AWS Cost Operations
Microck/ordinary-claude-skills
This skill provides AWS cost optimization, monitoring, and operational best practices with integrated MCP servers for billing analysis, cost estimation, observability, and security assessment.
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
$ npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent ecs-operation-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ecs-operation-review .claude/skills/ecs-operation-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ecs-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/ecs-operation-review into .claude/skills/ecs-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ecs-operation-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/ecs-operation-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent ecs-operation-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ecs-operation-review .agents/skills/ecs-operation-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ecs-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/ecs-operation-review into .agents/skills/ecs-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ecs-operation-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent ecs-operation-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ecs-operation-review .cursor/skills/ecs-operation-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ecs-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/ecs-operation-review into .cursor/skills/ecs-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ecs-operation-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/ecs-operation-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent ecs-operation-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ecs-operation-review .gemini/skills/ecs-operation-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ecs-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/ecs-operation-review into .gemini/skills/ecs-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ecs-operation-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent ecs-operation-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ecs-operation-review .github/skills/ecs-operation-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ecs-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/ecs-operation-review into .github/skills/ecs-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ecs-operation-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent ecs-operation-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ecs-operation-review .opencode/skills/ecs-operation-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ecs-operation-review" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/ecs-operation-review into .opencode/skills/ecs-operation-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ecs-operation-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ecs-operation-reviewPerforms a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
Ecs Operation Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs, with a 7-day CloudWatch metrics baseline, recommended alarm thresholds for IDR onboarding, per-pillar PASS/FAIL/N/A scorecards, and a prioritized, remediation-linked report artifact. Triggers on: "ECS operations review", "ECS assessment", "ECS review", "review my ECS service", "ECS reliability review", "ECS security…
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).
It sits in Security, covering Security review, Security operations and Observability. It works with Amazon Web Services and Model Context Protocol. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ecs Operation Review loads about 4.8k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 153 tokens; SKILL.md has 1,884 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,884 words, ~4,819 tokens.
.claude/skills/ecs-operation-review/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.Execute a comprehensive Amazon ECS operations review across the 6 review pillars with ✓/✗/N/A observations, 7-day CloudWatch baseline metrics, and alarm threshold recommendations for IDR onboarding.
review-common baseline (tagging, encryption, IAM least-privilege, alarms, logging, cost) via existing ECS check IDs. Read for any full review / CWR.Do NOT read all 6 pillar files at once. Read references/checks.md (the index) first, then read each references/pillars/<pillar>.md file ONE AT A TIME as you run that pillar's checks. Agent may add checks beyond the baseline using the next sequential ID in the pillar.
<required> Assessment WorkflowThis skill is self-contained — the procedural workflow is embedded below (this copy lives in aws-operations-review and does not depend on any external agent-sops/ SOP). Execute the steps in order; this skill's references/ files supply the check definitions and alarm thresholds.
arn:aws*:ecs:*:*:service/*/*); extract cluster name and service name. Halt if the ARN region does not match the region parameter.ecs.describeServices) MUST succeed before any other call. Save each response verbatim to the scratchpad. On non-Tier-1 access/API errors, mark dependent checks N/A and continue.launchType + capacityProviderStrategy + ecs.describeCapacityProviders: Fargate (FARGATE/FARGATE_SPOT), EC2 ASG capacity provider (autoScalingGroupProvider), Managed Instances (managedInstancesProvider), launchType-only EC2/Fargate (no strategy), or ECS Anywhere (EXTERNAL). Mixed strategies are valid — record every platform present. This decision drives check applicability in every pillar (full rules in references/checks.md). Record the platform in the report header.references/checks.md (the index) first, then for EACH pillar read its references/pillars/<pillar>.md file one at a time and apply its checks against the collected data, recording ✓ / ✗ / N/A with an observation. Use the exact check IDs and severities; mark platform-specific checks N/A where they don't apply (per the resolved compute platform). May add checks beyond the baseline.references/report-format.md exactly (Workload Details, per-pillar ✓/✗/N/A scorecards for all 6 pillars, Prioritized Action Plan, Detailed Findings, Recommended CloudWatch Alarms from references/alarm-thresholds.md, Access Limitations, Review Summary). Before finalizing, run the report-format Coverage gate — every check ID across all 6 pillars must appear in a scorecard as ✓/✗/N/A (including passes; no pillar dropped or truncated), the alarms table must be present, every ✗ needs a detailed finding block, and the shared review-common baseline must be accounted for per references/common-checks-coverage.md (all eight common checks covered via their ECS equivalents or ⚪ N/A with a reason). Default to a Markdown artifact; render DOCX only if asked (build from the same content). Strip internal check IDs from the customer-facing report. Return the Review Summary with verified counts, then delete the scratchpad.Review Pillars:
All calls below are public AWS API operations. Use read-only (describe/list/get) operations only, via the AWS CLI, an AWS SDK (e.g. boto3), or an AWS API MCP with least-privilege read-only credentials.
