Official agent skill

Directconnect

by aws in aws/agent-toolkit-for-aws

Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private, public, and transit virtual interfaces…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Directconnect

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill directconnect -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws directconnect --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/networking-and-content-delivery-skills/directconnect .claude/skills/directconnect && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
directconnect
GitHub stars
2.8k
Token cost
~2.3k tokens
SKILL.md length
1,023 words
Files
9 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private, public, and transit virtual interfaces…

  • The user wants a private
  • SKILL.md covers Overview, Which Direct Connect task do…, Routing notes and Security Considerations, plus 1 more section
  • Calls aws
  • Consistent network link between a data center and AWS

What it does

Directconnect is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private, public, and transit virtual interfaces and bringing up BGP; reaching many VPCs through a Direct Connect gateway including cross-account transit gateway associations; encrypting traffic with MACsec or a private IP Site-to-Site VPN; making the connection resilient and tuning failover; managing link aggregation groups; SiteLink; and migrating from a virtual…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/choosing-a-direct-connect-connection-type.md`, `references/connecting-many-vpcs-through-a-direct-connect-gateway.md` and `references/creating-a-direct-connect-virtual-interface-and-configuring-bgp.md`).

It sits in DevOps & Cloud, covering Backup and disaster recovery. It works with Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • The user wants a private
  • Consistent network link between a data center and AWS
  • Operates an existing Direct Connect setup and needs to extend
  • Transit gateway route tables and attachments (transitgateway skill)

Example prompts

  • “Use the directconnect skill to configure AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and…”
  • “/directconnect”

What it can do on your machine

Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Directconnect loads about 2.3k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 247 tokens; SKILL.md has 1,023 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~247
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 1,023 words, ~2,290 tokens.

Download SKILL.mdSave it as .claude/skills/directconnect/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
directconnect
description
Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private, public, and transit virtual interfaces and bringing up BGP; reaching many VPCs through a Direct Connect gateway including cross-account transit gateway associations; encrypting traffic with MACsec or a private IP Site-to-Site VPN; making the connection resilient and tuning failover; managing link aggregation groups; SiteLink; and migrating from a virtual private gateway to a transit gateway. Use when the user wants a private, consistent network link between a data center and AWS, or operates an existing Direct Connect setup and needs to extend, encrypt, or harden it. Routes to the right per-task procedure in references. Do NOT use for transit gateway route tables and attachments (transitgateway skill), Site-to-Site VPN without Direct Connect (sitetositevpn skill), or Route 53 DNS routing (route53 skill).
version
1

AWS Direct Connect

Overview

Domain expertise for configuring AWS Direct Connect, the service that gives a customer a private, consistent network link between their own data center or colocation and AWS instead of routing over the public internet. Covers choosing a connection model and completing the cross connect, creating virtual interfaces and bringing up Border Gateway Protocol (BGP), reaching many VPCs through a Direct Connect gateway, encrypting traffic in transit, making the connection resilient, managing link aggregation groups, SiteLink, and migrating from a virtual private gateway to a transit gateway.

This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting, then follow its constraints and steps. The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to the AWS CLI otherwise. The Direct Connect console is regional, so pass the customer's working --region on aws directconnect commands; a Direct Connect gateway is a global resource but is reached through a regional console view.

Which Direct Connect task do you need?

GoalReference
Choose dedicated vs hosted vs a link aggregation group, then complete the cross connectchoosing a Direct Connect connection type
Create a private, public, or transit virtual interface and bring up BGPcreating a virtual interface and configuring BGP
Reach many VPCs over one connection through a Direct Connect gatewayconnecting many VPCs through a Direct Connect gateway
Encrypt traffic in transit with MACsec or a private IP Site-to-Site VPNencrypting traffic over Direct Connect
Make the connection survive a failure and tune failover speedmaking a Direct Connect connection resilient
Bundle connections into one logical link and manage membersmanaging link aggregation groups
Connect on-premises sites to each other over the AWS backbonesetting up SiteLink
Move from a virtual private gateway to a transit gateway without dropping trafficmigrating from a virtual private gateway to a transit gateway

