Official agent skill

Ecs Operation Review

by aws in aws/tools-for-devops-agent

Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

OfficialApache-2.0Auto-check passedSecurity

Install Ecs Operation Review

skills CLI
$ npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/tools-for-devops-agent ecs-operation-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ecs-operation-review .claude/skills/ecs-operation-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ecs-operation-review
GitHub stars
102
Token cost
~4.8k tokens
SKILL.md length
1,884 words
Files
18 (incl. references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

  • Works in 6 steps: Setup — Create the output directory and… → Parse ARN — Validate the ECS service ARN… → Collect configuration data — Call the… → …
  • : ECS operations review
  • SKILL.md covers Overview, Usage, Core Concepts and Prerequisites, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ecs Operation Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs, with a 7-day CloudWatch metrics baseline, recommended alarm thresholds for IDR onboarding, per-pillar PASS/FAIL/N/A scorecards, and a prioritized, remediation-linked report artifact. Triggers on: "ECS operations review", "ECS assessment", "ECS review", "review my ECS service", "ECS reliability review", "ECS security…

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).

It sits in Security, covering Security review, Security operations and Observability. It works with Amazon Web Services and Model Context Protocol. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.

When your agent uses it

  • : ECS operations review
  • Review my ECS service
  • ECS reliability review
  • ECS security review

Example prompts

  • “ECS operations review”
  • “ECS assessment”
  • “ECS review”
  • “/ecs-operation-review”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Setup — Create the output directory and a scratchpad for raw API responses. Record account ID, region, and timestamp.
  2. Parse ARN — Validate the ECS service ARN (arn:aws*:ecs:*:*:service/*/*); extract cluster name and service name. Halt if the ARN region…
  3. Collect configuration data — Call the AWS APIs following the tier order in the API Tier Dependency Chain below. Tier 1…
  4. Resolve compute platform — Before grading any pillar, classify the service's compute platform from launchType + capacityProviderStrategy +…
  5. Run pillar checks — Read references/checks.md (the index) first, then for EACH pillar read its references/pillars/.md file one at a time…
  6. Generate report — Produce the per-service review artifact following references/report-format.md exactly (Workload Details, per-pillar…

What it can do on your machine

Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ecs Operation Review loads about 4.8k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 153 tokens; SKILL.md has 1,884 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~153
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,884 words, ~4,819 tokens.

Download SKILL.mdSave it as .claude/skills/ecs-operation-review/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.
name
ecs-operation-review
description
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs, with a 7-day CloudWatch metrics baseline, recommended alarm thresholds for IDR onboarding, per-pillar PASS/FAIL/N/A scorecards, and a prioritized, remediation-linked report artifact. Triggers on: "ECS operations review", "ECS assessment", "ECS review", "review my ECS service", "ECS reliability review", "ECS security review", "ECS best practices audit", "review ECS services for a workload".
metadata.author
shyamkulkarni
metadata.version
2.5.0
metadata.aws-devops-agent-skills.agent-t
Chat tasks, Evaluation
metadata.aws-devops-agent-skills.aws-ser
Amazon ECS

ECS Operations Review Skill

Overview

Execute a comprehensive Amazon ECS operations review across the 6 review pillars with ✓/✗/N/A observations, 7-day CloudWatch baseline metrics, and alarm threshold recommendations for IDR onboarding.

Usage

  • User mentions "ECS operations review", "ECS assessment", "ECS review"
  • User provides ECS service ARN(s) for operations review
  • User asks to review ECS services for a workload
  • User requests ECS reliability or security review
  • Delegated ECS service assessment from UOPS

Core Concepts

  • Review Pillars: Six assessment dimensions — Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis
  • ECS Service/Cluster: The primary resources assessed — includes tasks, services, and cluster configuration
  • AWS API: Public AWS service APIs used for all data collection, called read-only (describe/list/get) via the AWS CLI, an AWS SDK, or an AWS API MCP
  • Baseline Metrics: 7-day CloudWatch metric history used to establish normal operating patterns

Prerequisites

  • Read-only AWS API access (describe/list/get) for ECS, CloudWatch, IAM, Application Auto Scaling, ELB, ECR, EC2 APIs — via AWS CLI, an AWS SDK, or an AWS API MCP
  • AWS Knowledge MCP access (search_documentation, read_documentation, recommend, list_regions, get_regional_availability)
  • AWS account ID and region
  • CloudWatch metrics access (7-day minimum for baseline)
  • ECS service ARN — format: arn:aws*:ecs:::service//

