Ak Add Capabilities
yaalalabs/agent-kernel
Add capabilities to an existing Agent Kernel project. An agent skill from yaalalabs/agent-kernel.
Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools.
$ npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/tools-for-devops-agent investigation-cost-guardrail --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/investigation-cost-guardrail .claude/skills/investigation-cost-guardrail && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "investigation-cost-guardrail" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/investigation-cost-guardrail into .claude/skills/investigation-cost-guardrail/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigation-cost-guardrail", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/tools-for-devops-agent/tree/main/skills/investigation-cost-guardrailType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/tools-for-devops-agent investigation-cost-guardrail --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/investigation-cost-guardrail .agents/skills/investigation-cost-guardrail && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "investigation-cost-guardrail" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/investigation-cost-guardrail into .agents/skills/investigation-cost-guardrail/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigation-cost-guardrail", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/tools-for-devops-agent investigation-cost-guardrail --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/investigation-cost-guardrail .cursor/skills/investigation-cost-guardrail && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "investigation-cost-guardrail" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/investigation-cost-guardrail into .cursor/skills/investigation-cost-guardrail/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigation-cost-guardrail", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/tools-for-devops-agent.git --path skills/investigation-cost-guardrail--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/tools-for-devops-agent investigation-cost-guardrail --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/investigation-cost-guardrail .gemini/skills/investigation-cost-guardrail && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "investigation-cost-guardrail" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/investigation-cost-guardrail into .gemini/skills/investigation-cost-guardrail/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigation-cost-guardrail", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/tools-for-devops-agent investigation-cost-guardrailInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/investigation-cost-guardrail .github/skills/investigation-cost-guardrail && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "investigation-cost-guardrail" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/investigation-cost-guardrail into .github/skills/investigation-cost-guardrail/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigation-cost-guardrail", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/tools-for-devops-agent investigation-cost-guardrail --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/investigation-cost-guardrail .opencode/skills/investigation-cost-guardrail && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "investigation-cost-guardrail" agent skill from https://github.com/aws/tools-for-devops-agent/tree/main/skills/investigation-cost-guardrail into .opencode/skills/investigation-cost-guardrail/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigation-cost-guardrail", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
investigation-cost-guardrailCost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools.
Investigation Cost Guardrail is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools. Before the agent makes any paid API call, this skill estimates cost, enforces budgets per investigation, detects expensive operations across all services (Athena queries, S3 scans, DynamoDB scans, SageMaker inference, PromQL, etc.), enforces time window requirements, monitors cumulative call volume, and cancels if thresholds are exceeded. This skill applies to ALL investigations regardless of which services are involved.
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `CHANGELOG.md`, `README.md` and `evals/benchmark.json`).
It sits in AI & LLM Engineering, covering LLM guardrails, File uploads and storage and NoSQL databases. It works with Amazon Web Services, Amazon SageMaker, Amazon DynamoDB and Prometheus. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Investigation Cost Guardrail loads about 4.5k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 136 tokens; SKILL.md has 1,700 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,700 words, ~4,491 tokens.
.claude/skills/investigation-cost-guardrail/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.This skill provides cost guardrails for ANY AWS service and ALL native agent tools — not just a hardcoded list. It uses heuristic classification to determine whether an API operation is free or paid, estimates cost before execution, and enforces per-investigation budgets.
Rather than listing every free/paid operation across 200+ AWS services, this skill uses three layers:
This skill MUST be ALWAYS ACTIVE during investigations. It does NOT require user invocation.
The first time an operation is classified PAID by Layer 2, fetch the live rate before estimating cost.
For AWS operations: read references/pricing-reference.md for the exact Pricing API call patterns, filter fields, filter values, and failure handling. The reference file specifies — for each service and operation — whether to use Field:"operation" or Field:"usagetype", and the exact value to use. Do not derive these from the operation name.
For non-AWS tools (Splunk, Datadog, Grafana, etc.): use the cost model from Layer 0 directly — no live lookup available.
