Official agent skill

Investigation Cost Guardrail

by aws in aws/tools-for-devops-agent

Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools.

OfficialApache-2.0Auto-check passedAI & LLM Engineering

Install Investigation Cost Guardrail

skills CLI
$ npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/tools-for-devops-agent investigation-cost-guardrail --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/investigation-cost-guardrail .claude/skills/investigation-cost-guardrail && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
investigation-cost-guardrail
GitHub stars
103
Token cost
~4.5k tokens
SKILL.md length
1,700 words
Files
9 (incl. references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools.

  • Works in 3 steps: Heuristic rules — classify any operation… → Known-paid registry — explicit overrides… → Response validation — detect metered…
  • Tasks that involve LLM guardrails
  • SKILL.md covers Overview, Design Principle, Activation and Fetch Live Rate Before…, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Investigation Cost Guardrail is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools. Before the agent makes any paid API call, this skill estimates cost, enforces budgets per investigation, detects expensive operations across all services (Athena queries, S3 scans, DynamoDB scans, SageMaker inference, PromQL, etc.), enforces time window requirements, monitors cumulative call volume, and cancels if thresholds are exceeded. This skill applies to ALL investigations regardless of which services are involved.

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `CHANGELOG.md`, `README.md` and `evals/benchmark.json`).

It sits in AI & LLM Engineering, covering LLM guardrails, File uploads and storage and NoSQL databases. It works with Amazon Web Services, Amazon SageMaker, Amazon DynamoDB and Prometheus. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve LLM guardrails
  • Tasks that involve File uploads and storage
  • Tasks that involve NoSQL databases

Example prompts

  • “/investigation-cost-guardrail”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Heuristic rules — classify any operation based on naming patterns and behavior
  2. Known-paid registry — explicit overrides for high-cost operations with pricing formulas
  3. Response validation — detect metered usage from API response fields after execution

What it can do on your machine

Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Investigation Cost Guardrail loads about 4.5k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 136 tokens; SKILL.md has 1,700 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 1,700 words, ~4,491 tokens.

Download SKILL.mdSave it as .claude/skills/investigation-cost-guardrail/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
investigation-cost-guardrail
description
Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools. Before the agent makes any paid API call, this skill estimates cost, enforces budgets per investigation, detects expensive operations across all services (Athena queries, S3 scans, DynamoDB scans, SageMaker inference, PromQL, etc.), enforces time window requirements, monitors cumulative call volume, and cancels if thresholds are exceeded. This skill applies to ALL investigations regardless of which services are involved.
metadata.author
tqquresh, inesttia
metadata.version
2.1.0
metadata.aws-devops-agent-skills.agent-t
Incident RCA
metadata.aws-devops-agent-skills.aws-ser
All
metadata.aws-devops-agent-skills.technic
Cost Optimization, Operations

Investigation Cost Guardrail Skill

Overview

This skill provides cost guardrails for ANY AWS service and ALL native agent tools — not just a hardcoded list. It uses heuristic classification to determine whether an API operation is free or paid, estimates cost before execution, and enforces per-investigation budgets.

Design Principle

Rather than listing every free/paid operation across 200+ AWS services, this skill uses three layers:

  1. Heuristic rules — classify any operation based on naming patterns and behavior
  2. Known-paid registry — explicit overrides for high-cost operations with pricing formulas
  3. Response validation — detect metered usage from API response fields after execution

Activation

This skill MUST be ALWAYS ACTIVE during investigations. It does NOT require user invocation.

Fetch Live Rate Before Estimating

The first time an operation is classified PAID by Layer 2, fetch the live rate before estimating cost.

For AWS operations: read references/pricing-reference.md for the exact Pricing API call patterns, filter fields, filter values, and failure handling. The reference file specifies — for each service and operation — whether to use Field:"operation" or Field:"usagetype", and the exact value to use. Do not derive these from the operation name.

For non-AWS tools (Splunk, Datadog, Grafana, etc.): use the cost model from Layer 0 directly — no live lookup available.


