrockagent.ListAgentVersions / GetAgentVersion  # deployed versions — read only the
                                               # per-version model ID, orchestration
                                               # type, and whether a prompt override is
                                               # present. Do NOT read the override
                                               # base-prompt template text.
bedrockagent.ListAgentAliases
bedrockagent.ListKnowledgeBases / GetKnowledgeBase
bedrockagent.ListDataSources / GetDataSource
bedrockagent.ListPrompts                       # Prompt Management: presence/metadata
                                               # only (identifiers, versions, counts).
                                               # Do NOT call GetPrompt — it returns
                                               # prompt template/variant content, which
                                               # this skill does not read.

Capture per resource: identifiers, ARNs, status, creation/update timestamps, encryption configuration (AWS-managed vs customer-managed KMS key), and any VPC configuration.

Step 3: Collect CloudWatch Metrics (namespace AWS/Bedrock)

Before querying metrics, load the authoritative thresholds reference:

read_skill_resource(skill_id="bedrock-operation-review", path="references/metrics-thresholds.md")

Use the thresholds from that file when classifying metric values as Normal, Warning, or Critical throughout this step and Step 4.

Discover which models are actually invoked with cloudwatch.ListMetrics (dimension ModelId), then pull metric data with cloudwatch.GetMetricData. Use the user's selected window; default to 7 days.

Key model-level metrics (dimension ModelId):

MetricStatSignal
InvocationsSumVolume / denominator for rate calcs
InvocationThrottlesSumThrottling / quota pressure
InvocationServerErrorsSumServer-side failures
InvocationClientErrorsSumBad input / blocked content
InvocationLatencyAverage, p95End-to-end latency
TimeToFirstTokenAverage, p95Perceived latency (streaming)
InputTokenCountSumInput token volume
OutputTokenCountSumOutput token volume
InvocationsIntervenedSumGuardrail interventions
TextUnitCountSumGuardrail text-unit consumption
CacheReadInputTokenCountSumPrompt cache reads
CacheWriteInputTokenCountSumPrompt cache writes

GPU metrics for self-managed workloads live in the CWAgent namespace (nvidia_smi_utilization_gpu, nvidia_smi_memory_util).

cloudwatch.GetMetricData allows up to 500 metric-data queries per call — batch requests and paginate when a region has many invoked models.

Step 4: Analyze Against Best Practices

Before evaluating findings, load the best-practices checklist:

read_skill_resource(skill_id="bedrock-operation-review", path="references/best-practices-checklist.md")

Use the checklist as the canonical list of items to evaluate for each pillar. Mark each item as ✅ Pass, ⚠️ Warning, ❌ Fail, or ➖ Not Applicable, and generate a finding for every Fail or Warning.

Evaluate all collected data across the pillars below and assign a severity to every finding: CRITICAL, HIGH, MEDIUM, LOW, or INFO. The pillars mirror the Bedrock operational review structure: Security, Performance, Service Quotas, Cost Optimization, Resilience.

4.1 Security

Ref: Security in Amazon Bedrock

  • Guardrails: no guardrail configured on high-volume workloads → HIGH. Use guardrails to filter hate, insult, sexual, violence, and PII content and to block denied topics relevant to the use case. Guardrails
  • Guardrail signals: high InvocationClientErrors (>5% of Invocations) indicates problematic content reaching models — filter before invocation → MEDIUM. InvocationsIntervened <5% of invocations on an active guardrail suggests under-configuration; >15% suggests policy over-tuning → review.
  • Model invocation logging: for workloads handling sensitive content (PII, PCI, HIPAA), enabling invocation logging persists prompt/output on the account and may conflict with data-handling requirements. Flag logging configuration mismatches → MEDIUM. Model invocation logging
  • Knowledge Base configuration: chunking (200–1000 tokens), embedding strategy, encryption, access controls, and VPC endpoints → MEDIUM where missing. Knowledge bases
  • Knowledge Base data source encryption: data sources without a customer-managed KMS key when handling sensitive content → MEDIUM. Encryption of knowledge base resources
  • VPC configuration for model customization jobs: customization jobs without a configured VPC expose training data to the internet → HIGH. (us-east-1, us-west-2) Configure a VPC for Bedrock
  • IAM fine-grained access control: agent/alias IAM policies using resource * without justification → MEDIUM. Follow least privilege for inference endpoints. A comprehensive least-privilege audit of all IAM policies is out of scope for this skill — flag obvious *-resource findings only, at INFO severity. IAM for Amazon Bedrock
  • Knowledge Base logging: KB ingestion log delivery not configured → LOW. CloudTrail and CloudWatch not enabled for anomaly detection → MEDIUM.
  • Prompt injection: this skill does not read prompt template content, so it does not assess whether individual templates are hardened. Instead, treat a guardrail configured with prompt-attack filtering as the control signal — workloads with no guardrail (or a guardrail lacking a prompt-attack content filter) are exposed to prompt injection → MEDIUM. Provide general hardening guidance by reference only. Prompt engineering best practices
  • Model access: Amazon Bedrock foundation models are enabled by default (no explicit access request needed) — model access should instead be controlled via IAM and SCP policies scoped to the essential models for the use case (least privilege). A comprehensive least-privilege audit is out of scope for this skill — report gaps at INFO severity only. Model access
4.2 Performance