| API | Tier | Purpose |
|---|---|---|
| ecs.describeServices | 1 | Foundation — service config, task def, LB, deployment, network |
| ecs.describeTaskDefinition | 2 | Container defs, CPU/memory, roles, log config, network mode |
| ecs.describeClusters | 2 | Cluster settings, Container Insights, capacity providers, Exec logging config (include=["CONFIGURATIONS"] for OPS9) |
| ecs.listTasks | 2 | Running task ARNs for the service |
| ecs.describeTasks | 3 | Task health, AZ spread, connectivity status |
| ecs.listContainerInstances | 2 | Container instance ARNs for EC2 launch type clusters |
| ecs.describeContainerInstances | 3 | Agent version, AMI ID, instance status (EC2 only) |
| ecs.describeCapacityProviders | 2 | Compute platform classification (ASG vs Managed Instances vs Fargate), managed termination protection (REL12), managed scaling status/targetCapacity (PERF9), MI network config (REL14) |
| API | Tier | Purpose |
|---|---|---|
| applicationautoscaling.describeScalingPolicies | 2 | Auto scaling policies for the service |
| applicationautoscaling.describeScalableTargets | 2 | Min/max capacity configuration |
| API | Tier | Purpose |
|---|---|---|
| alb.describeTargetHealth | 2 | Target health for service tasks behind ALB/NLB (skip if no LB configured) |
| alb.describeTargetGroups | 2 | Target group details including LoadBalancerArns — used to determine LB type (ALB vs NLB) by ARN path segment: /app/ = ALB, /net/ = NLB, for correct alarm recommendations (skip if no LB configured) |
| elbv2.describeListeners | 2 | Listener protocol/port for the LB fronting the service — HTTPS/TLS vs plaintext HTTP/TCP for encryption-in-transit (SEC20); uses LoadBalancerArns from describeTargetGroups (skip if no LB configured) |
| API | Tier | Purpose |
|---|---|---|
| iam.listAttachedRolePolicies | 4a | Managed policies on execution/task roles |
| iam.listRolePolicies | 4a | Inline policy names on execution/task roles |
| iam.getRolePolicy | 4b | Inline policy document for execution/task roles |
| API | Tier | Purpose |
|---|---|---|
| ecr.describeRepositories | 3 | Image scanning config, tag immutability for container image repos |
| API | Tier | Purpose |
|---|---|---|
| ec2.describeSecurityGroups | 2 | Security group rules for service ENIs (awsvpc mode) |
| ec2.describeSubnets | 2 | Subnet AZ distribution for service network config |
| ec2.describeVpcEndpoints | 3 | VPC endpoints for ECR, CloudWatch Logs, Secrets Manager (uses VPC ID from describeSubnets) |
| ec2.describeRouteTables | 3 | Route table entries for NAT/internet access assessment |
| ec2.describeNatGateways | 3 | NAT Gateway availability for private subnets |
| ec2.describeImages | 4 | AMI creation date for container instance AMI currency check (EC2 only, uses imageId from describeContainerInstances) |
| ec2.describeVolumes | 3 | EBS volume encryption status for task-attached / container-instance volumes (SEC17) |
| ec2.describeFlowLogs | 3 | VPC Flow Logs enablement for the service VPC (SEC18, uses VPC ID from describeSubnets) |
| API | Tier | Purpose |
|---|---|---|
| cloudwatch.describeAlarms | 2 | Existing alarms for ECS service |
| cloudwatch.getMetricStatistics | 5 | 7-day baseline: CPU, memory, task count; plus CapacityProviderReservation (AWS/ECS/ManagedScaling) for EC2 ASG capacity providers (PERF10) |
| API | Tier | Purpose |
|---|---|---|
| logs.describeLogGroups | 3 | Log retention setting and Logs Insights query targeting for the awslogs group (OBS8, ADD6 — uses awslogs-group from task definition) |