Layer 0: Native Agent Tool Classification

Before Layer 1 heuristics, classify the agent's own tools. These are NOT use_aws calls but have distinct billing implications:

Tool Cost Matrix
ToolClassificationCost ModelGuardrail
get_prometheus_metricsPAIDBilled per sample scanned — rate from live CW:PromQL:SamplesScanned usagetype lookup (AmazonCloudWatch, workload-region prefix)Track samples scanned per call; HALT if rate lookup returns 0 products
use_awsVARIABLEDepends on operation — apply Layers 1–3Full heuristic pipeline
use_azureFREEAzure Reader role, no per-call billingTrack count only
grafana_query_prometheusCAUTIONDepends on Grafana data source billing modelTrack count, warn at 50+
use_datadogCAUTIONDatadog API rate limits (no per-call $ cost, but may throttle)Track count, warn at 100+
use_splunkPAIDSplunk search license (per GB ingested/searched)Treat like CW Logs StartQuery
use_pagerdutyFREEPagerDuty API (rate limited, not per-call billed)Track count only
shellCAUTIONMay invoke aws, az, kubectl — untracked by Layers 1–3Log commands, warn if aws/az detected
subagentPAIDCounts toward agent-seconds billing ($0.0083/sec)Track spawns, enforce total time
fs_read, fs_write, fs_treeFREELocal file I/ONo guardrail needed
datetimeFREEInternal state opsNo guardrail needed
write_scratchpad, read_scratchpadFREEInternal state (may not be available in all environments)No guardrail needed
read_memoriesFREEInternal memory recallNo guardrail needed
PromQL-Specific Controls

get_prometheus_metrics deserves special handling because:

  • Maximum 500 series per query — a broad query hitting the cap costs 500 × rate per period.
  • Range queries with small step multiply cost: 7d / 60s step = 10,080 datapoints × 500 series = 5M samples

Before each PromQL call:

text
rate = live usagetype lookup (AmazonCloudWatch, usagetype=<PREFIX>-CW:PromQL:SamplesScanned)
       # bare "CW:PromQL:SamplesScanned" for us-east-1; use workload-region prefix for all others
if rate lookup returns 0 products: 🚫 HALT — do not hardcode or improvise a rate

estimated_samples = min(500, estimated_series) × (time_range_seconds / step_seconds)
estimated_cost = estimated_samples × rate

if estimated_cost > $0.50:
    ⚠️ WARN — suggest narrower time range, larger step, or label filters
if estimated_cost > $2.00:
    🚫 HALT — require approval or suggest aggregation (sum, topk, avg)

Cost reduction for PromQL:

  • Use sum by (label) to reduce series count
  • Use topk(N, ...) to cap returned series
  • Increase step (300s instead of 60s = 5× cheaper)
  • Narrow time range (1h instead of 7d = 168× cheaper)

Layer 1: Heuristic Classification

Before making ANY use_aws call, classify the operation using these rules IN ORDER:

Rule 1: FREE by default — Metadata operations

An operation is FREE if it matches ALL of these:

  • Verb is: Describe, List, Get, Lookup, Check, Validate, Tag, Untag
  • It returns metadata/configuration (not data content or query results)
  • It does NOT scan, process, or transform customer data

⚠️ Exception: Some services charge per-request even for Get/List operations. Layer 2 overrides this heuristic for S3 and Lambda Invoke — when Layer 2 has an entry, it takes precedence over Rule 1.

⚠️ Tool policy can override cost classification. Some operations classified as FREE here (e.g., cloudtrail:LookupEvents) may be blocked by tool policy in certain environments. If an operation is denied, it costs $0.00 (never executed) — proceed with alternatives.