Before Layer 1 heuristics, classify the agent's own tools. These are NOT use_aws calls but have distinct billing implications:
| Tool | Classification | Cost Model | Guardrail |
|---|---|---|---|
get_prometheus_metrics | PAID | Billed per sample scanned — rate from live CW:PromQL:SamplesScanned usagetype lookup (AmazonCloudWatch, workload-region prefix) | Track samples scanned per call; HALT if rate lookup returns 0 products |
use_aws | VARIABLE | Depends on operation — apply Layers 1–3 | Full heuristic pipeline |
use_azure | FREE | Azure Reader role, no per-call billing | Track count only |
grafana_query_prometheus | CAUTION | Depends on Grafana data source billing model | Track count, warn at 50+ |
use_datadog | CAUTION | Datadog API rate limits (no per-call $ cost, but may throttle) | Track count, warn at 100+ |
use_splunk | PAID | Splunk search license (per GB ingested/searched) | Treat like CW Logs StartQuery |
use_pagerduty | FREE | PagerDuty API (rate limited, not per-call billed) | Track count only |
shell | CAUTION | May invoke aws, az, kubectl — untracked by Layers 1–3 | Log commands, warn if aws/az detected |
subagent | PAID | Counts toward agent-seconds billing ($0.0083/sec) | Track spawns, enforce total time |
fs_read, fs_write, fs_tree | FREE | Local file I/O | No guardrail needed |
datetime | FREE | Internal state ops | No guardrail needed |
write_scratchpad, read_scratchpad | FREE | Internal state (may not be available in all environments) | No guardrail needed |
read_memories | FREE | Internal memory recall | No guardrail needed |
get_prometheus_metrics deserves special handling because:
500 × rate per period.step multiply cost: 7d / 60s step = 10,080 datapoints × 500 series = 5M samplesBefore each PromQL call:
rate = live usagetype lookup (AmazonCloudWatch, usagetype=<PREFIX>-CW:PromQL:SamplesScanned)
# bare "CW:PromQL:SamplesScanned" for us-east-1; use workload-region prefix for all others
if rate lookup returns 0 products: 🚫 HALT — do not hardcode or improvise a rate
estimated_samples = min(500, estimated_series) × (time_range_seconds / step_seconds)
estimated_cost = estimated_samples × rate
if estimated_cost > $0.50:
⚠️ WARN — suggest narrower time range, larger step, or label filters
if estimated_cost > $2.00:
🚫 HALT — require approval or suggest aggregation (sum, topk, avg)Cost reduction for PromQL:
sum by (label) to reduce series counttopk(N, ...) to cap returned seriesstep (300s instead of 60s = 5× cheaper)Before making ANY use_aws call, classify the operation using these rules IN ORDER:
An operation is FREE if it matches ALL of these:
Describe, List, Get, Lookup, Check, Validate, Tag, Untag⚠️ Exception: Some services charge per-request even for Get/List operations. Layer 2 overrides this heuristic for S3 and Lambda Invoke — when Layer 2 has an entry, it takes precedence over Rule 1.
⚠️ Tool policy can override cost classification. Some operations classified as FREE here (e.g.,
cloudtrail:LookupEvents) may be blocked by tool policy in certain environments. If an operation is denied, it costs $0.00 (never executed) — proceed with alternatives.
An operation is PAID if it matches ANY of these patterns:
| Pattern | Why It Costs Money | Examples |
|---|---|---|
Verb contains Query | Scans indexed data | StartQuery, StartQueryExecution |
Verb contains Scan | Full table/index scan | Scan (DynamoDB), StartScan |
Verb contains Execute + processes data | Runs a computation | StartQueryExecution (Athena), ExecuteStatement |
Verb contains Invoke + runs workload | Triggers compute | InvokeEndpoint (SageMaker), Invoke (Lambda) |
| Operation reads content (not metadata) | Data transfer | GetObject (S3, large), GetLogEvents (bulk), BatchGetTraces |
| Operation starts a streaming session | Per-time billing | StartLiveTail |
Operation name contains Insights | Analytics processing | GetContributorInsights, GetInsightRuleReport |
An operation is FREE but CAUTION if:
Examples: ListObjectsV2 (large bucket), ListMetrics (unfiltered), DescribeTasks (large cluster)
If an operation doesn't clearly fit Rules 1–3:
These operations have confirmed pricing. Before estimating, fetch the live rate via the Pricing API using the exact filter field and value from the table below — see references/pricing-reference.md for the bash call patterns and region prefix mapping.
