Cloud Cost Optimization
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices.
$ npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent bedrock-operation-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bedrock-operation-review .claude/skills/bedrock-operation-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bedrock-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/bedrock-operation-review into .claude/skills/bedrock-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bedrock-operation-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/bedrock-operation-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent bedrock-operation-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/bedrock-operation-review .agents/skills/bedrock-operation-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bedrock-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/bedrock-operation-review into .agents/skills/bedrock-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bedrock-operation-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent bedrock-operation-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/bedrock-operation-review .cursor/skills/bedrock-operation-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bedrock-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/bedrock-operation-review into .cursor/skills/bedrock-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bedrock-operation-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/bedrock-operation-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent bedrock-operation-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/bedrock-operation-review .gemini/skills/bedrock-operation-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bedrock-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/bedrock-operation-review into .gemini/skills/bedrock-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bedrock-operation-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent bedrock-operation-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/bedrock-operation-review .github/skills/bedrock-operation-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bedrock-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/bedrock-operation-review into .github/skills/bedrock-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bedrock-operation-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent bedrock-operation-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/bedrock-operation-review .opencode/skills/bedrock-operation-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bedrock-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/bedrock-operation-review into .opencode/skills/bedrock-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bedrock-operation-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bedrock-operation-reviewComprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices.
Bedrock Operation Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices. Use this skill when a user asks to review, audit, or assess Amazon Bedrock workloads for best-practices compliance, security posture, performance, cost optimization, service quotas, or resilience. Triggers on requests like "Bedrock review", "Bedrock best practices audit", "GenAI operational assessment", "review my Bedrock account", "Bedrock health check", "Bedrock cost optimization review", or "ORR for…
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).
It sits in DevOps & Cloud, covering Cloud architecture. It works with Amazon Bedrock and Amazon Web Services. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comaws.amazon.comrepost.awsFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bedrock Operation Review loads about 5.4k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 138 tokens; SKILL.md has 1,925 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,925 words, ~5,448 tokens.
.claude/skills/bedrock-operation-review/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.Conduct a comprehensive operational review of Amazon Bedrock workloads aligned with the AWS Well-Architected Framework and Amazon Bedrock best practices.
This skill uses the AWS Bedrock, Bedrock Agent, CloudWatch, Service Quotas, and EC2 APIs only — all data is collected through native AWS control-plane APIs and CloudWatch metrics. It performs no data-plane model invocations and reads no prompt or response content.
Activate this skill when the user asks to:
Ask the user which accounts and regions to review. Accept:
If no scope is given, default to all configured account regions and all pillars. Default the analysis window to the last 7 days unless the user specifies a range (historical windows older than ~2 weeks may have reduced CloudWatch resolution).
Per account/region, begin by checking whether the account actually uses Bedrock in
this region. Do not use bedrock.ListFoundationModels as an activity signal — it
returns the regional model catalog available to the account and is generally non-empty
in every supported region regardless of usage, so it is treated as catalog data only
(see ListFoundationModels).
Instead, determine activity from account-owned resources and AWS/Bedrock metrics:
bedrockagent.ListAgents, bedrockagent.ListKnowledgeBases,
bedrock.ListGuardrails, bedrock.ListCustomModels,
bedrock.ListProvisionedModelThroughputs, bedrock.ListInferenceProfiles
(application-scoped), and bedrock.ListModelCustomizationJobs.cloudwatch.ListMetrics for the AWS/Bedrock namespace.If no account-owned Bedrock resources exist AND CloudWatch shows no AWS/Bedrock
metrics for the region, record "No Bedrock activity detected — skipping pillar
analysis" for that region and move on. Do not generate empty findings tables for
inactive regions.
For regions where Bedrock is active, collect the full resource inventory:
bedrock.ListFoundationModels # catalog reference only: model
# availability + lifecycle status
# (NOT an account-activity signal)
bedrock.ListGuardrails / GetGuardrail # configured guardrails
bedrock.GetModelInvocationLoggingConfiguration
bedrock.ListInferenceProfiles / GetInferenceProfile
bedrock.ListPromptRouters / GetPromptRouter
bedrock.ListProvisionedModelThroughputs / GetProvisionedModelThroughput
bedrock.ListCustomModels / GetCustomModel
bedrock.ListModelCustomizationJobs / GetModelCustomizationJob
bedrockagent.ListAgents / GetAgent # agents (draft version)
bedrockagent.ListAgentVersions / GetAgentVersion # deployed versions — read only the
# per-version model ID, orchestration
# type, and whether a prompt override is
# present. Do NOT read the override
# base-prompt template text.
bedrockagent.ListAgentAliases
bedrockagent.ListKnowledgeBases / GetKnowledgeBase
bedrockagent.ListDataSources / GetDataSource
bedrockagent.ListPrompts # Prompt Management: presence/metadata
# only (identifiers, versions, counts).
# Do NOT call GetPrompt — it returns
# prompt template/variant content, which
# this skill does not read.Capture per resource: identifiers, ARNs, status, creation/update timestamps, encryption configuration (AWS-managed vs customer-managed KMS key), and any VPC configuration.