Ref: Monitoring Amazon Bedrock

  • Latency and throttling: InvocationLatency p95, TimeToFirstToken p95, throttle rate (InvocationThrottles / Invocations), and server error rate. High throttle rate → HIGH (add retries with exponential backoff + jitter, request quota increase, spread load, use CRIS). Prefer smaller models and streaming for latency-sensitive apps. Improve Bedrock performance
  • Agent performance: agents can use a latency-optimized flow when they have a single knowledge base, no enabled action groups, don't ask follow-ups, and use the default orchestration template → flag agents that miss these conditions. Optimize agent performance
  • Agent version configuration drift: compare deployed alias versions (from GetAgentVersion) against the draft. Aliases pinned to outdated versions with different model IDs or orchestration types than the current draft → MEDIUM (may miss performance or capability improvements).
  • Invoked model versions: models in Legacy or End-of-Life state still receiving invocations → MEDIUM (plan upgrade; check the model card for its EOL date rather than assuming a fixed notice period — Legacy notice periods are either 6 months or 45 days depending on the model, with most models using 6 months). Model lifecycle
  • Data automation: success rate <95%, error rate >5%, or throttle rate >1% for production workloads → MEDIUM. Bedrock Data Automation
  • Bedrock service tier: verify tier selection (default, flex, priority, reserved) matches workload criticality. Latency-sensitive apps on Flex, or batch workloads on Priority, are misaligned → MEDIUM. Service tiers
Show full SKILL.md (771 more words)Show less
4.3 Service Quotas

Ref: Bedrock quotas

  • Model quotas: compare observed P95 invocations-per-minute and tokens-per-minute against the account RPM/TPM quotas (including CRIS and Global CRIS quotas) from servicequotas.GetServiceQuota. Utilization >75% → MEDIUM (request increase before throttling); sustained near the limit → HIGH.
  • Guardrail service quotas: track ApplyGuardrail requests and text-unit consumption for content filter, denied topic, sensitive information, word filter, and contextual grounding policies. Utilization >75% → MEDIUM. Note: CloudWatch metrics don't distinguish Classic vs Standard policy versions, so review manually when both are configured. Guardrail quotas
4.4 Cost Optimization

Ref: Bedrock pricing

  • Application inference profiles: not used for cost allocation / tagging → LOW. App inference profiles integrate with Cost Allocation Tags for usage tracking. Track cost and usage with inference profiles
  • Custom model distillation: narrow, repetitive, high-volume tasks on premium large models are distillation candidates. Rule of thumb: InvocationLatency p99

    3000 ms AND InputTokenCount >1M/month AND throttle rate >5% → high-priority candidate → MEDIUM opportunity. (us-east-1, us-west-2) Model distillation