Skill Files

  • references/checks.md — Checks index: pillar→file map, check-ID ranges, counts, and the access-limitation / minimum-baseline rules. Read this FIRST.
  • references/pillars/resiliency.md — Resiliency & HA checks (REL1-REL14). Read only when running the Resiliency pillar.
  • references/pillars/observability.md — Observability checks (OBS1-OBS9). Read only when running the Observability pillar.
  • references/pillars/security.md — Security checks (SEC1-SEC20). Read only when running the Security pillar.
  • references/pillars/operations.md — Operations checks (OPS1-OPS9). Read only when running the Operations pillar.
  • references/pillars/performance.md — Performance checks (PERF1-PERF11). Read only when running the Performance pillar.
  • references/pillars/additional-analysis.md — Additional Analysis checks (ADD1-ADD7). Read only when running the Additional pillar.
  • references/alarm-thresholds.md — Recommended CloudWatch alarm thresholds for IDR onboarding.
  • references/common-checks-coverage.md — Crosswalk proving the review covers the shared review-common baseline (tagging, encryption, IAM least-privilege, alarms, logging, cost) via existing ECS check IDs. Read for any full review / CWR.
  • references/report-format.md — Required report/artifact structure, severity model, finding-block format, and the coverage gate. Read before generating the report.
Context Management for Checks

Do NOT read all 6 pillar files at once. Read references/checks.md (the index) first, then read each references/pillars/<pillar>.md file ONE AT A TIME as you run that pillar's checks. Agent may add checks beyond the baseline using the next sequential ID in the pillar.

<required> Assessment Workflow

This skill is self-contained — the procedural workflow is embedded below (this copy lives in aws-operations-review and does not depend on any external agent-sops/ SOP). Execute the steps in order; this skill's references/ files supply the check definitions and alarm thresholds.

  1. Setup — Create the output directory and a scratchpad for raw API responses. Record account ID, region, and timestamp.
  2. Parse ARN — Validate the ECS service ARN (arn:aws*:ecs:*:*:service/*/*); extract cluster name and service name. Halt if the ARN region does not match the region parameter.
  3. Collect configuration data — Call the AWS APIs following the tier order in the API Tier Dependency Chain below. Tier 1 (ecs.describeServices) MUST succeed before any other call. Save each response verbatim to the scratchpad. On non-Tier-1 access/API errors, mark dependent checks N/A and continue.
  4. Resolve compute platform — Before grading any pillar, classify the service's compute platform from launchType + capacityProviderStrategy + ecs.describeCapacityProviders: Fargate (FARGATE/FARGATE_SPOT), EC2 ASG capacity provider (autoScalingGroupProvider), Managed Instances (managedInstancesProvider), launchType-only EC2/Fargate (no strategy), or ECS Anywhere (EXTERNAL). Mixed strategies are valid — record every platform present. This decision drives check applicability in every pillar (full rules in references/checks.md). Record the platform in the report header.
  5. Run pillar checks — Read references/checks.md (the index) first, then for EACH pillar read its references/pillars/<pillar>.md file one at a time and apply its checks against the collected data, recording ✓ / ✗ / N/A with an observation. Use the exact check IDs and severities; mark platform-specific checks N/A where they don't apply (per the resolved compute platform). May add checks beyond the baseline.
  6. Generate report — Produce the per-service review artifact following references/report-format.md exactly (Workload Details, per-pillar ✓/✗/N/A scorecards for all 6 pillars, Prioritized Action Plan, Detailed Findings, Recommended CloudWatch Alarms from references/alarm-thresholds.md, Access Limitations, Review Summary). Before finalizing, run the report-format Coverage gate — every check ID across all 6 pillars must appear in a scorecard as ✓/✗/N/A (including passes; no pillar dropped or truncated), the alarms table must be present, every ✗ needs a detailed finding block, and the shared review-common baseline must be accounted for per references/common-checks-coverage.md (all eight common checks covered via their ECS equivalents or ⚪ N/A with a reason). Default to a Markdown artifact; render DOCX only if asked (build from the same content). Strip internal check IDs from the customer-facing report. Return the Review Summary with verified counts, then delete the scratchpad.

