Official agent skill

Lambda Annotations

by aws in aws/aws-lambda-dotnet

Conventions and safety rules for changing the Amazon.Lambda.Annotations library and its source generator, including the T4 templates that generate Lambda handler code.

OfficialApache-2.0Auto-check passedBackend & APIs

Install Lambda Annotations

skills CLI
$ npx skills add aws/aws-lambda-dotnet --skill lambda-annotations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/aws-lambda-dotnet lambda-annotations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/aws-lambda-dotnet.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/lambda-annotations .claude/skills/lambda-annotations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
lambda-annotations
GitHub stars
1.7k
Token cost
~1.7k tokens
SKILL.md length
740 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conventions and safety rules for changing the Amazon.Lambda.Annotations library and its source generator, including the T4 templates that generate Lambda handler code.

  • Works in 5 steps: Confirm the catch block changes the… → For authorizers, confirm the catch sets… → Quick audit of the authorizer template.… → …
  • Modifying parameter binding
  • SKILL.md covers Key Locations, Template Editing, Parameter Binding Must Never… and Change Files
  • Calls dotnet

What it does

Lambda Annotations is an agent skill from aws/aws-lambda-dotnet, published by the product's own GitHub organization. Conventions and safety rules for changing the Amazon.Lambda.Annotations library and its source generator, including the T4 templates that generate Lambda handler code. Use when modifying parameter binding, generated handler code, authorizer support, or the source generator templates.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Amazon Web Services and AWS Lambda. The repository describes itself as: Libraries, samples and tools to help .NET Core developers develop AWS Lambda functions. The licence is Apache-2.0.

When your agent uses it

  • Modifying parameter binding
  • Generated handler code
  • Authorizer support
  • The source generator templates

Example prompts

  • “Use the lambda-annotations skill to convention and safety rules for changing the Amazon.Lambda.Annotations library and its source generator…”
  • “/lambda-annotations”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the catch block changes the outcome of the request (validation error, 401 or deny) and doesn't only log.
  2. For authorizers, confirm the catch sets bindingFailed = true; and that HasBoundParameters() covers the new parameter source.
  3. Quick audit of the authorizer template. The three counts should match
  4. Add a runtime test with a malformed value (for example abc and an overflowing number for a long). It should assert that the user's method…
  5. Remember that existing snapshot tests mostly use string parameters, which can't fail conversion. Snapshots alone don't prove the failure…

What it can do on your machine

Read from SKILL.md and the folder at commit c801451. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Lambda Annotations loads about 1.7k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 740 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/aws-lambda-dotnet at commit c801451, republished under its Apache-2.0 licence (© aws). 740 words, ~1,654 tokens.

Download SKILL.mdSave it as .claude/skills/lambda-annotations/SKILL.md (or your agent's skills folder).
name
lambda-annotations
description
Conventions and safety rules for changing the Amazon.Lambda.Annotations library and its source generator, including the T4 templates that generate Lambda handler code. Use when modifying parameter binding, generated handler code, authorizer support, or the source generator templates.

Working on Amazon.Lambda.Annotations

This skill covers rules for changing the Amazon.Lambda.Annotations source generator. The code it generates is compiled into customer assemblies. A bug in a template becomes a bug in every customer function built with that version, and a fix only reaches customers when they rebuild and redeploy.

Key Locations

  • Attributes and runtime types: Libraries/src/Amazon.Lambda.Annotations/
  • Source generator: Libraries/src/Amazon.Lambda.Annotations.SourceGenerator/
  • Templates: Libraries/src/Amazon.Lambda.Annotations.SourceGenerator/Templates/
    • *.tt: T4 templates (the source of truth)
    • *.cs with the same name as a .tt: preprocessed output from TextTemplatingFilePreprocessor. Keep it in sync with the .tt.
    • *Code.cs: hand-written partial classes for the templates. Put non-trivial generation logic here rather than in the .tt so the preprocessed .cs changes stay small.
  • Source generator tests: Libraries/test/Amazon.Lambda.Annotations.SourceGenerators.Tests/
    • Snapshots/: expected generated code. Update these when template output changes.
    • AuthorizerBindingFailureTests.cs: runs the generator, compiles the output and invokes the generated handlers. Use it as the pattern for runtime behavior tests of generated code.