Critical lookup rule:
usagetypeandoperationare different Pricing API filter fields. The correct field and value for each operation are specified explicitly below — do NOT derive them from the operation name.
if len(products) == 0:
🚫 HALT — Pricing lookup returned no results for <ServiceCode>:<Operation>
Reason: filter field/value or workload-region prefix may be incorrect
Do NOT proceed with the paid operation.
Do NOT improvise a rate from memory, training data, or any other source.
Options:
→ Re-check pricing-reference.md for the correct filter field, value, and region prefix
→ Skip this operation and use a free alternative
→ Report the lookup gap to the userRate =
pricePerUnit.USDfromterms.OnDemand → priceDimensionswherebeginRange="0". No /1K or /1M divisors. Region scoping: see Region Scoping column.
| ServiceCode | Layer 2 Operation | Pricing API Filter Field | Filter Value | Region scoping | Cost Formula | Estimation Method |
|---|---|---|---|---|---|---|
AmazonCloudWatch | GetMetricData | operation | GetMetricData | + regionCode=<workload-region> | (metrics × periods) × rate | Count metrics and periods |
AmazonCloudWatch | StartQuery | operation | StartQuery | + regionCode=<workload-region> | scan_gb × rate | Query IncomingBytes metric for time window |
AmazonCloudWatch | StartLiveTail | operation | StartLiveTail | + regionCode=<workload-region> | Duration-based | Duration-based |
AmazonCloudWatch | GetInsightRuleReport | usagetype | CW:GIRR-Metrics | workload-region prefix required (bare in us-east-1) | metrics_requested × rate | Count metrics requested in the report call |
AmazonCloudWatch | get_prometheus_metrics (native tool) | usagetype | CW:PromQL:SamplesScanned | workload-region prefix required (bare in us-east-1) | samples_scanned × rate | Estimate min(500, series) × (range_seconds / step_seconds) |
AWSXRay | GetTraceSummaries | operation | XRay-Traces-Scanned | + regionCode=<workload-region> | traces × rate | Paginate or sample to estimate count |
AWSXRay | BatchGetTraces | operation | XRay-Traces-Retrieved | + regionCode=<workload-region> | traces × rate | Count trace IDs in request |
AmazonAthena | StartQueryExecution | usagetype | DataScannedInTB | workload-region prefix required (USE1- for us-east-1) | scan_tb × rate; min 10MB | Check table metadata; require WHERE clause |
AmazonDynamoDB | Scan | usagetype | ReadRequestUnits | workload-region prefix required (bare in us-east-1, no USE1-) | RCU consumed × rate | Check TableSizeBytes; BLOCK unless user approves |
AmazonDynamoDB | Query | usagetype | ReadRequestUnits | workload-region prefix required (bare in us-east-1, no USE1-) | RCU consumed × rate | Check ItemCount; warn if > 10K items |
AmazonS3 | GetObject | usagetype | Requests-Tier2 | workload-region prefix required (bare in us-east-1) | See pricing-reference.md | Count requests; flag if cross-region or >100MB |
AmazonS3 | ListObjectsV2, ListObjects | usagetype | Requests-Tier1 | workload-region prefix required (bare in us-east-1) | See pricing-reference.md | Count calls; warn if paginating heavily |
AmazonS3 | PutObject, CopyObject | usagetype | Requests-Tier1 | workload-region prefix required (bare in us-east-1) | See pricing-reference.md | Count calls |
AmazonS3 | SelectObjectContent | usagetype | Bills on 3 meters — see pricing-reference.md | workload-region prefix required (bare in us-east-1) | See pricing-reference.md | Check object size |
AmazonSageMaker | InvokeEndpoint | — | — | — | — | BLOCK — require explicit user approval |
AWSLambda | Invoke | — | — | — | Per request + compute | BLOCK unless user explicitly requests function execution |
After ANY operation executes, check the response for metered fields:
| Field Pattern | Meaning | Action |
|---|---|---|
BytesScanned, DataScanned | Data scanning charge | Record GB scanned, add to running cost |
RecordsProcessed, ItemCount | Record processing | Record count, estimate RCU/cost |
QueryExecutionId + DataScannedInBytes | Athena scan | Add to cost at live rate |
TracesProcessedCount | X-Ray processing | Add to cost at live rate |
ConsumedCapacity | DynamoDB RCU/WCU | Add to cost at live rate |
ContentLength > 100MB | Large object fetch | Flag for transfer cost |
NextToken after 10+ pages | Pagination runaway | Trigger volume guardrail |
warnings containing "500 series" | PromQL truncation | Flag max-cost query, suggest narrowing |
If a previously-unclassified operation returns metered fields:
⚠️ Discovered paid operation: <servicecode>:<operation> cost $X.XXThe agent MUST mentally track a running cost estimate throughout the investigation. Since write_scratchpad/read_scratchpad are not available in all environments, budget enforcement is behavioral — the agent maintains the accumulator in its context window.