Review Pillars:

  • Resiliency and High Availability (REL1-REL14) — Multi-AZ, desired count, deployment config, circuit breaker, deployment alarms, health checks, subnet AZ spread, capacity-provider managed termination protection, target-group deregistration delay, capacity provider infrastructure multi-AZ
  • Observability (OBS1-OBS9) — Container Insights, CloudWatch alarms, logging, log retention, distributed tracing, metrics monitoring
  • Security (SEC1-SEC20) — IAM least privilege, network mode, secrets management, ECR image scanning, security groups, VPC endpoints, private connectivity, encryption at rest, encryption in transit (TLS), VPC Flow Logs, GuardDuty Runtime Monitoring
  • Operations (OPS1-OPS9) — Deployment controller, resource tagging, IaC-managed, platform version, ECS agent version, ECS Exec posture and session audit logging
  • Performance (PERF1-PERF11) — Auto scaling, CPU/memory rightsizing, capacity provider strategy, managed scaling / targetCapacity headroom, CapacityProviderReservation 7-day baseline analysis, base/weight strategy design, Compute Optimizer recommendations
  • Additional Analysis & Recommendations (ADD1-ADD7) — Graviton/ARM64, Fargate Spot, Service Connect, cost optimization, CloudWatch Logs Insights queries, ECS Managed Instances evaluation

AWS API Summary

All calls below are public AWS API operations. Use read-only (describe/list/get) operations only, via the AWS CLI, an AWS SDK (e.g. boto3), or an AWS API MCP with least-privilege read-only credentials.

ECS APIs (Tier 1, 2, 3)
APITierPurpose
ecs.describeServices1Foundation — service config, task def, LB, deployment, network
ecs.describeTaskDefinition2Container defs, CPU/memory, roles, log config, network mode
ecs.describeClusters2Cluster settings, Container Insights, capacity providers, Exec logging config (include=["CONFIGURATIONS"] for OPS9)
ecs.listTasks2Running task ARNs for the service
ecs.describeTasks3Task health, AZ spread, connectivity status
ecs.listContainerInstances2Container instance ARNs for EC2 launch type clusters
ecs.describeContainerInstances3Agent version, AMI ID, instance status (EC2 only)
ecs.describeCapacityProviders2Compute platform classification (ASG vs Managed Instances vs Fargate), managed termination protection (REL12), managed scaling status/targetCapacity (PERF9), MI network config (REL14)
Application Auto Scaling APIs (Tier 2)
APITierPurpose
applicationautoscaling.describeScalingPolicies2Auto scaling policies for the service
applicationautoscaling.describeScalableTargets2Min/max capacity configuration
ELB APIs (Tier 2)
APITierPurpose
alb.describeTargetHealth2Target health for service tasks behind ALB/NLB (skip if no LB configured)
alb.describeTargetGroups2Target group details including LoadBalancerArns — used to determine LB type (ALB vs NLB) by ARN path segment: /app/ = ALB, /net/ = NLB, for correct alarm recommendations (skip if no LB configured)
elbv2.describeListeners2Listener protocol/port for the LB fronting the service — HTTPS/TLS vs plaintext HTTP/TCP for encryption-in-transit (SEC20); uses LoadBalancerArns from describeTargetGroups (skip if no LB configured)
Show full SKILL.md (745 more words)Show less
IAM APIs (Tier 4a, 4b)
APITierPurpose
iam.listAttachedRolePolicies4aManaged policies on execution/task roles
iam.listRolePolicies4aInline policy names on execution/task roles
iam.getRolePolicy4bInline policy document for execution/task roles
ECR APIs (Tier 3)
APITierPurpose
ecr.describeRepositories3Image scanning config, tag immutability for container image repos
EC2/VPC APIs (Tier 2, 3, 4)
APITierPurpose
ec2.describeSecurityGroups2Security group rules for service ENIs (awsvpc mode)
ec2.describeSubnets2Subnet AZ distribution for service network config
ec2.describeVpcEndpoints3VPC endpoints for ECR, CloudWatch Logs, Secrets Manager (uses VPC ID from describeSubnets)
ec2.describeRouteTables3Route table entries for NAT/internet access assessment
ec2.describeNatGateways3NAT Gateway availability for private subnets
ec2.describeImages4AMI creation date for container instance AMI currency check (EC2 only, uses imageId from describeContainerInstances)
ec2.describeVolumes3EBS volume encryption status for task-attached / container-instance volumes (SEC17)
ec2.describeFlowLogs3VPC Flow Logs enablement for the service VPC (SEC18, uses VPC ID from describeSubnets)
CloudWatch APIs (Tier 2, 5)
APITierPurpose
cloudwatch.describeAlarms2Existing alarms for ECS service
cloudwatch.getMetricStatistics57-day baseline: CPU, memory, task count; plus CapacityProviderReservation (AWS/ECS/ManagedScaling) for EC2 ASG capacity providers (PERF10)
CloudWatch Logs APIs (Tier 3)
APITierPurpose
logs.describeLogGroups3Log retention setting and Logs Insights query targeting for the awslogs group (OBS8, ADD6 — uses awslogs-group from task definition)
GuardDuty APIs (Tier 2)
APITierPurpose
guardduty.listDetectors2Detector presence in region (SEC19)
guardduty.getDetector2Runtime Monitoring feature status for ECS (SEC19 — uses detector ID from listDetectors)
Compute Optimizer APIs (Tier 2)
APITierPurpose
computeoptimizer.getECSServiceRecommendations2ECS service task CPU/memory rightsizing recommendations (PERF8)
AWS Knowledge MCP
ToolPurpose
aws___search_documentationSearch across all AWS documentation with optional topic-based filtering
aws___read_documentationRetrieve and convert AWS documentation pages to markdown
aws___recommendGet content recommendations for AWS documentation pages
aws___list_regionsRetrieve a list of all AWS regions
aws___get_regional_availabilityRetrieve AWS regional availability information