  • Prompt caching: cache offload % = CacheReadInputTokenCount / (CacheReadInputTokenCount + CacheWriteInputTokenCount). Statuses: Not Supported, Not Enabled, Misconfigured (writes but no reads), Underutilized (<50%), Optimized (≥50%). Input-heavy repeated context that isn't cached → MEDIUM opportunity (up to ~85% latency and ~90% cost reduction on cached prefixes). Prompt caching
  • Prompt management: presence indicates adoption maturity — INFO. Encourage versioning and variant testing for cost/quality tradeoffs. Prompt management
  • Intelligent prompt routing: routes requests within a model family to the best-quality/lowest-cost model. Absence on mixed-complexity workloads → LOW opportunity. Intelligent prompt routing
  • Provisioned throughput: balance provisioned commitments against on-demand. Idle or expiring provisioned models, or steady baseline load on on-demand → MEDIUM. Provisioned Throughput
  • Batch inference opportunity: high-volume (>10K/day), latency-tolerant, or scheduled workloads on on-demand → MEDIUM (up to ~50% cost savings). Self-managed batch on EC2 GPU / SageMaker Batch Transform → migrate to managed Batch Inference. Batch inference
  • EC2 GPU utilization (self-managed P4/P5/P5en/P6, requires CloudWatch Agent + NVIDIA DCGM plugin, 7-day minimum window):
    • Avg GPU util <40% → over-provisioned → migrate training to Trainium2 (~30–50%).
    • Avg GPU memory util >90% → OOM risk → model parallelism / larger instance.
    • GPU usage CV (StdDev/Mean) >0.5 → bursty → Spot Instances / Capacity Blocks.
    • Avg GPU util >80% sustained → commitment candidate → ML Savings Plans / RIs.
4.5 Resilience

Ref: Cross-region inference

  • Cross-Region Inference (CRIS): CRIS adoption % = Profile InputTokenCount / (Profile InputTokenCount + Base Model InputTokenCount). Low adoption (traffic bypassing the inference profile by invoking base models directly) reduces burst resilience and, for global profiles, forgoes ~10% savings → MEDIUM.

Step 5: Generate Report

Generate a shareable report artifact for the review.

Artifact naming: bedrock-review-<account-id>-<region>-<YYYY-MM-DD>.md Example: bedrock-review-123456789012-us-east-1-2026-04-29.md

Structure the Markdown document with:

Report Header
# Amazon Bedrock Operational Review — <account-id> / <region>
Date: <YYYY-MM-DD> | Analysis window: <start> to <end>
Pillars reviewed: <list>
Executive Summary
  • Health: ✅ HEALTHY / ⚠️ WARNINGS / ❌ CRITICAL
  • Finding counts by severity
  • Top 3 critical/high items
Findings by Pillar

For each of Security, Performance, Service Quotas, Cost Optimization, Resilience:

| # | Finding | Severity | Current State | Recommendation |

CloudWatch Metrics Summary

| Metric | Model | Stat | Value | Status | Finding |

Service Quota Utilization

| Quota | Value | Observed P95 | Utilization % | Risk |

Cost Optimization Opportunities

| Opportunity | Signal | Est. Impact | Effort |

Priority Matrix

| # | Finding | Severity | Pillar | Effort | Impact |

Next Steps
  • Immediate (CRITICAL/HIGH — 7 days)
  • Short-term (MEDIUM — 30 days)
  • Long-term (LOW — 90 days)

Severity Definitions

SeverityDefinitionSLA
CRITICALImmediate risk to availability, security, or data integrityFix within 24–48 hours
HIGHSignificant gap that could lead to incidentsFix within 1 week
MEDIUMNotable improvement opportunityPlan within 30 days
LOWMinor optimization or hardeningAddress when convenient
INFOObservation, no action requiredN/A

Region-Restricted Checks

Some checks only run in specific regions:

  • VPC Configuration for Model Customization Job: us-east-1, us-west-2
  • Custom Model Distillation: us-east-1, us-west-2
  • Application Inference Profiles: us-east-1, us-east-2, us-west-2, ap-northeast-1, ap-northeast-2, ap-southeast-2, ap-south-1, eu-central-1, eu-west-1, eu-west-3, us-gov-east-1, us-gov-west-1

Skip a check silently in unsupported regions rather than reporting a failure.

Known API Quirks

  • CloudWatch metrics for guardrail Content Filter and Denied Topic policies do not distinguish Classic vs Standard policy versions — utilization can be inaccurate when both are configured. Review manually.
  • cloudwatch.GetMetricData caps at 500 metric-data queries per call — batch and paginate for accounts with many invoked models.
  • Some models are only invocable through Cross-Region Inference profiles and will show 0 direct token usage (100% CRIS adoption by design).
  • Prompt cache entries expire after ~5 minutes of inactivity; aggregate CloudWatch windows are directional, not per-session.
  • EC2 GPU signals require the CloudWatch Agent with the NVIDIA DCGM plugin; without it, nvidia_smi_* metrics are absent and GPU signals can't be evaluated.

