Official agent skill

Cloudfront

by aws in aws/agent-toolkit-for-aws

Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a…

OfficialApache-2.0Auto-check passedBackend & APIs

Install Cloudfront

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill cloudfront -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws cloudfront --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/networking-and-content-delivery-skills/cloudfront .claude/skills/cloudfront && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudfront
GitHub stars
2.8k
Token cost
~1.3k tokens
SKILL.md length
491 words
Files
7 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a…

  • Tasks that involve Cloud networking
  • SKILL.md covers Overview, Which CloudFront task do you…, Routing notes and Cross-service work, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Multi-tenancy

What it does

Cloudfront is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a distribution, caching, and Flat Rate Pricing (FRP) versus pay-as-you-go pricing); managing custom-domain TLS certificates (ACM in us-east-1); configuring multi-tenant distributions; protecting origins with origin access control (OAC), VPC origins, and origin mutual TLS (mTLS); securing content with signed URLs and…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/cloudfront-observability.md`, `references/managing-certificates-with-cloudfront.md` and `references/multi-tenant-distributions.md`).

It sits in Backend & APIs, covering Cloud networking, Multi-tenancy and Authorization and RBAC. It works with Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cloud networking
  • Tasks that involve Multi-tenancy
  • Tasks that involve Authorization and RBAC

Example prompts

  • “Use the cloudfront skill to configure Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF…”
  • “/cloudfront”

What it can do on your machine

Read from SKILL.md and the folder at commit bd49cc8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudfront loads about 1.3k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 253 tokens; SKILL.md has 491 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~253
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit bd49cc8, republished under its Apache-2.0 licence (© aws). 491 words, ~1,311 tokens.

Download SKILL.mdSave it as .claude/skills/cloudfront/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
cloudfront
description
Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a distribution, caching, and Flat Rate Pricing (FRP) versus pay-as-you-go pricing); managing custom-domain TLS certificates (ACM in us-east-1); configuring multi-tenant distributions; protecting origins with origin access control (OAC), VPC origins, and origin mutual TLS (mTLS); securing content with signed URLs and cookies, geographic restrictions, viewer mutual TLS, and edge token validation; and observing traffic with standard and real-time logs. Applicable when the customer wants to put CloudFront in front of content, choose pricing, lock an origin, restrict who can view content, or analyze logs. Not applicable for the Route 53 DNS side of a CloudFront custom domain or failover between distributions (see the route53-cloudfront skill), or for pure-Route 53 DNS work (see the route53 skill).
version
1

Amazon CloudFront

Overview

Domain expertise for configuring Amazon CloudFront content delivery: deciding when to use CloudFront and how it fits the wider architecture, managing custom-domain certificates and multi-tenant distributions, protecting origins, securing content, and observing traffic.

This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting, then follow its constraints and steps. The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to the AWS CLI otherwise. CloudFront is a global service; its API calls and the AWS Certificate Manager (ACM) certificates it uses are made in us-east-1 regardless of where the customer's application runs.

Which CloudFront task do you need?

GoalReference
Decide whether CloudFront is the right layer, see how it integrates, create a distribution, tune caching, or choose pricingwhen to use CloudFront
Serve a custom domain over HTTPS, manage ACM certificates, or run many domains with a certificate per tenantmanaging certificates with CloudFront
Make CloudFront the only way to reach the origin (S3 OAC, VPC origins, origin mutual TLS, security groups)protecting your origins
Limit who can view content by identity, location, client certificate, or auth tokensecuring your content
Get visibility into traffic with standard and real-time logs, and analyze themCloudFront observability
Serve multiple domains through shared configuration with per-tenant customization (SaaS, platform)multi-tenant distributions
Show full SKILL.md (245 more words)Show less

Routing notes

  • Choosing the layer and creating a distribution vs the rest. Whether CloudFront is the right entry layer, what it integrates with, creating a distribution, caching, and pricing live in the when-to-use reference. The other references assume a distribution exists and configure one aspect of it.
  • Protecting origins vs securing content. Locking the origin so it is reachable only through CloudFront (OAC, VPC origins, origin mTLS) is the protecting-your-origins reference. Restricting which viewers can see content (signed URLs and cookies, geographic restrictions, viewer mTLS, edge token validation) is the securing-your-content reference. They are paired: a content control only holds when the origin is also locked.
  • Viewer mTLS vs origin mTLS. Authenticating the client to CloudFront (viewer mTLS) is content security. Authenticating CloudFront to the origin (origin mTLS) is origin protection. Different controls, different references.
  • Custom domain certificate vs Route 53 DNS cutover. Requesting and validating the ACM certificate and adding the alternate domain name is the managing-certificates reference here. Pointing the domain's DNS at the distribution, including the zone apex alias and any failover, is Route 53 work owned by the separate route53-cloudfront skill.