Rule 2: PAID — Data-scanning operations

An operation is PAID if it matches ANY of these patterns:

PatternWhy It Costs MoneyExamples
Verb contains QueryScans indexed dataStartQuery, StartQueryExecution
Verb contains ScanFull table/index scanScan (DynamoDB), StartScan
Verb contains Execute + processes dataRuns a computationStartQueryExecution (Athena), ExecuteStatement
Verb contains Invoke + runs workloadTriggers computeInvokeEndpoint (SageMaker), Invoke (Lambda)
Operation reads content (not metadata)Data transferGetObject (S3, large), GetLogEvents (bulk), BatchGetTraces
Operation starts a streaming sessionPer-time billingStartLiveTail
Operation name contains InsightsAnalytics processingGetContributorInsights, GetInsightRuleReport
Rule 3: CAUTION — High-volume free operations

An operation is FREE but CAUTION if:

  • It's a paginated List/Describe that could return thousands of results
  • It has no built-in limit and the scope is broad (e.g., all resources in a region)

Examples: ListObjectsV2 (large bucket), ListMetrics (unfiltered), DescribeTasks (large cluster)

Rule 4: UNKNOWN — Cannot classify

If an operation doesn't clearly fit Rules 1–3:

  • Treat as CAUTION (proceed but track)
  • After execution, check response for metered fields (see Layer 3)
  • If metered: add to the known-paid list for this session

Layer 2: Known-Paid Registry

These operations have confirmed pricing. Before estimating, fetch the live rate via the Pricing API using the exact filter field and value from the table below — see references/pricing-reference.md for the bash call patterns and region prefix mapping.

Critical lookup rule: usagetype and operation are different Pricing API filter fields. The correct field and value for each operation are specified explicitly below — do NOT derive them from the operation name.

Pricing Lookup Rules
text
if len(products) == 0:
    🚫 HALT — Pricing lookup returned no results for <ServiceCode>:<Operation>
    Reason: filter field/value or workload-region prefix may be incorrect
    Do NOT proceed with the paid operation.
    Do NOT improvise a rate from memory, training data, or any other source.
    Options:
      → Re-check pricing-reference.md for the correct filter field, value, and region prefix
      → Skip this operation and use a free alternative
      → Report the lookup gap to the user
Confirmed Paid Operations

Rate = pricePerUnit.USD from terms.OnDemand → priceDimensions where beginRange="0". No /1K or /1M divisors. Region scoping: see Region Scoping column.

ServiceCodeLayer 2 OperationPricing API Filter FieldFilter ValueRegion scopingCost FormulaEstimation Method
AmazonCloudWatchGetMetricDataoperationGetMetricData+ regionCode=<workload-region>(metrics × periods) × rateCount metrics and periods
AmazonCloudWatchStartQueryoperationStartQuery+ regionCode=<workload-region>scan_gb × rateQuery IncomingBytes metric for time window
AmazonCloudWatchStartLiveTailoperationStartLiveTail+ regionCode=<workload-region>Duration-basedDuration-based
AmazonCloudWatchGetInsightRuleReportusagetypeCW:GIRR-Metricsworkload-region prefix required (bare in us-east-1)metrics_requested × rateCount metrics requested in the report call
AmazonCloudWatchget_prometheus_metrics (native tool)usagetypeCW:PromQL:SamplesScannedworkload-region prefix required (bare in us-east-1)samples_scanned × rateEstimate min(500, series) × (range_seconds / step_seconds)
AWSXRayGetTraceSummariesoperationXRay-Traces-Scanned+ regionCode=<workload-region>traces × ratePaginate or sample to estimate count
AWSXRayBatchGetTracesoperationXRay-Traces-Retrieved+ regionCode=<workload-region>traces × rateCount trace IDs in request
AmazonAthenaStartQueryExecutionusagetypeDataScannedInTBworkload-region prefix required (USE1- for us-east-1)scan_tb × rate; min 10MBCheck table metadata; require WHERE clause
AmazonDynamoDBScanusagetypeReadRequestUnitsworkload-region prefix required (bare in us-east-1, no USE1-)RCU consumed × rateCheck TableSizeBytes; BLOCK unless user approves
AmazonDynamoDBQueryusagetypeReadRequestUnitsworkload-region prefix required (bare in us-east-1, no USE1-)RCU consumed × rateCheck ItemCount; warn if > 10K items
AmazonS3GetObjectusagetypeRequests-Tier2workload-region prefix required (bare in us-east-1)See pricing-reference.mdCount requests; flag if cross-region or >100MB
AmazonS3ListObjectsV2, ListObjectsusagetypeRequests-Tier1workload-region prefix required (bare in us-east-1)See pricing-reference.mdCount calls; warn if paginating heavily
AmazonS3PutObject, CopyObjectusagetypeRequests-Tier1workload-region prefix required (bare in us-east-1)See pricing-reference.mdCount calls
AmazonS3SelectObjectContentusagetypeBills on 3 meters — see pricing-reference.mdworkload-region prefix required (bare in us-east-1)See pricing-reference.mdCheck object size
AmazonSageMakerInvokeEndpoint————BLOCK — require explicit user approval
AWSLambdaInvoke———Per request + computeBLOCK unless user explicitly requests function execution