Routing notes

  • Connection model comes first. The choosing-a-connection-type reference is the entry point for a customer with no link yet. It settles dedicated vs hosted vs a link aggregation group, checks location support for the chosen speed, and separates a hosted connection from a hosted virtual interface, a distinction customers confuse constantly. Run it before any cross connect is ordered, since port speed cannot change after the connection is created.
  • A connection carries no traffic until a virtual interface exists. After the cross connect is live, the creating-a-virtual-interface reference is the required next step. The virtual interface type (private, public, or transit) decides what the connection can reach and is fixed at creation. The jumbo-frame maximum transmission unit (MTU) should be set at creation but, on a private or transit virtual interface, can be changed later with a brief connectivity disruption.
  • One VPC vs many VPCs. A single VPC in one Region can be reached over a private virtual interface to a virtual private gateway. Reaching many VPCs, crossing accounts, or crossing Regions is the Direct Connect gateway reference, which also owns the cross-account transit gateway proposal-and-acceptance handshake.
  • Encryption is a separate, deliberate step. Direct Connect is not encrypted in transit by default. The encrypting-traffic reference compares MACsec (Layer 2, over the cross connect) against a private IP Site-to-Site VPN over a transit virtual interface (the recommended IPsec path). Route here whenever the customer mentions regulated data or encryption.
  • Resiliency model vs failover speed are two different questions. The resiliency reference covers both: the Resiliency Toolkit sets the topology and service level target, while BGP hold-timer tuning and Bidirectional Forwarding Detection (BFD) set how fast failover actually converges.
  • Link aggregation group as a model vs as ongoing management. The connection-type reference introduces the link aggregation group as a model choice at order time. The managing-link-aggregation-groups reference owns ongoing member add/remove and minimum-links behavior, where removing a member can take the whole group down.
  • Migration is order-dependent. The virtual-private-gateway-to-transit-gateway migration reference exists because doing the cutover steps out of order drops production traffic. Route any "we outgrew the single-VPC model" request here rather than to the plain Direct Connect gateway reference.
Show full SKILL.md (327 more words)Show less

Security Considerations

Direct Connect provides a private link into VPC resources, so the security posture differs from the public internet path. Carry these into every task:

  • Not encrypted by default. Direct Connect does not encrypt traffic in transit. You MUST treat encryption as a separate, deliberate step (MACsec or a private IP Site-to-Site VPN) before regulated or sensitive data crosses the link. See the encrypting-traffic reference.
  • Physical and colocation security. The link terminates on customer equipment at a Direct Connect location or partner colocation. You SHOULD remind the customer that physical access control and partner trust at that facility are part of the connection's security boundary.
  • Monitoring and alerting. You SHOULD recommend CloudWatch alarms on connection state and virtual interface BGP status so connection-state changes and failures trigger alerts rather than relying on manual detection.
  • Audit logging. You SHOULD confirm CloudTrail is enabled and logging directconnect API calls (connection, virtual interface, and gateway-association changes) so all configuration changes are captured for audit and compliance.
  • CloudWatch Logs encryption. You SHOULD encrypt CloudWatch Logs log groups that receive Direct Connect-related logs or alarm state data with a KMS key, so sensitive connection metadata is protected at rest.
  • Least-privilege IAM. You MUST scope IAM permissions for directconnect API actions to the specific actions and resources each principal needs, and prefer ephemeral IAM credentials over long-lived IAM user access keys. You MUST NOT grant directconnect:* on resource * or attach any *FullAccess managed policy; instead scope actions to specific resource ARNs, e.g. arn:aws:directconnect:*:*:dxcon/{connection_id} for a connection, so a compromised principal cannot touch every Direct Connect resource in the account.
  • Route leaks between VPCs. You SHOULD warn that advertising a supernet that overlaps VPC CIDRs can cause unintended VPC-to-VPC traffic over a shared Direct Connect gateway; mitigate with specific prefixes, separate gateways, or transit gateway blackhole routes.