At investigation start:
Budget: $10.00
Running cost: $0.00
Call counts: {}Before each PAID operation:
estimated_cost = estimate(operation)
if running_cost + estimated_cost > budget:
🚫 HALT — show budget display
else:
proceed
# After execution:
running_cost += actual_cost (from response fields or estimation)
call_counts[servicecode] += 1Volume guardrails:
if call_counts[any_servicecode] > 200: ⚠️ WARN
if call_counts[any_servicecode] > 500: 🚫 HALT
if sum(all_call_counts) > 1000: 🚫 HALTℹ️ If
write_scratchpadbecomes available in your environment, use it for persistent state across subagent boundaries. Check with:search_user_tools("scratchpad"). If found, store{budget, running_cost, call_counts}as JSON.
📋 INVESTIGATION BUDGET STATUS
════════════════════════════════════════════════════════════
Budget: $10.00
Spent: $X.XX (Y paid operations)
Free calls: Z operations (no cost)
PromQL: X,XXX samples scanned ($X.XX)
Next op: <servicecode>:<operation> — estimated $X.XX
Projected: $X.XX (exceeds budget by $X.XX)
🚫 HALTED — would exceed $10.00 budget.
💡 Options:
→ Approve additional $X.XX to continue
→ Narrow the time window to reduce scan volume
→ Skip this operation and continue with free alternatives
→ End investigation with findings so farFor ANY operation classified as PAID that scans data over a time range:
| Scenario | Action |
|---|---|
| User provided time window | ✅ Use it — estimate cost for that window |
| No time window, operation scans data | 🚫 CANCEL — show worst-case cost, ask for window |
| No time window, operation is bounded (single resource lookup) | ✅ Proceed — no scan involved |
Key distinction: "Get me the config of Lambda X" (bounded, free) vs. "Search logs for errors" (unbounded scan, needs window).
PromQL-specific: Range queries without explicit start/end default to "now" which is safe. But broad label selectors ({} with just metric name) can hit 500 series cap — always prefer specific labels.