Show full SKILL.md (543 more words)Show less

Layer 3: Response Validation

After ANY operation executes, check the response for metered fields:

Metered Response Fields (indicates cost was incurred)
Field PatternMeaningAction
BytesScanned, DataScannedData scanning chargeRecord GB scanned, add to running cost
RecordsProcessed, ItemCountRecord processingRecord count, estimate RCU/cost
QueryExecutionId + DataScannedInBytesAthena scanAdd to cost at live rate
TracesProcessedCountX-Ray processingAdd to cost at live rate
ConsumedCapacityDynamoDB RCU/WCUAdd to cost at live rate
ContentLength > 100MBLarge object fetchFlag for transfer cost
NextToken after 10+ pagesPagination runawayTrigger volume guardrail
warnings containing "500 series"PromQL truncationFlag max-cost query, suggest narrowing

If a previously-unclassified operation returns metered fields:

  1. Log it as a paid operation for this session
  2. Add the cost to the running total
  3. Warn the user: ⚠️ Discovered paid operation: <servicecode>:<operation> cost $X.XX

Budget Enforcement

Per-Investigation Budget

The agent MUST mentally track a running cost estimate throughout the investigation. Since write_scratchpad/read_scratchpad are not available in all environments, budget enforcement is behavioral — the agent maintains the accumulator in its context window.

At investigation start:

text
Budget: $10.00
Running cost: $0.00
Call counts: {}

Before each PAID operation:

text
estimated_cost = estimate(operation)
if running_cost + estimated_cost > budget:
    🚫 HALT — show budget display
else:
    proceed
    # After execution:
    running_cost += actual_cost (from response fields or estimation)
    call_counts[servicecode] += 1

Volume guardrails:

text
if call_counts[any_servicecode] > 200: ⚠️ WARN
if call_counts[any_servicecode] > 500: 🚫 HALT
if sum(all_call_counts) > 1000: 🚫 HALT

ℹ️ If write_scratchpad becomes available in your environment, use it for persistent state across subagent boundaries. Check with: search_user_tools("scratchpad"). If found, store {budget, running_cost, call_counts} as JSON.

Budget Display (on halt)
text
📋 INVESTIGATION BUDGET STATUS
════════════════════════════════════════════════════════════
Budget:      $10.00
Spent:       $X.XX (Y paid operations)
Free calls:  Z operations (no cost)
PromQL:      X,XXX samples scanned ($X.XX)
Next op:     <servicecode>:<operation> — estimated $X.XX
Projected:   $X.XX (exceeds budget by $X.XX)

🚫 HALTED — would exceed $10.00 budget.
💡 Options:
  → Approve additional $X.XX to continue
  → Narrow the time window to reduce scan volume
  → Skip this operation and continue with free alternatives
  → End investigation with findings so far

Time Window Enforcement

For ANY operation classified as PAID that scans data over a time range:

ScenarioAction
User provided time window✅ Use it — estimate cost for that window
No time window, operation scans data🚫 CANCEL — show worst-case cost, ask for window
No time window, operation is bounded (single resource lookup)✅ Proceed — no scan involved

Key distinction: "Get me the config of Lambda X" (bounded, free) vs. "Search logs for errors" (unbounded scan, needs window).

