Official agent skill

Configuring Vpc Endpoints For Private AWS Service Access

by aws in aws/agent-toolkit-for-aws

Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink.

OfficialApache-2.0Auto-check passedDatabases

Install Configuring Vpc Endpoints For Private AWS Service Access

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill configuring-vpc-endpoints-for-private-aws-service-access -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws configuring-vpc-endpoints-for-private-aws-service-access --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/networking-and-content-delivery-skills/configuring-vpc-endpoints-for-private-aws-service-access .claude/skills/configuring-vpc-endpoints-for-private-aws-service-access && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuring-vpc-endpoints-for-private-aws-service-access
GitHub stars
2.8k
Token cost
~396 tokens
SKILL.md length
146 words
Files
2 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink.

  • Setting up secure private connectivity to S3
  • SKILL.md covers Overview, Configure VPC endpoints and Troubleshooting
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Other AWS services without internet gateway

What it does

Configuring Vpc Endpoints For Private AWS Service Access is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink. Use when setting up secure private connectivity to S3, DynamoDB, and other AWS services without internet gateway, NAT device, or public IP addresses. Covers endpoint creation, security groups, route tables, and DNS configuration.

Its SKILL.md is about 400 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/configure-vpc-endpoints-for-private-aws-service-access.md`).

It sits in Databases, covering File uploads and storage and NoSQL databases. It works with Amazon Web Services and Amazon DynamoDB. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Setting up secure private connectivity to S3
  • Other AWS services without internet gateway
  • Public IP addresses

Example prompts

  • “Use the configuring-vpc-endpoints-for-private-aws-service-access skill to configure VPC endpoints (interface and gateway) for private AWS service…”
  • “/configuring-vpc-endpoints-for-private-aws-service-access”

What it can do on your machine

Read from SKILL.md and the folder at commit 2cb0fa1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuring Vpc Endpoints For Private AWS Service Access loads about 396 tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 146 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~396
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit 2cb0fa1, republished under its Apache-2.0 licence (© aws). 146 words, ~396 tokens.

Download SKILL.mdSave it as .claude/skills/configuring-vpc-endpoints-for-private-aws-service-access/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
configuring-vpc-endpoints-for-private-aws-service-access
description
Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink. Use when setting up secure private connectivity to S3, DynamoDB, and other AWS services without internet gateway, NAT device, or public IP addresses. Covers endpoint creation, security groups, route tables, and DNS configuration.
version
1

Configuring VPC Endpoints for Private AWS Service Access

Overview

Domain expertise for configuring VPC endpoints to enable private access to AWS services without routing traffic through the internet. Covers both gateway endpoints (S3, DynamoDB) and interface endpoints (EC2, SSM, Secrets Manager, etc.) powered by AWS PrivateLink.

Configure VPC endpoints

To create and configure VPC endpoints for private AWS service access, follow the procedure exactly. See VPC endpoints configuration procedure.

Troubleshooting

Endpoint not available

Check security group rules, subnet configurations, and service availability in the region.

DNS resolution issues

Verify DNS hostnames and DNS resolution are enabled on the VPC and that the DHCP options set has correct domain name servers.

Connection timeouts

Verify security group rules allow HTTPS traffic (port 443) and route tables are properly configured for gateway endpoints.

Policy restrictions

Review endpoint policies — default policies allow all access, but custom policies may be restrictive.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/specialized-skills/networking-and-content-delivery-skills/configuring-vpc-endpoints-for-private-aws-service-access of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/configure-vpc-endpoints-for-private-aws-service-access.md

Open the folder on GitHubat commit 2cb0fa1

Compare with similar skills

Configuring Vpc Endpoints For Private AWS Service Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuring Vpc Endpoints For Private AWS Service Access compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuring Vpc Endpoints For Private AWS Service Access this skillaws/agent-toolkit-for-aws2.8k—~396Automated safety check: PassApache-2.0
AWS CLI Beastgiuseppe-trisciuoglio/developer-kit357—~1.7kAutomated safety check: NotesMIT
AWSkid-sid/claude-spellbook190—~4.9kAutomated safety check: WarnMIT
AWS Cloud Patternsrohitg00/awesome-claude-code-toolkit2.7k—~1.1kAutomated safety check: PassApache-2.0
Amplify Workflowawslabs/agent-plugins916—~3.2kAutomated safety check: PassApache-2.0
Msk Operationsaws/tools-for-devops-agent103—~6.6kAutomated safety check: PassApache-2.0