For EVERY paid operation:
if target_region ≠ agent_space_region:
fetch transfer_rate = transfer_rate_cache[target_region]
?? live lookup (see references/pricing-reference.md)
# If the live lookup returns 0 products: 🚫 HALT — do NOT improvise a rate
estimated_return_size = estimate_return_bytes(operation_type)
transfer_cost = estimated_return_size × transfer_rate
total_estimate += transfer_cost
flag: "⚠️ Cross-region transfer: <target> → <agent_space>"Return size heuristics:
When halting or warning, ALWAYS suggest free or cheaper alternatives:
| Pattern | Free/Cheaper Alternative |
|---|---|
| Broad time window scan | Narrow to ±30 min around the incident |
| Multiple resource query | Target specific resource ID |
| Full scan (DynamoDB, Athena) | Add filter/WHERE/key condition |
| Analytics query for known string | Use free filter API (FilterLogEvents) — note: LookupEvents may be tool-policy-blocked in some environments |
| Cross-region operation | Suggest user run from workload region |
| Large object fetch | Use SelectObjectContent with SQL filter |
| Pagination explosion | Add limit, filter, or narrower scope |
| Broad PromQL (no label filters) | Add specific label matchers or use aggregation |
| PromQL small step (60s over 7d) | Increase to 300s+ or reduce time range |
| Instead of... | Use... | Savings |
|---|---|---|
logs:StartQuery | logs:FilterLogEvents (if searching for known string) | 100% |
cloudwatch:GetMetricData (many) | cloudwatch:GetMetricStatistics (single) | ~100% |
get_prometheus_metrics (broad) | Add sum by (label) or topk(5, ...) | 90%+ |
dynamodb:Scan | dynamodb:Query with key condition | ~100% |
athena:StartQueryExecution (full) | Add partition filter in WHERE | 90%+ |
xray:GetTraceSummaries (broad) | Narrow time + add filter expression | 90%+ |
s3:GetObject (large) | s3:SelectObjectContent with SQL | Variable |
© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (references) in skills/investigation-cost-guardrail of aws/tools-for-devops-agent.
Open the folder on GitHubat commit ddda70b
Investigation Cost Guardrail next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Investigation Cost Guardrail this skillaws/tools-for-devops-agent | 103 | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Ak Add Capabilitiesyaalalabs/agent-kernel | 192 | — | ~13k | Automated safety check: Pass | Apache-2.0 | |
| AWS CLI Beastgiuseppe-trisciuoglio/developer-kit | 357 | — | ~1.7k | Automated safety check: Notes | MIT | |
| AWS Cloud Patternsrohitg00/awesome-claude-code-toolkit | 2.7k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| AWS Advisordiegosouzapw/awesome-omni-skills | 159 | — | ~4.3k | Automated safety check: Pass | MIT | |
| Amplify Workflowawslabs/agent-plugins | 916 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 |
yaalalabs/agent-kernel
Add capabilities to an existing Agent Kernel project. An agent skill from yaalalabs/agent-kernel.
giuseppe-trisciuoglio/developer-kit
Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.
rohitg00/awesome-claude-code-toolkit
AWS cloud patterns for Lambda, ECS, S3, DynamoDB, and Infrastructure as Code with CDK/Terraform
diegosouzapw/awesome-omni-skills
AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
awslabs/agent-plugins
Build and deploy full-stack web and mobile apps with AWS Amplify Gen2 (TypeScript code-first).
aws/agent-toolkit-for-aws
AWS SDK for Python (boto3/botocore) development patterns. An agent skill from aws/agent-toolkit-for-aws.
aws/tools-for-devops-agent
A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.
aws/tools-for-devops-agent
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.
aws/tools-for-devops-agent
AWS Database Migration Service (DMS) operational review and troubleshooting skill.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
aws/tools-for-devops-agent
Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.
aws/tools-for-devops-agent
Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.
Categories
Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools. Investigation Cost Guardrail is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools.
Investigation Cost Guardrail fits situations like: tasks that involve LLM guardrails; tasks that involve File uploads and storage; tasks that involve NoSQL databases.
Run `npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a claude-code`. Or copy the skill folder (skills/investigation-cost-guardrail in aws/tools-for-devops-agent) into .claude/skills/investigation-cost-guardrail in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a codex`. Or copy the skill folder (skills/investigation-cost-guardrail in aws/tools-for-devops-agent) into .agents/skills/investigation-cost-guardrail in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigation-cost-guardrail, .gemini/skills/investigation-cost-guardrail, .github/skills/investigation-cost-guardrail and .opencode/skills/investigation-cost-guardrail in your project.
SKILL.md names no scripts, command-line tools or credentials: Investigation Cost Guardrail is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Investigation Cost Guardrail is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Investigation Cost Guardrail: Ak Add Capabilities (yaalalabs/agent-kernel, 192 stars), AWS CLI Beast (giuseppe-trisciuoglio/developer-kit, 357 stars), AWS Cloud Patterns (rohitg00/awesome-claude-code-toolkit, 2.7k stars) and AWS Advisor (diegosouzapw/awesome-omni-skills, 159 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 103 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 9, 2026.
Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.