PromQL-specific: Range queries without explicit start/end default to "now" which is safe. But broad label selectors ({} with just metric name) can hit 500 series cap — always prefer specific labels.


Cross-Region Detection

For EVERY paid operation:

text
if target_region ≠ agent_space_region:
    fetch transfer_rate = transfer_rate_cache[target_region]
                       ?? live lookup (see references/pricing-reference.md)
    # If the live lookup returns 0 products: 🚫 HALT — do NOT improvise a rate
    estimated_return_size = estimate_return_bytes(operation_type)
    transfer_cost = estimated_return_size × transfer_rate
    total_estimate += transfer_cost
    flag: "⚠️ Cross-region transfer: <target> → <agent_space>"

Return size heuristics:

  • Aggregation queries (stats, count, group-by): ~KB (negligible)
  • PromQL with aggregation (sum, topk): ~KB (negligible)
  • PromQL range query (500 series × 10K points): ~50MB (flag ⚠️)
  • Raw log/trace fetches: up to 100% of matched bytes
  • Describe/List results: ~KB (negligible)
  • Unknown: use 15% of scan volume as upper bound, flag ⚠️

Cost Reduction Suggestions

When halting or warning, ALWAYS suggest free or cheaper alternatives:

Generic Alternatives (apply to any service)
PatternFree/Cheaper Alternative
Broad time window scanNarrow to ±30 min around the incident
Multiple resource queryTarget specific resource ID
Full scan (DynamoDB, Athena)Add filter/WHERE/key condition
Analytics query for known stringUse free filter API (FilterLogEvents) — note: LookupEvents may be tool-policy-blocked in some environments
Cross-region operationSuggest user run from workload region
Large object fetchUse SelectObjectContent with SQL filter
Pagination explosionAdd limit, filter, or narrower scope
Broad PromQL (no label filters)Add specific label matchers or use aggregation
PromQL small step (60s over 7d)Increase to 300s+ or reduce time range
Service-Specific Alternatives
Instead of...Use...Savings
logs:StartQuerylogs:FilterLogEvents (if searching for known string)100%
cloudwatch:GetMetricData (many)cloudwatch:GetMetricStatistics (single)~100%
get_prometheus_metrics (broad)Add sum by (label) or topk(5, ...)90%+
dynamodb:Scandynamodb:Query with key condition~100%
athena:StartQueryExecution (full)Add partition filter in WHERE90%+
xray:GetTraceSummaries (broad)Narrow time + add filter expression90%+
s3:GetObject (large)s3:SelectObjectContent with SQLVariable

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in skills/investigation-cost-guardrail of aws/tools-for-devops-agent.

  • SKILL.md
  • CHANGELOG.md
  • README.md
  • evals/benchmark.json
  • evals/eval_queries.json
  • evals/evals.json
  • evals/report.json
  • evals/trigger_report.json
  • references/pricing-reference.md

Open the folder on GitHubat commit ddda70b

Compare with similar skills

Investigation Cost Guardrail next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Investigation Cost Guardrail compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Investigation Cost Guardrail this skillaws/tools-for-devops-agent103—~4.5kAutomated safety check: PassApache-2.0
Ak Add Capabilitiesyaalalabs/agent-kernel192—~13kAutomated safety check: PassApache-2.0
AWS CLI Beastgiuseppe-trisciuoglio/developer-kit357—~1.7kAutomated safety check: NotesMIT
AWS Cloud Patternsrohitg00/awesome-claude-code-toolkit2.7k—~1.1kAutomated safety check: PassApache-2.0
AWS Advisordiegosouzapw/awesome-omni-skills159—~4.3kAutomated safety check: PassMIT
Amplify Workflowawslabs/agent-plugins916—~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Ak Add Capabilities

    yaalalabs/agent-kernel

    Add capabilities to an existing Agent Kernel project. An agent skill from yaalalabs/agent-kernel.