AWS/Bedrock)Before querying metrics, load the authoritative thresholds reference:
read_skill_resource(skill_id="bedrock-operation-review", path="references/metrics-thresholds.md")Use the thresholds from that file when classifying metric values as Normal, Warning, or Critical throughout this step and Step 4.
Discover which models are actually invoked with cloudwatch.ListMetrics
(dimension ModelId), then pull metric data with cloudwatch.GetMetricData.
Use the user's selected window; default to 7 days.
Key model-level metrics (dimension ModelId):
| Metric | Stat | Signal |
|---|---|---|
| Invocations | Sum | Volume / denominator for rate calcs |
| InvocationThrottles | Sum | Throttling / quota pressure |
| InvocationServerErrors | Sum | Server-side failures |
| InvocationClientErrors | Sum | Bad input / blocked content |
| InvocationLatency | Average, p95 | End-to-end latency |
| TimeToFirstToken | Average, p95 | Perceived latency (streaming) |
| InputTokenCount | Sum | Input token volume |
| OutputTokenCount | Sum | Output token volume |
| InvocationsIntervened | Sum | Guardrail interventions |
| TextUnitCount | Sum | Guardrail text-unit consumption |
| CacheReadInputTokenCount | Sum | Prompt cache reads |
| CacheWriteInputTokenCount | Sum | Prompt cache writes |
GPU metrics for self-managed workloads live in the CWAgent namespace
(nvidia_smi_utilization_gpu, nvidia_smi_memory_util).
cloudwatch.GetMetricData allows up to 500 metric-data queries per call — batch
requests and paginate when a region has many invoked models.
Before evaluating findings, load the best-practices checklist:
read_skill_resource(skill_id="bedrock-operation-review", path="references/best-practices-checklist.md")Use the checklist as the canonical list of items to evaluate for each pillar. Mark each item as ✅ Pass, ⚠️ Warning, ❌ Fail, or ➖ Not Applicable, and generate a finding for every Fail or Warning.
Evaluate all collected data across the pillars below and assign a severity to every finding: CRITICAL, HIGH, MEDIUM, LOW, or INFO. The pillars mirror the Bedrock operational review structure: Security, Performance, Service Quotas, Cost Optimization, Resilience.
Ref: Security in Amazon Bedrock
InvocationClientErrors (>5% of Invocations)
indicates problematic content reaching models — filter before invocation → MEDIUM.
InvocationsIntervened <5% of invocations on an active guardrail suggests
under-configuration; >15% suggests policy over-tuning → review.*
without justification → MEDIUM. Follow least privilege for inference endpoints.
A comprehensive least-privilege audit of all IAM policies is out of scope for this
skill — flag obvious *-resource findings only, at INFO severity.
IAM for Amazon BedrockRef: Monitoring Amazon Bedrock
InvocationLatency p95, TimeToFirstToken p95,
throttle rate (InvocationThrottles / Invocations), and server error rate. High
throttle rate → HIGH (add retries with exponential backoff + jitter, request quota
increase, spread load, use CRIS). Prefer smaller models and streaming for
latency-sensitive apps.
Improve Bedrock performanceGetAgentVersion) against the draft. Aliases pinned to outdated versions with
different model IDs or orchestration types than the current draft → MEDIUM (may
miss performance or capability improvements).default, flex, priority,
reserved) matches workload criticality. Latency-sensitive apps on Flex, or batch
workloads on Priority, are misaligned → MEDIUM.
Service tiersRef: Bedrock quotas
servicequotas.GetServiceQuota. Utilization >75% → MEDIUM (request increase before
throttling); sustained near the limit → HIGH.Ref: Bedrock pricing
InvocationLatency p993000 ms AND
InputTokenCount>1M/month AND throttle rate >5% → high-priority candidate → MEDIUM opportunity. (us-east-1, us-west-2) Model distillation
CacheReadInputTokenCount / (CacheReadInputTokenCount + CacheWriteInputTokenCount).