Template Editing

  • Edit the .tt and the matching preprocessed .cs together. Regenerating with Visual Studio is preferred. If you edit the .cs by hand, mirror the .tt exactly and keep the this.Write(...) strings using \r\n line endings like the rest of the file.
  • Generated code that is emitted from *Code.cs helpers should also use \r\n line endings to match the T4 output.
  • After changing templates, run the source generator tests on both target frameworks:
    cd Libraries/test/Amazon.Lambda.Annotations.SourceGenerators.Tests
    dotnet test
  • Building the test projects rewrites the serverless.template files under Libraries/test/* with the current Annotations version. Revert those changes unless the template change is intentional.

Parameter Binding Must Never Fail Silently

The templates convert client-supplied strings (headers, query string, route parameters, authorization tokens, authorizer context values) to the parameter type with Convert.ChangeType. Every Convert.ChangeType failure must change the outcome of the request. Logging the failure and continuing is not acceptable.

If a conversion failure is only logged, the parameter keeps its default(T) value (0, false, MinValue, null) and the user's method runs with a value the client never sent. For any security decision, an attacker can then choose that value by sending something that doesn't parse.

Required behavior by handler type:

Handler typeTemplateOn conversion failure
API Gateway ([RestApi], [HttpApi]) [FromHeader], [FromQuery], [FromRoute], [FromBody]APIGatewaySetupParameters.ttAdd to validationErrors and return 400 without invoking the user's method
API Gateway [FromCustomAuthorizer]APIGatewaySetupParameters.ttReturn 401 without invoking the user's method
ALBALBSetupParameters.ttAdd to validationErrors and return 400 without invoking the user's method
Authorizers ([HttpApiAuthorizer], [RestApiAuthorizer])AuthorizerSetupParameters.ttDeny without invoking the user's authorizer method
Show full SKILL.md (351 more words)Show less
Authorizers Must Fail Closed

An authorizer that runs on a default value can grant access. When binding fails, authorizer templates must deny the request:

  • Each conversion catch block in AuthorizerSetupParameters.tt sets __bindingFailed__ = true; after logging.
  • After all parameters are bound, the generated code checks __bindingFailed__ and returns the deny response from GenerateBindingFailureResponse() in AuthorizerSetupParametersCode.cs. The deny response matches the authorizer's return type:
    • IAuthorizerResult: AuthorizerResults.Deny() serialized with the same format and method/route ARN as the normal path
    • APIGatewayCustomAuthorizerV2SimpleResponse: IsAuthorized = false
    • APIGatewayCustomAuthorizerResponse / APIGatewayCustomAuthorizerV2IamResponse: an explicit Deny policy
    • Any other type: throw new Exception("Unauthorized")
  • The __bindingFailed__ declaration and the deny check are both emitted only when HasBoundParameters() is true. If you add a new binding source, such as a new [From*] attribute or a new conversion branch, update HasBoundParameters(). If you forget, the generated code fails to compile because the flag is set but never declared. That's loud, but it fails in customer builds too.
  • The dangerous mistake is a new conversion catch that doesn't set __bindingFailed__. That silently fails open and nothing catches it unless a test sends a malformed value.
Checklist for Binding Changes

When adding or changing any code path that converts a client-supplied value:

  1. Confirm the catch block changes the outcome of the request (validation error, 401 or deny) and doesn't only log.
  2. For authorizers, confirm the catch sets __bindingFailed__ = true; and that HasBoundParameters() covers the new parameter source.
  3. Quick audit of the authorizer template. The three counts should match:
    grep -c "Convert.ChangeType" Templates/AuthorizerSetupParameters.tt
    grep -c "catch (Exception e)" Templates/AuthorizerSetupParameters.tt
    grep -c "__bindingFailed__ = true;" Templates/AuthorizerSetupParameters.tt
  4. Add a runtime test with a malformed value (for example abc and an overflowing number for a long). It should assert that the user's method is not invoked and that the response is a 400, 401 or deny as appropriate. Extend AuthorizerBindingFailureTests.cs for authorizers.
  5. Remember that existing snapshot tests mostly use string parameters, which can't fail conversion. Snapshots alone don't prove the failure path works, so the runtime test in step 4 is required.

Change Files

Every change needs an AutoVer change file (see CONTRIBUTING.md). Run from the repository root:

autover change --project-name "Amazon.Lambda.Annotations" -m "<changelog message>"

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/lambda-annotations of aws/aws-lambda-dotnet.

