Neon Functions
neondatabase/agent-skills
Long-running, serverless Node.js HTTP functions deployed onto your Neon branch, with DATABASEURL injected automatically and compute that runs next to your data.
Enables Redshift system-table (SYS) log publishing to S3 Tables in Apache Iceberg format for both Provisioned clusters and Serverless namespaces, verifies publishing status, and queries the…
$ npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/agent-toolkit-for-aws querying-aws-redshift --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/system-table-skills/querying-aws-redshift .claude/skills/querying-aws-redshift && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "querying-aws-redshift" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/system-table-skills/querying-aws-redshift into .claude/skills/querying-aws-redshift/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "querying-aws-redshift", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/system-table-skills/querying-aws-redshiftType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/agent-toolkit-for-aws querying-aws-redshift --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/specialized-skills/system-table-skills/querying-aws-redshift .agents/skills/querying-aws-redshift && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "querying-aws-redshift" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/system-table-skills/querying-aws-redshift into .agents/skills/querying-aws-redshift/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "querying-aws-redshift", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/agent-toolkit-for-aws querying-aws-redshift --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/specialized-skills/system-table-skills/querying-aws-redshift .cursor/skills/querying-aws-redshift && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "querying-aws-redshift" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/system-table-skills/querying-aws-redshift into .cursor/skills/querying-aws-redshift/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "querying-aws-redshift", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/agent-toolkit-for-aws.git --path skills/specialized-skills/system-table-skills/querying-aws-redshift--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/agent-toolkit-for-aws querying-aws-redshift --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/specialized-skills/system-table-skills/querying-aws-redshift .gemini/skills/querying-aws-redshift && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "querying-aws-redshift" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/system-table-skills/querying-aws-redshift into .gemini/skills/querying-aws-redshift/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "querying-aws-redshift", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/agent-toolkit-for-aws querying-aws-redshiftInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/specialized-skills/system-table-skills/querying-aws-redshift .github/skills/querying-aws-redshift && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "querying-aws-redshift" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/system-table-skills/querying-aws-redshift into .github/skills/querying-aws-redshift/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "querying-aws-redshift", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/agent-toolkit-for-aws querying-aws-redshift --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/specialized-skills/system-table-skills/querying-aws-redshift .opencode/skills/querying-aws-redshift && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "querying-aws-redshift" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/system-table-skills/querying-aws-redshift into .opencode/skills/querying-aws-redshift/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "querying-aws-redshift", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
querying-aws-redshiftEnables Redshift system-table (SYS) log publishing to S3 Tables in Apache Iceberg format for both Provisioned clusters and Serverless namespaces, verifies publishing status, and queries the…
Querying AWS Redshift is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Enables Redshift system-table (SYS) log publishing to S3 Tables in Apache Iceberg format for both Provisioned clusters and Serverless namespaces, verifies publishing status, and queries the published logs via any Iceberg-compatible engine including Redshift and Athena. Covers system tables such as sysqueryhistory, sysquerytext, sysconnectionlog, sysquerydetail, and syssessionhistory. Applies when turning on S3 Tables log publishing for a cluster or namespace, confirming publishing status and locating the S3…
Its SKILL.md is about 5.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/example-queries.md`, `references/permissions-setup.md` and `references/security.md`).
It sits in Backend & APIs, covering Data warehousing, File uploads and storage and Serverless. It works with Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awsFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Querying AWS Redshift loads about 5.9k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 255 tokens; SKILL.md has 2,368 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 2,368 words, ~5,860 tokens.
.claude/skills/querying-aws-redshift/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Works best with the AWS MCP server for sandboxed execution and audit logging. All commands below use the AWS CLI and work in any environment with configured AWS credentials. Use IAM roles or temporary credentials; avoid long-lived access keys.
Redshift can publish system tables — the SYS_* monitoring data such as sys_query_history, sys_query_detail, and sys_connection_log — to S3 Tables as continuously-updated Apache Iceberg tables.