API Tier Dependency Chain

Tier 1: ecs.describeServices (FOUNDATION — must complete first)
  ├─ extracts: taskDefinition ARN, clusterArn, loadBalancers,
  │            desiredCount, launchType, networkConfiguration, tags
  │
  ├─► Tier 2 (parallel): ecs.describeTaskDefinition, ecs.describeClusters,
  │     ecs.listTasks, cloudwatch.describeAlarms,
  │     applicationautoscaling.describeScalingPolicies,
  │     applicationautoscaling.describeScalableTargets,
  │     ecs.describeCapacityProviders (compute platform classification;
  │       ASG providers — REL12/PERF9; Managed Instances providers — REL14),
  │     guardduty.listDetectors ─► guardduty.getDetector (SEC19),
  │     computeoptimizer.getECSServiceRecommendations (PERF8),
  │     alb.describeTargetHealth (if LB configured),
  │     alb.describeTargetGroups (if LB configured — resolves ALB vs NLB type from LoadBalancerArns: /app/ = ALB, /net/ = NLB; also deregistration delay for REL13),
  │     elbv2.describeListeners (if LB configured — listener protocol for encryption-in-transit SEC20),
  │     ec2.describeSecurityGroups (from networkConfiguration.securityGroups),
  │     ec2.describeSubnets (from networkConfiguration.subnets),
  │     ecs.listContainerInstances (EC2 launch type only)
  │     │
  │     ├─► Tier 3: ecs.describeTasks (using task ARNs from listTasks)
  │     │            ecs.describeContainerInstances (EC2 only, using instance ARNs from listContainerInstances)
  │     │            ecr.describeRepositories (using repo name from task definition image URI)
  │     │            ec2.describeVpcEndpoints (using VPC ID from describeSubnets)
  │     │            ec2.describeRouteTables (using subnet IDs from describeSubnets)
  │     │            ec2.describeNatGateways (using VPC ID from describeSubnets)
  │     │            ec2.describeFlowLogs (using VPC ID from describeSubnets — SEC18)
  │     │            ec2.describeVolumes (task-attached / container-instance EBS encryption — SEC17)
  │     │            logs.describeLogGroups (using awslogs-group from task definition — OBS8, ADD6)
  │     │
  │     ├─► Tier 4 (EC2 only): ec2.describeImages (using imageId from describeContainerInstances)
  │     │
  │     └─► Tier 4a (parallel): iam.listAttachedRolePolicies (execution + task role),
  │           iam.listRolePolicies (execution + task role)
  │           │
  │           └─► Tier 4b: iam.getRolePolicy (execution + task role)
  │                 (uses policy names from listRolePolicies)
  │
  └─► Tier 5 (per-metric loop): cloudwatch.getMetricStatistics