Open the folder on GitHubat commit c801451

Compare with similar skills

Lambda Annotations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Lambda Annotations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Lambda Annotations this skillaws/aws-lambda-dotnet1.7k—~1.7kAutomated safety check: PassApache-2.0
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT
Processing S3 Uploads With Step Functionsaws/agent-toolkit-for-aws2.8k—~4kAutomated safety check: PassApache-2.0
AWS Serverlessdavila7/claude-code-templates33k7 repos~2kAutomated safety check: PassMIT
AWS Lambda Microvmsawslabs/agent-plugins9161 repos~4.1kAutomated safety check: PassApache-2.0
AWS Step Functionsaws/agent-toolkit-for-aws2.8k—~3.4kAutomated safety check: PassApache-2.0

Similar skills

  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Backend & APIsAuto-check passed
  • AWS Serverless

    davila7/claude-code-templates

    Specialized skill for building production-ready serverless applications on AWS.

    33k GitHub starsUsed in 7 repos~2k tokens
    Backend & APIsAuto-check passed
  • AWS Lambda Microvms

    awslabs/agent-plugins

    Official

    Build, run, debug, and operate applications on AWS Lambda MicroVMs — Firecracker-isolated, snapshot-resumable serverless compute environments that run inside a container with up to 8-hour lifetimes.

    916 GitHub starsUsed in 1 repo~4.1k tokens
    Backend & APIsAuto-check passed
  • AWS Step Functions

    aws/agent-toolkit-for-aws

    Official

    Authors and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses and structures state types (Task, Choice, Map, Parallel, Pass, Wait, Succeed, Fail).

    2.8k GitHub stars~3.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • AWS Lambda Durable Functions

    awslabs/agent-plugins

    Official

    Build resilient, long-running, multi-step applications with AWS Lambda durable functions with automatic state persistence, retry logic, and orchestration for long-running executions.

    916 GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from aws/aws-lambda-dotnet

  • New Event Source

    aws/aws-lambda-dotnet

    Official

    Add a new AWS event source attribute (e.g., Kinesis, Kafka, MQ) to the Lambda .NET Annotations framework, including the attribute class, source generator integration, CloudFormation writer, unit…

    1.7k GitHub stars~3k tokensUpdated today
    Auto-check passed

Categories

Questions about Lambda Annotations

What does Lambda Annotations do?

Conventions and safety rules for changing the Amazon.Lambda.Annotations library and its source generator, including the T4 templates that generate Lambda handler code. Lambda Annotations is an agent skill from aws/aws-lambda-dotnet, published by the product's own GitHub organization.Annotations library and its source generator, including the T4 templates that generate Lambda handler code.

When should I use Lambda Annotations?

Lambda Annotations fits situations like: modifying parameter binding; generated handler code; authorizer support; the source generator templates.

How do I install Lambda Annotations in Claude Code?

Run `npx skills add aws/aws-lambda-dotnet --skill lambda-annotations -a claude-code`. Or copy the skill folder (.agents/skills/lambda-annotations in aws/aws-lambda-dotnet) into .claude/skills/lambda-annotations in your project. Claude Code loads it when a task matches its description.

How do I install Lambda Annotations in Codex?

Run `npx skills add aws/aws-lambda-dotnet --skill lambda-annotations -a codex`. Or copy the skill folder (.agents/skills/lambda-annotations in aws/aws-lambda-dotnet) into .agents/skills/lambda-annotations in your project. Codex loads it when a task matches its description.

Can I use Lambda Annotations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/aws-lambda-dotnet --skill lambda-annotations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/lambda-annotations, .gemini/skills/lambda-annotations, .github/skills/lambda-annotations and .opencode/skills/lambda-annotations in your project.

What does Lambda Annotations need to run?

Going by SKILL.md and its folder, Lambda Annotations needs the command-line tools its instructions call (dotnet).

Does Lambda Annotations access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Lambda Annotations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Lambda Annotations use?

Lambda Annotations is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Lambda Annotations use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Lambda Annotations?

Skills that share tags, products or a category with Lambda Annotations: AWS Serverless Eda (zxkane/aws-skills, 367 stars), Processing S3 Uploads With Step Functions (aws/agent-toolkit-for-aws, 2.8k stars), AWS Serverless (davila7/claude-code-templates, 33k stars) and AWS Lambda Microvms (awslabs/agent-plugins, 916 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Lambda Annotations?

aws (a GitHub organization, an official publisher) maintains it in aws/aws-lambda-dotnet, which has 1,661 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 10, 2026.

Source: aws/aws-lambda-dotnet on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.