Cross-service work

Pointing a custom domain's DNS at a CloudFront distribution, or failing over between distributions with Route 53 records, is cross-service work owned by the separate route53-cloudfront skill. Use this skill for the CloudFront-side configuration only.

Additional Resources

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/specialized-skills/networking-and-content-delivery-skills/cloudfront of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/cloudfront-observability.md
  • references/managing-certificates-with-cloudfront.md
  • references/multi-tenant-distributions.md
  • references/protecting-your-origins.md
  • references/securing-your-content.md
  • references/when-to-use-cloudfront.md

Open the folder on GitHubat commit bd49cc8

Compare with similar skills

Cloudfront next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudfront compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudfront this skillaws/agent-toolkit-for-aws2.8k—~1.3kAutomated safety check: PassApache-2.0
System Designninehills/skills281—~4.7kAutomated safety check: PassMIT
System Designwondelai/skills2.4k—~4kAutomated safety check: PassMIT
Multi Tenancyrrezartprebreza/spring-boot-skills296—~576Automated safety check: PassMIT
Test Web Cache Behaviorcyberful/cyberful134—~631Automated safety check: PassAGPL-3.0
Cb Security HardeningBlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT

Similar skills

  • System Design

    ninehills/skills

    Design scalable distributed systems using structured approaches for load balancing, caching, database scaling, and message queues.

    281 GitHub stars~4.7k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • System Design

    wondelai/skills

    Design scalable distributed systems using structured approaches for load balancing, caching, database scaling, and message queues.

    2.4k GitHub stars~4k tokensUpdated 26 days ago
    Backend & APIsAuto-check passed
  • Multi Tenancy

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when implementing tenant resolution, database or schema isolation, tenant-aware JPA, reactive tenant context, migrations, caching, jobs, or authorization in Spring Boot 3.

    296 GitHub stars~576 tokensUpdated 16 days ago
    Backend & APIsAuto-check passed
  • Test Web Cache Behavior

    cyberful/cyberful

    Test authorized web-cache key construction, variation, partitioning, authenticated response handling, revalidation, poisoning, deception, purge, and TTL behavior.

    134 GitHub stars~631 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • LLM Gateway

    sickn33/agentic-awesome-skills

    Deploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking.

    47k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Questions about Cloudfront

What does Cloudfront do?

Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a…. Cloudfront is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization.

When should I use Cloudfront?

Cloudfront fits situations like: tasks that involve Cloud networking; tasks that involve Multi-tenancy; tasks that involve Authorization and RBAC.

How do I install Cloudfront in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill cloudfront -a claude-code`. Or copy the skill folder (skills/specialized-skills/networking-and-content-delivery-skills/cloudfront in aws/agent-toolkit-for-aws) into .claude/skills/cloudfront in your project. Claude Code loads it when a task matches its description.

How do I install Cloudfront in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill cloudfront -a codex`. Or copy the skill folder (skills/specialized-skills/networking-and-content-delivery-skills/cloudfront in aws/agent-toolkit-for-aws) into .agents/skills/cloudfront in your project. Codex loads it when a task matches its description.

Can I use Cloudfront in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill cloudfront -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudfront, .gemini/skills/cloudfront, .github/skills/cloudfront and .opencode/skills/cloudfront in your project.

What does Cloudfront need to run?

SKILL.md names no scripts, command-line tools or credentials: Cloudfront is instructions for the agent only.

Does Cloudfront access the network?

SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and aws.amazon.com. This is read from the text; nothing was executed.

Is Cloudfront safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloudfront use?

Cloudfront is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudfront use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 21k tokens, read only when the agent opens those files.

What are the alternatives to Cloudfront?

Skills that share tags, products or a category with Cloudfront: System Design (ninehills/skills, 281 stars), System Design (wondelai/skills, 2.4k stars), Multi Tenancy (rrezartprebreza/spring-boot-skills, 296 stars) and Test Web Cache Behavior (cyberful/cyberful, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudfront?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,816 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.