Statuses: Not Supported, Not Enabled, Misconfigured (writes but no reads),
Underutilized (<50%), Optimized (≥50%). Input-heavy repeated context that isn't
cached → MEDIUM opportunity (up to ~85% latency and ~90% cost reduction on cached
prefixes).
Prompt cachingProfile InputTokenCount / (Profile InputTokenCount + Base Model InputTokenCount).
Low adoption (traffic bypassing the inference profile by invoking base models
directly) reduces burst resilience and, for global profiles, forgoes ~10% savings →
MEDIUM.Generate a shareable report artifact for the review.
Artifact naming: bedrock-review-<account-id>-<region>-<YYYY-MM-DD>.md
Example: bedrock-review-123456789012-us-east-1-2026-04-29.md
Structure the Markdown document with:
# Amazon Bedrock Operational Review — <account-id> / <region>
Date: <YYYY-MM-DD> | Analysis window: <start> to <end>
Pillars reviewed: <list>For each of Security, Performance, Service Quotas, Cost Optimization, Resilience:
| # | Finding | Severity | Current State | Recommendation |
| Metric | Model | Stat | Value | Status | Finding |
| Quota | Value | Observed P95 | Utilization % | Risk |
| Opportunity | Signal | Est. Impact | Effort |
| # | Finding | Severity | Pillar | Effort | Impact |
| Severity | Definition | SLA |
|---|---|---|
| CRITICAL | Immediate risk to availability, security, or data integrity | Fix within 24–48 hours |
| HIGH | Significant gap that could lead to incidents | Fix within 1 week |
| MEDIUM | Notable improvement opportunity | Plan within 30 days |
| LOW | Minor optimization or hardening | Address when convenient |
| INFO | Observation, no action required | N/A |
Some checks only run in specific regions:
Skip a check silently in unsupported regions rather than reporting a failure.
cloudwatch.GetMetricData caps at 500 metric-data queries per call — batch and
paginate for accounts with many invoked models.nvidia_smi_* metrics are absent and GPU signals can't be evaluated.This skill collects data exclusively through native AWS APIs
(bedrock, bedrockagent, cloudwatch, servicequotas, ec2). It does not:
© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files (references) in skills/bedrock-operation-review of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
Bedrock Operation Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bedrock Operation Review this skillaws/tools-for-devops-agent | 103 | — | ~5.4k | Automated safety check: Pass | Apache-2.0 | |
| Cloud Cost Optimizationwshobson/agents | 40k | 14 repos | ~1.7k | Automated safety check: Pass | MIT | |
| Thesvgglincker/thesvg | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | |
| AWS Cloud Advisortech-leads-club/agent-skills | 7k | — | ~2.1k | Automated safety check: Pass | CC-BY-4.0 | |
| Dangling DNS Finderanirudhbiyani/findmytakeover | 180 | — | ~1.8k | Automated safety check: Pass | GPL-3.0 | |
| AWS Architecture Diagramvidanov/aws-architecture-diagram-skill | 159 | — | ~4.9k | Automated safety check: Pass | MIT |
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
glincker/thesvg
Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.
tech-leads-club/agent-skills
Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.
anirudhbiyani/findmytakeover
Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.
vidanov/aws-architecture-diagram-skill
Generate AWS architecture diagrams in draw.io format. An agent skill from vidanov/aws-architecture-diagram-skill.
wshobson/agents
Configure secure, high-performance connectivity between on-premises infrastructure and cloud platforms using VPN and dedicated connections.
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
Works with
Categories
Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices. Bedrock Operation Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Comprehensive Amazon Bedrock review aligned with the AWS Well-Architected Framework and Bedrock best practices.
Bedrock Operation Review fits situations like: A user asks to review; assess Amazon Bedrock workloads for best-practices compliance; security posture; cost optimization.
Run `npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a claude-code`. Or copy the skill folder (skills/bedrock-operation-review in aws/tools-for-devops-agent) into .claude/skills/bedrock-operation-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a codex`. Or copy the skill folder (skills/bedrock-operation-review in aws/tools-for-devops-agent) into .agents/skills/bedrock-operation-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill bedrock-operation-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bedrock-operation-review, .gemini/skills/bedrock-operation-review, .github/skills/bedrock-operation-review and .opencode/skills/bedrock-operation-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Bedrock Operation Review is instructions for the agent only.
SKILL.md names 3 domains. As links in the text: docs.aws.amazon.com, aws.amazon.com and repost.aws. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bedrock Operation Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Bedrock Operation Review: Cloud Cost Optimization (wshobson/agents, 40k stars), Thesvg (glincker/thesvg, 2.8k stars), AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars) and Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 103 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 9, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.