Terminology used throughout: system table refers to a SYS_* dataset generally, and each one maps 1:1 to a published Iceberg table. Where this skill says SYS_ view, it means specifically the live in-cluster object you query on the cluster itself — that is a view, and it is a different thing from the published S3 Tables copy. This applies to both Provisioned clusters and Serverless namespaces. It is an opt-in extension of the existing logging APIs. Published tables are read-only, stored in the AWS-managed aws-redshift table bucket, and queryable via any Iceberg-compatible engine including Amazon Athena and Amazon Redshift itself.
Querying the S3 Tables copy is preferred over the live in-cluster SYS_ views when analyzing historical or high-volume system-table data because:
SYS_ views have a limited retention window; S3 Tables retains history well beyond it.| User intent | Use this skill? | Alternative |
|---|---|---|
| Turn on S3 Tables log publishing for a cluster or namespace | Yes | — |
| Confirm a cluster/namespace is publishing / find its S3 Tables namespace | Yes | — |
| Querying non-realtime data from Redshift system tables | Yes | — |
| Build daily/weekly/monthly dashboard for Redshift monitoring and auditing | Yes | — |
| Selectively stop S3 Tables publishing | Yes | — |
| Query published system tables from Redshift (cross-database) | Yes | — |
| Query published system tables from Athena | Yes | — |
Inspect the current, real-time SYS_ state on a live cluster | No | Query the SYS_ view on the cluster directly |
| Query data inside customer tables | No | Direct Redshift SQL on the cluster |
| Compute type | Enable / disable API | Status API | Granularity options |
|---|---|---|---|
| Redshift Provisioned cluster | redshift enable-logging / redshift disable-logging | redshift describe-logging-status | cluster (default), account |
| Redshift Serverless namespace | redshift-serverless update-namespace with --s3-table-action Enable/Disable | redshift-serverless get-namespace | namespace (default), account |
Both compute types publish into the same AWS-managed aws-redshift table bucket and are queried identically once published. They differ only in the enable/disable API surface and in the casing of the status response — see the flag and field tables in Common Tasks.
Not covered by this skill: Redshift audit logs delivered to S3 or CloudWatch (useractivitylog, userlog, connectionlog), which use the separate --log-exports mechanism on Serverless and are not SYS_* system tables.
Before querying, confirm the cluster or namespace is publishing to S3 Tables.
# Provisioned
aws redshift describe-logging-status --region <REGION> --cluster-identifier <CLUSTER_ID>
# Serverless
aws redshift-serverless get-namespace --region <REGION> --namespace-name <NAMESPACE_NAME>Interpret the response. The two compute types return the same information under different field names and casing — Provisioned uses PascalCase under S3Tables, Serverless uses camelCase under namespace.s3TablePublishStatus:
| Meaning | Provisioned (describe-logging-status) | Serverless (get-namespace) |
|---|---|---|
| Not enabled | LoggingEnabled: false or no S3Tables block | no s3TablePublishStatus block |
| Destination includes S3 Tables | LogDestinationType contains s3table | logDestinationType contains s3table |
List of published SYS_* tables | S3Tables.S3Tables | namespace.s3TablePublishStatus.s3Tables |
| The exact S3 Tables namespace (required for querying) | S3Tables.S3TableNamespace | namespace.s3TablePublishStatus.s3TableNamespace |
| Granularity | S3Tables.S3TableGranularity (cluster/account) | namespace.s3TablePublishStatus.s3TableGranularity (namespace/account) |
| Per-table last ingest time | S3Tables.LastIngestionTimes | namespace.s3TablePublishStatus.lastIngestionTimes |
| All available system tables published | S3Tables.EnabledAll | namespace.s3TablePublishStatus.enabledAll |
Notes:
LogDestinationType is a comma-joined list when more than one destination is active — e.g. "cloudwatch,s3table". Test with a substring/contains check, not equality against s3table.LastIngestionTimes / lastIngestionTimes map, or a table listed as published but absent from the map, means data for that table may still be in flight. Compare successive values to confirm new data is landing.logExports field for this feature — that field carries the CloudWatch/S3 audit logs (useractivitylog, userlog, connectionlog) and is unrelated to SYS_* S3 Tables publishing.# Provisioned
aws redshift enable-logging --region <REGION> --cluster-identifier <CLUSTER_ID> --log-destination-type s3table --log-exports <SYS_TABLE>... --s3-table-granularity <cluster|account> --s3-table-kms-key-id <KMS_KEY_ARN>
# Serverless
aws redshift-serverless update-namespace --region <REGION> --namespace-name <NAMESPACE_NAME> --log-destination-type s3table --s3-table-names <SYS_TABLE>... --s3-table-action Enable --s3-table-granularity <namespace|account> --s3-table-kms-key-id <KMS_KEY_ARN>--s3-table-kms-key-id is part of both commands deliberately, not an optional add-on. Omitting it does not fail — the tables fall back to an AWS-owned key you cannot audit, restrict by policy, or revoke. Because SYS_* tables carry query_text, user_name, and remote_host, treat the customer-managed key as the default and drop the flag only for throwaway environments.