| API | Tier | Purpose |
|---|---|---|
| guardduty.listDetectors | 2 | Detector presence in region (SEC19) |
| guardduty.getDetector | 2 | Runtime Monitoring feature status for ECS (SEC19 — uses detector ID from listDetectors) |
| API | Tier | Purpose |
|---|---|---|
| computeoptimizer.getECSServiceRecommendations | 2 | ECS service task CPU/memory rightsizing recommendations (PERF8) |
| Tool | Purpose |
|---|---|
| aws___search_documentation | Search across all AWS documentation with optional topic-based filtering |
| aws___read_documentation | Retrieve and convert AWS documentation pages to markdown |
| aws___recommend | Get content recommendations for AWS documentation pages |
| aws___list_regions | Retrieve a list of all AWS regions |
| aws___get_regional_availability | Retrieve AWS regional availability information |
Tier 1: ecs.describeServices (FOUNDATION — must complete first)
├─ extracts: taskDefinition ARN, clusterArn, loadBalancers,
│ desiredCount, launchType, networkConfiguration, tags
│
├─► Tier 2 (parallel): ecs.describeTaskDefinition, ecs.describeClusters,
│ ecs.listTasks, cloudwatch.describeAlarms,
│ applicationautoscaling.describeScalingPolicies,
│ applicationautoscaling.describeScalableTargets,
│ ecs.describeCapacityProviders (compute platform classification;
│ ASG providers — REL12/PERF9; Managed Instances providers — REL14),
│ guardduty.listDetectors ─► guardduty.getDetector (SEC19),
│ computeoptimizer.getECSServiceRecommendations (PERF8),
│ alb.describeTargetHealth (if LB configured),
│ alb.describeTargetGroups (if LB configured — resolves ALB vs NLB type from LoadBalancerArns: /app/ = ALB, /net/ = NLB; also deregistration delay for REL13),
│ elbv2.describeListeners (if LB configured — listener protocol for encryption-in-transit SEC20),
│ ec2.describeSecurityGroups (from networkConfiguration.securityGroups),
│ ec2.describeSubnets (from networkConfiguration.subnets),
│ ecs.listContainerInstances (EC2 launch type only)
│ │
│ ├─► Tier 3: ecs.describeTasks (using task ARNs from listTasks)
│ │ ecs.describeContainerInstances (EC2 only, using instance ARNs from listContainerInstances)
│ │ ecr.describeRepositories (using repo name from task definition image URI)
│ │ ec2.describeVpcEndpoints (using VPC ID from describeSubnets)
│ │ ec2.describeRouteTables (using subnet IDs from describeSubnets)
│ │ ec2.describeNatGateways (using VPC ID from describeSubnets)
│ │ ec2.describeFlowLogs (using VPC ID from describeSubnets — SEC18)
│ │ ec2.describeVolumes (task-attached / container-instance EBS encryption — SEC17)
│ │ logs.describeLogGroups (using awslogs-group from task definition — OBS8, ADD6)
│ │
│ ├─► Tier 4 (EC2 only): ec2.describeImages (using imageId from describeContainerInstances)
│ │
│ └─► Tier 4a (parallel): iam.listAttachedRolePolicies (execution + task role),
│ iam.listRolePolicies (execution + task role)
│ │
│ └─► Tier 4b: iam.getRolePolicy (execution + task role)
│ (uses policy names from listRolePolicies)
│
└─► Tier 5 (per-metric loop): cloudwatch.getMetricStatisticsWhen AWS API calls return access denied or authorization errors:
<good> Example OutputThe agent produces a per-service review artifact (Markdown by default; DOCX if asked) containing: service configuration summary, all 6 review pillar scorecards (✓/✗/N/A with observations, every check including passes), 7-day baseline metrics, the recommended-alarms table with clickable doc links, and priority action items. A Review Summary with verified counts is returned to the orchestrator.