Similar skills

  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    DatabasesAuto-check: notes
  • AWS

    kid-sid/claude-spellbook

    A skill your agent uses when writing boto3 or AWS SDK v3 code — configuring IAM auth, reading/writing S3, designing DynamoDB access patterns, writing Lambda handlers, processing SQS batches, or…

    190 GitHub stars~4.9k tokensUpdated 2 mo ago
    DatabasesAuto-check: warnings
  • AWS Cloud Patterns

    rohitg00/awesome-claude-code-toolkit

    AWS cloud patterns for Lambda, ECS, S3, DynamoDB, and Infrastructure as Code with CDK/Terraform

    2.7k GitHub stars~1.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Amplify Workflow

    awslabs/agent-plugins

    Official

    Build and deploy full-stack web and mobile apps with AWS Amplify Gen2 (TypeScript code-first).

    916 GitHub stars~3.2k tokensUpdated yesterday
    MobileAuto-check passed
  • Msk Operations

    aws/tools-for-devops-agent

    Official

    Amazon MSK Provisioned operations, troubleshooting, and health assessment for Standard and Express brokers.

    103 GitHub stars~6.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Investigation Cost Guardrail

    aws/tools-for-devops-agent

    Official

    Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools.

    103 GitHub stars~4.5k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated yesterday
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Configuring Vpc Endpoints For Private AWS Service Access

What does Configuring Vpc Endpoints For Private AWS Service Access do?

Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink. Configuring Vpc Endpoints For Private AWS Service Access is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink.

When should I use Configuring Vpc Endpoints For Private AWS Service Access?

Configuring Vpc Endpoints For Private AWS Service Access fits situations like: setting up secure private connectivity to S3; other AWS services without internet gateway; public IP addresses.

How do I install Configuring Vpc Endpoints For Private AWS Service Access in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill configuring-vpc-endpoints-for-private-aws-service-access -a claude-code`. Or copy the skill folder (skills/specialized-skills/networking-and-content-delivery-skills/configuring-vpc-endpoints-for-private-aws-service-access in aws/agent-toolkit-for-aws) into .claude/skills/configuring-vpc-endpoints-for-private-aws-service-access in your project. Claude Code loads it when a task matches its description.

How do I install Configuring Vpc Endpoints For Private AWS Service Access in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill configuring-vpc-endpoints-for-private-aws-service-access -a codex`. Or copy the skill folder (skills/specialized-skills/networking-and-content-delivery-skills/configuring-vpc-endpoints-for-private-aws-service-access in aws/agent-toolkit-for-aws) into .agents/skills/configuring-vpc-endpoints-for-private-aws-service-access in your project. Codex loads it when a task matches its description.

Can I use Configuring Vpc Endpoints For Private AWS Service Access in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill configuring-vpc-endpoints-for-private-aws-service-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuring-vpc-endpoints-for-private-aws-service-access, .gemini/skills/configuring-vpc-endpoints-for-private-aws-service-access, .github/skills/configuring-vpc-endpoints-for-private-aws-service-access and .opencode/skills/configuring-vpc-endpoints-for-private-aws-service-access in your project.

What does Configuring Vpc Endpoints For Private AWS Service Access need to run?

SKILL.md names no scripts, command-line tools or credentials: Configuring Vpc Endpoints For Private AWS Service Access is instructions for the agent only.

Does Configuring Vpc Endpoints For Private AWS Service Access access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuring Vpc Endpoints For Private AWS Service Access safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuring Vpc Endpoints For Private AWS Service Access use?

Configuring Vpc Endpoints For Private AWS Service Access is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuring Vpc Endpoints For Private AWS Service Access use?

About 396 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Configuring Vpc Endpoints For Private AWS Service Access?

Skills that share tags, products or a category with Configuring Vpc Endpoints For Private AWS Service Access: AWS CLI Beast (giuseppe-trisciuoglio/developer-kit, 357 stars), AWS (kid-sid/claude-spellbook, 190 stars), AWS Cloud Patterns (rohitg00/awesome-claude-code-toolkit, 2.7k stars) and Amplify Workflow (awslabs/agent-plugins, 916 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuring Vpc Endpoints For Private AWS Service Access?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,835 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 9, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.