Data Source Boundaries

This skill collects data exclusively through native AWS APIs (bedrock, bedrockagent, cloudwatch, servicequotas, ec2). It does not:

  • Invoke any foundation model (no data-plane calls).
  • Read prompt or response content.
  • Depend on any non-AWS tooling or internal scripts — the skill is self-contained on the DevOps Agent's primary cloud-source IAM role.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (references) in skills/bedrock-operation-review of aws/tools-for-devops-agent.

  • SKILL.md
  • .skilleval.yaml
  • CHANGELOG.md
  • README.md
  • evals/benchmark.json
  • evals/eval_queries.json
  • evals/evals.json
  • evals/files/bedrock-context.json
  • evals/report.json
  • evals/trigger_report.json
  • references/best-practices-checklist.md
  • references/metrics-thresholds.md

Open the folder on GitHubat commit ddda70b

Compare with similar skills

Bedrock Operation Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bedrock Operation Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bedrock Operation Review this skillaws/tools-for-devops-agent103—~5.4kAutomated safety check: PassApache-2.0
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Thesvgglincker/thesvg2.8k—~1.5kAutomated safety check: PassMIT
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0
AWS Architecture Diagramvidanov/aws-architecture-diagram-skill159—~4.9kAutomated safety check: PassMIT

Similar skills

  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • AWS Architecture Diagram

    vidanov/aws-architecture-diagram-skill

    Generate AWS architecture diagrams in draw.io format. An agent skill from vidanov/aws-architecture-diagram-skill.

    159 GitHub stars~4.9k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Configure secure, high-performance connectivity between on-premises infrastructure and cloud platforms using VPN and dedicated connections.

    40k GitHub starsUsed in 11 repos~1.5k tokens
    DevOps & CloudAuto-check passed

More from aws/tools-for-devops-agent

All 31 skills in this repo
  • Aiml GPU Training Cluster Investigation

    aws/tools-for-devops-agent

    Official

    A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.

    103 GitHub stars~5.4k tokensUpdated today
    Auto-check passed
  • AWS Health Events

    aws/tools-for-devops-agent

    Official

    ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

    103 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Database Migration Service Expertise

    aws/tools-for-devops-agent

    Official

    AWS Database Migration Service (DMS) operational review and troubleshooting skill.

    103 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    103 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    103 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Sagemaker AI Ops Review

    aws/tools-for-devops-agent

    Official

    Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.

    103 GitHub stars~3.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Bedrock Operation Review

What does Bedrock Operation Review do?

Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices. Bedrock Operation Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices.

When should I use Bedrock Operation Review?

Bedrock Operation Review fits situations like: A user asks to review; assess Amazon Bedrock workloads for best-practices compliance; security posture; cost optimization.

How do I install Bedrock Operation Review in Claude Code?

Run `npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a claude-code`. Or copy the skill folder (skills/bedrock-operation-review in aws/tools-for-devops-agent) into .claude/skills/bedrock-operation-review in your project. Claude Code loads it when a task matches its description.

How do I install Bedrock Operation Review in Codex?

Run `npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a codex`. Or copy the skill folder (skills/bedrock-operation-review in aws/tools-for-devops-agent) into .agents/skills/bedrock-operation-review in your project. Codex loads it when a task matches its description.

Can I use Bedrock Operation Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bedrock-operation-review, .gemini/skills/bedrock-operation-review, .github/skills/bedrock-operation-review and .opencode/skills/bedrock-operation-review in your project.

What does Bedrock Operation Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Bedrock Operation Review is instructions for the agent only.

Does Bedrock Operation Review access the network?

SKILL.md names 3 domains. As links in the text: docs.aws.amazon.com, aws.amazon.com and repost.aws. This is read from the text; nothing was executed.

Is Bedrock Operation Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bedrock Operation Review use?

Bedrock Operation Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bedrock Operation Review use?

About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Bedrock Operation Review?

Skills that share tags, products or a category with Bedrock Operation Review: Cloud Cost Optimization (wshobson/agents, 40k stars), Thesvg (glincker/thesvg, 2.8k stars), AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars) and Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bedrock Operation Review?

aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 103 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 9, 2026.

Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.