<bad> What Not to Doaws___search_documentation) to supplement the doc links provided in checks.mddoc_url column from references/alarm-thresholds.md as the canonical link targetecs.describeServices fails after retries: HALT workflow — delete {{scratchpad_dir}}/ and return error to orchestratorpython-docx, retry with --user on install failure) when a DOCX deliverable was explicitly requested{{output_directory}}/ (Markdown by default; DOCX only if requested){{scratchpad_dir}}/ deleted after report verified© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 17 other files (references) in skills/ecs-operation-review of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
Ecs Operation Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ecs Operation Review this skillaws/tools-for-devops-agent | 102 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| AWS Cost OperationsMicrock/ordinary-claude-skills | 404 | 1 repos | ~2.5k | Automated safety check: Pass | Custom licence | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Tool Defs Analysiscyanheads/pubmed-mcp-server | 156 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| AWS Cost Operationszxkane/aws-skills | 367 | — | ~2.4k | Automated safety check: Pass | MIT | |
| AWS Agentic AIsickn33/agentic-awesome-skills | 47k | 1 repos | ~3.2k | Automated safety check: Pass | MIT |
Microck/ordinary-claude-skills
This skill provides AWS cost optimization, monitoring, and operational best practices with integrated MCP servers for billing analysis, cost estimation, observability, and security assessment.
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
cyanheads/pubmed-mcp-server
Read-only audit of MCP definition language across an existing surface — tools, resources, prompts, server instructions.
zxkane/aws-skills
AWS cost optimization, monitoring, and operational excellence expert.
sickn33/agentic-awesome-skills
AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.
aws-samples/appmod-blueprints
Run a live EKS cluster cost efficiency assessment — analyze spending across 6 dimensions (compute efficiency, Spot/Graviton adoption, networking, storage, observability, idle resources), calculate a…
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
aws/tools-for-devops-agent
Use this skill during any incident investigation, capacity planning, or operational troubleshooting when the issue may be caused by hitting AWS service limits.
Categories
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…. Ecs Operation Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs, with a 7-day CloudWatch metrics baseline, recommended alarm thresholds for IDR onboarding, per-pillar PASS/FAIL/N/A scorecards, and a prioritized, remediation-linked report artifact.
Ecs Operation Review fits situations like: : ECS operations review; review my ECS service; ECS reliability review; ECS security review.
Run `npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a claude-code`. Or copy the skill folder (skills/ecs-operation-review in aws/tools-for-devops-agent) into .claude/skills/ecs-operation-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a codex`. Or copy the skill folder (skills/ecs-operation-review in aws/tools-for-devops-agent) into .agents/skills/ecs-operation-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ecs-operation-review, .gemini/skills/ecs-operation-review, .github/skills/ecs-operation-review and .opencode/skills/ecs-operation-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Ecs Operation Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ecs Operation Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Ecs Operation Review: AWS Cost Operations (Microck/ordinary-claude-skills, 404 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Tool Defs Analysis (cyanheads/pubmed-mcp-server, 156 stars) and AWS Cost Operations (zxkane/aws-skills, 367 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 102 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.