Enable from AWS console Amazon Redshift Console > Clusters > select your cluster > Tabs > Integrations / System table integration
The two compute types take different flags for the same feature. Do not carry Provisioned flag names over to Serverless:
| Purpose | Provisioned (enable-logging) | Serverless (update-namespace) |
|---|---|---|
| Which system tables to publish | --log-exports | --s3-table-names |
| Enable vs disable | separate enable-logging / disable-logging operations | --s3-table-action Enable | Disable |
| Granularity | --s3-table-granularity cluster | account | --s3-table-granularity namespace | account |
| Customer-managed KMS key | --s3-table-kms-key-id | --s3-table-kms-key-id |
| Validate without applying | --dry-run | --dry-run |
Notes:
cluster (default) or account; Serverless supports namespace (default) or account.cluster/namespace granularity → one S3 table per cluster/namespace; account → one shared table for all clusters/namespaces per account per region.all to publish all available SYS_* tables — --log-exports all on Provisioned, --s3-table-names all on Serverless.--s3-table-kms-key-id the published tables are encrypted with an AWS-owned key, which you cannot audit, restrict by policy, or revoke. SYS_* tables carry query_text, user_name, and remote_host (see Security Considerations), so pass a customer-managed key. Grant key access using the complete key policy in ${SKILL_DIR}/references/security.md rather than an abbreviated action list — it needs two service principals (systemtables.redshift.amazonaws.com for publishing and maintenance.s3tables.amazonaws.com for table maintenance/compaction). Provisioning only the publishing principal lets writes succeed while compaction silently fails.--dry-run to validate the request without changing anything. Provisioned returns a DryRunOperation error on success ("Request would have succeeded, but DryRun flag is set"); Serverless returns an empty body and exit code 0. Note that the Serverless dry-run validates request shape only, not parameter values, so a successful dry-run there does not guarantee the values are accepted.Disable selectively:
# Provisioned
aws redshift disable-logging --region <REGION> --cluster-identifier <CLUSTER_ID> --log-destination-type s3table --log-exports <SYS_TABLE>...
# Serverless
aws redshift-serverless update-namespace --region <REGION> --namespace-name <NAMESPACE_NAME> --log-destination-type s3table --s3-table-names <SYS_TABLE>... --s3-table-action DisableFull setup commands for both paths: ${SKILL_DIR}/references/permissions-setup.md. Load it before creating roles or registering resources.
Athena path — needs the s3tablescatalog/aws-redshift catalog registered in Glue, a workgroup with an output location, and S3 Tables read permissions. Confirm the catalog is queryable:
aws glue get-databases --region <REGION> \
--catalog-id "<ACCOUNT>:s3tablescatalog/aws-redshift"Namespaces returned → registered and queryable. EntityNotFoundException / CATALOG_NOT_FOUND → the S3 Tables integration is not enabled (S3 console > Table buckets > Enable integration). Encrypt the workgroup output location — Athena writes full result sets, including query_text and user_name, to S3.