Access Limitation Handling

When AWS API calls return access denied or authorization errors:

  • Mark dependent checks as N/A with observation: "Unable to assess — access denied on {{api_name}}. Manual verification recommended."
  • Include a dedicated Access Limitations section in the report listing all checks that could not be evaluated due to permissions
  • Continue with remaining assessable checks — do NOT halt the entire assessment for non-Tier-1 access errors
  • In the Review Summary, note how many checks could not be evaluated due to access limitations

<good> Example Output

The agent produces a per-service review artifact (Markdown by default; DOCX if asked) containing: service configuration summary, all 6 review pillar scorecards (✓/✗/N/A with observations, every check including passes), 7-day baseline metrics, the recommended-alarms table with clickable doc links, and priority action items. A Review Summary with verified counts is returned to the orchestrator.

<bad> What Not to Do

  • Don't skip any pillar — all 6 must be assessed
  • Don't use write or mutating API calls — this is a read-only assessment; use describe/list/get operations only
  • Don't hardcode doc URLs for ✗ check findings — use AWS Knowledge MCP (aws___search_documentation) to supplement the doc links provided in checks.md
  • Don't hardcode doc URLs for alarm recommendation hyperlinks — use the doc_url column from references/alarm-thresholds.md as the canonical link target
  • Don't skip alarm recommendations — this is a core IDR deliverable
  • Don't omit the metrics baseline section — if 7-day data is unavailable, note the limitation in the report rather than skipping it
  • Don't hallucinate findings — only report what AWS API data confirms
  • Don't silently skip checks when access is denied — always mark as N/A with explicit access limitation note

Failure Recovery

  • If ecs.describeServices fails after retries: HALT workflow — delete {{scratchpad_dir}}/ and return error to orchestrator
  • If Tier 2-5 APIs fail: mark dependent checks as N/A, continue assessment with available data
  • If report generation fails: default to the Markdown artifact (no external dependency); only fall back to DOCX (python-docx, retry with --user on install failure) when a DOCX deliverable was explicitly requested
  • If artifact write fails: capture the error, delete scratchpad, return error to orchestrator

Success Criteria

  • All 6 review pillars assessed with ✓/✗/N/A observations — coverage gate passed: every check ID across all 6 pillars appears in a scorecard (including passes), no pillar dropped or truncated
  • Review artifact generated at {{output_directory}}/ (Markdown by default; DOCX only if requested)
  • Recommended-alarms table populated from alarm-thresholds.md, marking exist-vs-missing
  • 7-day baseline metrics included (or limitation noted)
  • Every ✗ has a detailed finding block; every recommendation includes a resolvable AWS documentation link
  • Access limitations explicitly documented; unobtainable checks are N/A-with-reason, never omitted or guessed
  • Review Summary with verified counts returned to orchestrator
  • {{scratchpad_dir}}/ deleted after report verified

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 17 other files (references) in skills/ecs-operation-review of aws/tools-for-devops-agent.

  • SKILL.md
  • .skilleval.yaml
  • CHANGELOG.md
  • README.md
  • evals/TESTING.md
  • evals/eval_queries.json
  • evals/evals.json
  • evals/files/service-context.json
  • references/alarm-thresholds.md
  • references/checks.md
  • references/common-checks-coverage.md
  • references/pillars/additional-analysis.md
  • references/pillars/observability.md
  • references/pillars/operations.md
  • references/pillars/performance.md
  • references/pillars/resiliency.md
  • references/pillars/security.md
  • … and 1 more

Open the folder on GitHubat commit ddda70b

Compare with similar skills

Ecs Operation Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ecs Operation Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ecs Operation Review this skillaws/tools-for-devops-agent102—~4.8kAutomated safety check: PassApache-2.0
AWS Cost OperationsMicrock/ordinary-claude-skills4041 repos~2.5kAutomated safety check: PassCustom licence
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Tool Defs Analysiscyanheads/pubmed-mcp-server156—~4.8kAutomated safety check: PassApache-2.0
AWS Cost Operationszxkane/aws-skills367—~2.4kAutomated safety check: PassMIT
AWS Agentic AIsickn33/agentic-awesome-skills47k1 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • AWS Cost Operations

    Microck/ordinary-claude-skills

    This skill provides AWS cost optimization, monitoring, and operational best practices with integrated MCP servers for billing analysis, cost estimation, observability, and security assessment.