    192 GitHub stars~13k tokensUpdated yesterday
    DatabasesAuto-check passed
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    DatabasesAuto-check: notes
  • AWS Cloud Patterns

    rohitg00/awesome-claude-code-toolkit

    AWS cloud patterns for Lambda, ECS, S3, DynamoDB, and Infrastructure as Code with CDK/Terraform

    2.7k GitHub stars~1.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • AWS Advisor

    diegosouzapw/awesome-omni-skills

    AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4.3k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Amplify Workflow

    awslabs/agent-plugins

    Official

    Build and deploy full-stack web and mobile apps with AWS Amplify Gen2 (TypeScript code-first).

    916 GitHub stars~3.2k tokensUpdated yesterday
    MobileAuto-check passed
  • AWS SDK Python Usage

    aws/agent-toolkit-for-aws

    Official

    AWS SDK for Python (boto3/botocore) development patterns. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub starsUsed in 1 repo~2.1k tokens
    DatabasesAuto-check passed

More from aws/tools-for-devops-agent

All 31 skills in this repo
  • Aiml GPU Training Cluster Investigation

    aws/tools-for-devops-agent

    Official

    A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.

    103 GitHub stars~5.4k tokensUpdated yesterday
    Auto-check passed
  • AWS Health Events

    aws/tools-for-devops-agent

    Official

    ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

    103 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check passed
  • Database Migration Service Expertise

    aws/tools-for-devops-agent

    Official

    AWS Database Migration Service (DMS) operational review and troubleshooting skill.

    103 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    103 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    103 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Sagemaker AI Ops Review

    aws/tools-for-devops-agent

    Official

    Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.

    103 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed

Questions about Investigation Cost Guardrail

What does Investigation Cost Guardrail do?

Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools. Investigation Cost Guardrail is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. Cost guardrail for AWS DevOps Agent that covers ALL AWS services and native agent tools.

When should I use Investigation Cost Guardrail?

Investigation Cost Guardrail fits situations like: tasks that involve LLM guardrails; tasks that involve File uploads and storage; tasks that involve NoSQL databases.

How do I install Investigation Cost Guardrail in Claude Code?

Run `npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a claude-code`. Or copy the skill folder (skills/investigation-cost-guardrail in aws/tools-for-devops-agent) into .claude/skills/investigation-cost-guardrail in your project. Claude Code loads it when a task matches its description.

How do I install Investigation Cost Guardrail in Codex?

Run `npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a codex`. Or copy the skill folder (skills/investigation-cost-guardrail in aws/tools-for-devops-agent) into .agents/skills/investigation-cost-guardrail in your project. Codex loads it when a task matches its description.

Can I use Investigation Cost Guardrail in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill investigation-cost-guardrail -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigation-cost-guardrail, .gemini/skills/investigation-cost-guardrail, .github/skills/investigation-cost-guardrail and .opencode/skills/investigation-cost-guardrail in your project.

What does Investigation Cost Guardrail need to run?

SKILL.md names no scripts, command-line tools or credentials: Investigation Cost Guardrail is instructions for the agent only.

Does Investigation Cost Guardrail access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Investigation Cost Guardrail safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Investigation Cost Guardrail use?

Investigation Cost Guardrail is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Investigation Cost Guardrail use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Investigation Cost Guardrail?

Skills that share tags, products or a category with Investigation Cost Guardrail: Ak Add Capabilities (yaalalabs/agent-kernel, 192 stars), AWS CLI Beast (giuseppe-trisciuoglio/developer-kit, 357 stars), AWS Cloud Patterns (rohitg00/awesome-claude-code-toolkit, 2.7k stars) and AWS Advisor (diegosouzapw/awesome-omni-skills, 159 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Investigation Cost Guardrail?

aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 103 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 9, 2026.

Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.