Redshift auto-mount path — needs a Provisioned RA3 cluster and a four-step setup: create the query_s3_tables role (trust policy must name both redshift.amazonaws.com and lakeformation.amazonaws.com, the latter with all four of sts:AssumeRole, sts:SetContext, sts:SetSourceIdentity, sts:TagSession), attach it to the cluster, register the table bucket with Lake Formation, and add the Redshift service-linked roles to ReadOnlyAdmins. Constraints that cause most failures:
aws:SourceAccount — a bare service principal is a confused-deputy risk.AWSLakeFormationDataAdmin to the cluster's query role. It is needed only by the principal performing setup, and only during setup. The cluster's role needs read access alone.pg_database. A cluster reboot forces immediate discovery.Namespace — resolve it from the API, do not construct it:
S3Tables.S3TableNamespace from describe-logging-status (Provisioned) or s3TablePublishStatus.s3TableNamespace from get-namespace (Serverless) and use it verbatim.<namespace_arn_id>_sys for cluster/namespace granularity and <account>_sys for account granularity. Use this only to verify the value looks right — never to generate the namespace when the API response is unavailable.Table — each publishable system table maps 1:1 to a table in the aws-redshift table bucket. Do not work from a memorized list — resolve it at runtime, in this order:
S3Tables.S3Tables (Provisioned) or s3TablePublishStatus.s3Tables (Serverless) from the status call above, e.g. sys_query_history. This is the only authoritative answer to "what can I query right now".aws redshift enable-logging help (accepted --log-exports values) or aws redshift-serverless update-namespace help (accepted --s3-table-names values).SYS_* view and its columns. AWS adds views over time, so treat the docs as the current list rather than hardcoding one.Column names and types come from the same public reference, or from the live table:
aws glue get-table --region <REGION> \
--catalog-id "<ACCOUNT>:s3tablescatalog/aws-redshift" \
--database-name "<NAMESPACE>" --name "<SYS_TABLE>"Two caveats when reading the public docs against a published table: enum-valued columns (query_type, status, event) gain values over time, so confirm with SELECT DISTINCT rather than filtering on an assumed set; and the published Iceberg table prepends warehouse-identity columns (warehouse_name, warehouse_namespace_arn, and peers) that the in-cluster SYS_ view does not have — they are how you tell apart multiple clusters publishing at account granularity.
Query syntax:
"s3tablescatalog/aws-redshift"."<NAMESPACE>"."<SYS_TABLE>"Once the auto-mounted catalog is set up (see ${SKILL_DIR}/references/permissions-setup.md), query using cross-database notation:
"aws-redshift@s3tablescatalog"."<NAMESPACE>".<SYS_TABLE>Alternatively, create an external schema pointing to the S3 Tables catalog:
CREATE EXTERNAL SCHEMA <schema_name>
FROM DATA CATALOG
DATABASE '<NAMESPACE>'
CATALOG_ID '<ACCOUNT>:s3tablescatalog/aws-redshift'
IAM_ROLE 'arn:aws:iam::<ACCOUNT>:role/query_s3_tables'
REGION '<REGION>';
SELECT * FROM <schema_name>.<SYS_TABLE> LIMIT 10;describe-logging-status or get-namespace to get the namespace before writing any SQL query — never construct it manually1000000.0 for secondsINSERT/UPDATE/DELETELIMIT when the user doesn't specify one; filter on start_time/record_time where possibleWorked SQL for the common asks — longest-running queries, error analysis, connection auditing, queue-time trends, cross-table joins — is in ${SKILL_DIR}/references/example-queries.md. Two rules that apply to every one of them:
elapsed_time as-is overstates durations by 10^6.year/month/day or the table's own partitioning) in addition to any timestamp predicate, or the engine scans the full history.| Scenario | Use |
|---|---|
| Historical/high-volume log analysis, no cluster load | Athena or Redshift on S3 Tables |
| Already connected to a Redshift cluster, want to query S3 Tables logs | Redshift cross-database or external schema |
| Join system table logs with other lake data | Athena or Redshift Spectrum |
| Real-time current state of the cluster | Direct SYS_ view on the cluster |
| Quick ad-hoc query without Redshift cluster access | Athena |
describe-logging-status (S3Tables.S3TableNamespace) or get-namespace (s3TablePublishStatus.s3TableNamespace); never construct it manuallyaws-redshift), different enable APIs| Error | Cause | Fix |
|---|---|---|