    404 GitHub starsUsed in 1 repo~2.5k tokens
    DevOps & CloudAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Tool Defs Analysis

    cyanheads/pubmed-mcp-server

    Read-only audit of MCP definition language across an existing surface — tools, resources, prompts, server instructions.

    156 GitHub stars~4.8k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • AWS Cost Operations

    zxkane/aws-skills

    AWS cost optimization, monitoring, and operational excellence expert.

    367 GitHub stars~2.4k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • AWS Agentic AI

    sickn33/agentic-awesome-skills

    AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.

    47k GitHub starsUsed in 1 repo~3.2k tokens
    DevOps & CloudAuto-check passed
  • Eks Cost Intelligence

    aws-samples/appmod-blueprints

    Official

    Run a live EKS cluster cost efficiency assessment — analyze spending across 6 dimensions (compute efficiency, Spot/Graviton adoption, networking, storage, observability, idle resources), calculate a…

    115 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings

More from aws/tools-for-devops-agent

All 31 skills in this repo
  • Aiml GPU Training Cluster Investigation

    aws/tools-for-devops-agent

    Official

    A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.

    102 GitHub stars~5.4k tokensUpdated 2 days ago
    Auto-check passed
  • AWS Health Events

    aws/tools-for-devops-agent

    Official

    ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

    102 GitHub stars~4.6k tokensUpdated 2 days ago
    Auto-check passed
  • Database Migration Service Expertise

    aws/tools-for-devops-agent

    Official

    AWS Database Migration Service (DMS) operational review and troubleshooting skill.

    102 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    102 GitHub stars~4.8k tokensUpdated 2 days ago
    Auto-check passed
  • Sagemaker AI Ops Review

    aws/tools-for-devops-agent

    Official

    Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.

    102 GitHub stars~3.9k tokensUpdated 2 days ago
    Auto-check passed
  • Service Quota Check

    aws/tools-for-devops-agent

    Official

    Use this skill during any incident investigation, capacity planning, or operational troubleshooting when the issue may be caused by hitting AWS service limits.

    102 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed

Questions about Ecs Operation Review

What does Ecs Operation Review do?

Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…. Ecs Operation Review is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs, with a 7-day CloudWatch metrics baseline, recommended alarm thresholds for IDR onboarding, per-pillar PASS/FAIL/N/A scorecards, and a prioritized, remediation-linked report artifact.

When should I use Ecs Operation Review?

Ecs Operation Review fits situations like: : ECS operations review; review my ECS service; ECS reliability review; ECS security review.

How do I install Ecs Operation Review in Claude Code?

Run `npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a claude-code`. Or copy the skill folder (skills/ecs-operation-review in aws/tools-for-devops-agent) into .claude/skills/ecs-operation-review in your project. Claude Code loads it when a task matches its description.

How do I install Ecs Operation Review in Codex?

Run `npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a codex`. Or copy the skill folder (skills/ecs-operation-review in aws/tools-for-devops-agent) into .agents/skills/ecs-operation-review in your project. Codex loads it when a task matches its description.

Can I use Ecs Operation Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill ecs-operation-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ecs-operation-review, .gemini/skills/ecs-operation-review, .github/skills/ecs-operation-review and .opencode/skills/ecs-operation-review in your project.

What does Ecs Operation Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Ecs Operation Review is instructions for the agent only.

Does Ecs Operation Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ecs Operation Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ecs Operation Review use?

Ecs Operation Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ecs Operation Review use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Ecs Operation Review?

Skills that share tags, products or a category with Ecs Operation Review: AWS Cost Operations (Microck/ordinary-claude-skills, 404 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Tool Defs Analysis (cyanheads/pubmed-mcp-server, 156 stars) and AWS Cost Operations (zxkane/aws-skills, 367 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ecs Operation Review?

aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 102 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.

Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.