Additional Resources

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in skills/specialized-skills/networking-and-content-delivery-skills/directconnect of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/choosing-a-direct-connect-connection-type.md
  • references/connecting-many-vpcs-through-a-direct-connect-gateway.md
  • references/creating-a-direct-connect-virtual-interface-and-configuring-bgp.md
  • references/encrypting-traffic-over-direct-connect.md
  • references/making-a-direct-connect-connection-resilient.md
  • references/managing-direct-connect-link-aggregation-groups.md
  • references/migrating-direct-connect-from-a-virtual-private-gateway-to-a-transit-gateway.md
  • references/setting-up-direct-connect-sitelink.md

Open the folder on GitHubat commit 188af2f

Compare with similar skills

Directconnect next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Directconnect compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Directconnect this skillaws/agent-toolkit-for-aws2.8k—~2.3kAutomated safety check: PassApache-2.0
Cloud ArchitectJeffallan/claude-skills12k—~1.9kAutomated safety check: PassMIT
Rds Operation Reviewaws/tools-for-devops-agent100—~4.8kAutomated safety check: PassApache-2.0
AWS Rdssickn33/agentic-awesome-skills47k2 repos~3.3kAutomated safety check: PassMIT
Storage S3 Resiliency Expertiseaws/tools-for-devops-agent100—~2.8kAutomated safety check: PassApache-2.0
Rdsitsmostafa/aws-agent-skills1.2k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Cloud Architect

    Jeffallan/claude-skills

    Designs cloud architectures, migration plans, cost optimization recommendations and disaster recovery strategies across AWS, Azure and GCP.

    12k GitHub stars~1.9k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    100 GitHub stars~4.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Rds

    sickn33/agentic-awesome-skills

    Provision and manage RDS databases. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.3k tokens
    DevOps & CloudAuto-check passed
  • Storage S3 Resiliency Expertise

    aws/tools-for-devops-agent

    Official

    S3 resiliency, security, and data protection review. An agent skill from aws/tools-for-devops-agent.

    100 GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Rds

    itsmostafa/aws-agent-skills

    AWS RDS relational database service for managed databases. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~2.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Frappe Ops Backup

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when configuring backups, restoring sites, encrypting backup files, scheduling automated backups, or planning disaster recovery.

    187 GitHub stars~2.9k tokensUpdated 20 days ago
    DevOps & CloudAuto-check: notes

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Categories

Questions about Directconnect

What does Directconnect do?

Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private, public, and transit virtual interfaces…. Directconnect is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization.

When should I use Directconnect?

Directconnect fits situations like: the user wants a private; consistent network link between a data center and AWS; operates an existing Direct Connect setup and needs to extend; transit gateway route tables and attachments (transitgateway skill).

How do I install Directconnect in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill directconnect -a claude-code`. Or copy the skill folder (skills/specialized-skills/networking-and-content-delivery-skills/directconnect in aws/agent-toolkit-for-aws) into .claude/skills/directconnect in your project. Claude Code loads it when a task matches its description.

How do I install Directconnect in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill directconnect -a codex`. Or copy the skill folder (skills/specialized-skills/networking-and-content-delivery-skills/directconnect in aws/agent-toolkit-for-aws) into .agents/skills/directconnect in your project. Codex loads it when a task matches its description.

Can I use Directconnect in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill directconnect -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/directconnect, .gemini/skills/directconnect, .github/skills/directconnect and .opencode/skills/directconnect in your project.

What does Directconnect need to run?

Going by SKILL.md and its folder, Directconnect needs the command-line tools its instructions call (aws).

Does Directconnect access the network?

SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and aws.amazon.com. This is read from the text; nothing was executed.

Is Directconnect safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Directconnect use?

Directconnect is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Directconnect use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.

What are the alternatives to Directconnect?

Skills that share tags, products or a category with Directconnect: Cloud Architect (Jeffallan/claude-skills, 12k stars), Rds Operation Review (aws/tools-for-devops-agent, 100 stars), AWS Rds (sickn33/agentic-awesome-skills, 47k stars) and Storage S3 Resiliency Expertise (aws/tools-for-devops-agent, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Directconnect?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.