aws-redshift bucket not found | S3 Tables integration not enabled or logging not started | Run enable-logging (Provisioned) or update-namespace (Serverless) with --log-destination-type s3table |
CATALOG_NOT_FOUND in Athena | S3 Tables not registered in Glue | Enable integration: S3 console > Table buckets > Enable integration |
| Athena table empty after enabling | Ingestion still in flight | Check LastIngestionTimes (Provisioned) / lastIngestionTimes (Serverless); wait and re-query |
SYS_* table missing from the namespace | System table not included when enabling | Re-run enable with that table included, or use all — --log-exports (Provisioned), --s3-table-names (Serverless) |
| Wrong / empty namespace | Namespace constructed instead of read from API | Use the namespace from the describe/get response — S3Tables.S3TableNamespace (Provisioned) or s3TablePublishStatus.s3TableNamespace (Serverless) |
Status response has no S3Tables / s3TablePublishStatus field at all, even though publishing is on | Outdated AWS CLI / SDK. The field is silently omitted rather than raising an error, so this looks identical to the feature being disabled | Upgrade the CLI/SDK, then re-run. Confirm publishing is actually off before acting on the absence — check the aws-redshift table bucket for the namespace, or that LogDestinationType includes s3table |
Unknown options: --log-exports, --log-export-action on Serverless | Provisioned flag names used against update-namespace | Use --s3-table-names and --s3-table-action — see the flag table in the Enable section |
AccessDenied querying the table | Missing s3tables:GetTable or GetTableData | See references/security.md |
Empty results from sys_connection_log | Querying identity lacks visibility | Use an identity with superuser-level access |
Catalog doesn't appear in pg_database | LF resource not registered, or SLRs not ReadOnlyAdmins | Complete the Lake Formation steps in references/permissions-setup.md, wait 5 min or reboot |
| "Unable to assume role" from Glue | Missing sts:SetContext/sts:SetSourceIdentity in trust policy, or missing AWSLakeFormationDataAdmin | Fix trust policy and attach AWSLakeFormationDataAdmin |
VerificationStatus: NOT_VERIFIED | Normal after Lake Formation registration | No action needed if queries work |
| Query fails with "does not exist" in Redshift | Catalog not yet auto-mounted (poll delay) | Wait up to 300s or reboot cluster |
Full policies, key policy, and detection setup: ${SKILL_DIR}/references/security.md. Read it before granting access. The non-negotiables:
s3tablescatalog/aws-redshift — the bare database/* form grants metadata read on the whole account. lakeformation:GetDataAccess is the one action that must use "Resource": "*"; constrain it with an aws:ResourceAccount StringEquals condition.systemtables.redshift.amazonaws.com (publisher) and maintenance.s3tables.amazonaws.com (compaction). Granting only the publisher lets writes succeed while compaction silently fails.query_text can contain credentials, not just schema — interpolated SQL and CREATE USER ... PASSWORD land verbatim in sys_query_history. Treat broad access to that table as a secrets-exposure decision; restrict the column with Lake Formation.s3tables.amazonaws.com AccessDenied spikes and sys_connection_log failed-auth counts are the two signals to alert on; encrypt the alarm topic with a customer-managed key.${SKILL_DIR} is the absolute path of the directory containing this SKILL.md. Load these on demand; do not read them all up front.
| File | What it covers | When to load |
|---|---|---|
${SKILL_DIR}/references/permissions-setup.md | Athena prerequisites and workgroup encryption; the full Redshift auto-mount path — IAM role trust/inline policies, Lake Formation register-resource, put-data-lake-settings, the SLR ReadOnlyAdmins step, and the 300s auto-mount poll | Before running any IAM or Lake Formation setup |
${SKILL_DIR}/references/example-queries.md | Worked SQL for longest-running queries, error analysis, connection auditing, queue-time trends, and joins across sys_* tables | When writing queries against the published tables |
${SKILL_DIR}/references/security.md | Full least-privilege policy, KMS key policy with both service principals, query_text sensitivity, CloudTrail/metric-filter detection | Before granting access, or when hardening an existing setup |
Security best practices:
lakeformation:GetDataAccess requires "Resource": "*"© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/specialized-skills/system-table-skills/querying-aws-redshift of aws/agent-toolkit-for-aws.
Open the folder on GitHubat commit 188af2f
Querying AWS Redshift next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Querying AWS Redshift this skillaws/agent-toolkit-for-aws | 2.8k | — | ~5.9k | Automated safety check: Pass | Apache-2.0 | |
| Neon Functionsneondatabase/agent-skills | 100 | — | ~12k | Automated safety check: Notes | Apache-2.0 | |
| Msk Operationsaws/tools-for-devops-agent | 100 | — | ~6.6k | Automated safety check: Pass | Apache-2.0 | |
| Redshift Support Specialistaws/tools-for-devops-agent | 100 | — | ~7.3k | Automated safety check: Pass | Apache-2.0 | |
| AWS Advisordiegosouzapw/awesome-omni-skills | 159 | — | ~4.3k | Automated safety check: Pass | MIT | |
| Edgeone Makers StorageTencentEdgeOne/edgeone-makers-tools | 1.9k | 1 repos | ~930 | Automated safety check: Pass | MIT |
neondatabase/agent-skills
Long-running, serverless Node.js HTTP functions deployed onto your Neon branch, with DATABASEURL injected automatically and compute that runs next to your data.
aws/tools-for-devops-agent
Amazon MSK Provisioned operations, troubleshooting, and health assessment for Standard and Express brokers.
aws/tools-for-devops-agent
Amazon Redshift domain expertise for query optimization, operational reviews, and cost optimization on provisioned clusters and Serverless workgroups.
diegosouzapw/awesome-omni-skills
AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.
TencentEdgeOne/edgeone-makers-tools
KV and Blob storage services on EdgeOne Makers. An agent skill from TencentEdgeOne/edgeone-makers-tools.
majiayu000/claude-skill-registry
Configure S3 buckets, policies, and lifecycle rules. An agent skill from majiayu000/claude-skill-registry.
aws/agent-toolkit-for-aws
Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.
aws/agent-toolkit-for-aws
A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.
aws/agent-toolkit-for-aws
Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.
aws/agent-toolkit-for-aws
Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.
aws/agent-toolkit-for-aws
Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…
aws/agent-toolkit-for-aws
A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.
Works with
Categories
Enables Redshift system-table (SYS) log publishing to S3 Tables in Apache Iceberg format for both Provisioned clusters and Serverless namespaces, verifies publishing status, and queries the…. Querying AWS Redshift is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Enables Redshift system-table (SYS) log publishing to S3 Tables in Apache Iceberg format for both Provisioned clusters and Serverless namespaces, verifies publishing status, and queries the published logs via any Iceberg-compatible engine including Redshift and Athena.
Querying AWS Redshift fits situations like: phrases: publish redshift system table log to s3 tables; enable-logging s3 tables; describe redshift logging status; query redshift system tables in athena.
Run `npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a claude-code`. Or copy the skill folder (skills/specialized-skills/system-table-skills/querying-aws-redshift in aws/agent-toolkit-for-aws) into .claude/skills/querying-aws-redshift in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a codex`. Or copy the skill folder (skills/specialized-skills/system-table-skills/querying-aws-redshift in aws/agent-toolkit-for-aws) into .agents/skills/querying-aws-redshift in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill querying-aws-redshift -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/querying-aws-redshift, .gemini/skills/querying-aws-redshift, .github/skills/querying-aws-redshift and .opencode/skills/querying-aws-redshift in your project.
Going by SKILL.md and its folder, Querying AWS Redshift needs the command-line tools its instructions call (aws).
SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Querying AWS Redshift is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.9k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Querying AWS Redshift: Neon Functions (neondatabase/agent-skills, 100 stars), Msk Operations (aws/tools-for-devops-agent, 100 stars), Redshift Support Specialist (aws/tools-for-devops-agent, 100 stars) and AWS Advisor (diegosouzapw/awesome-omni-skills, 159 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.
Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.