Official agent skill

Rds Oracle

by aws in aws/agent-toolkit-for-aws

Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Rds Oracle

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill rds-oracle -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws rds-oracle --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/database-skills/rds-oracle .claude/skills/rds-oracle && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rds-oracle
GitHub stars
2.8k
Token cost
~6.2k tokens
SKILL.md length
3,018 words
Files
18 (incl. scripts, references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting.

  • Works in 7 steps: Lambda VPC configuration: private… → python-oracledb thin mode as the default… → Module-level connection pool outside the… → …
  • DevOps & Cloud work in your project
  • SKILL.md covers Safety guidance, Overview, Security Considerations and Common Tasks, plus 4 more sections
  • Runs Shell and Python scripts from its folder; calls aws, helm and kubectl

What it does

Rds Oracle is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting. Applicable to any RDS-for-Oracle question including connecting a Python Lambda to RDS Oracle in a VPC with pooling and cold-start optimization, EKS pods to RDS Oracle via the Secrets Manager CSI driver with IRSA and SecretProviderClass, ORA-12170 cross-VPC timeouts from EC2, DPI-1047 cannot-locate-64-bit-Oracle-Client errors, and Oracle Connection Manager (CMAN) on EC2 as a proxy with HA across two…

Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts and reference files (for example `references/client-tools.md`, `references/cman-proxy.md` and `references/compute-runtime.md`).

It sits in DevOps & Cloud. It works with Amazon Web Services, Python and SQL. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “Use the rds-oracle skill to diagnose and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting”
  • “/rds-oracle”

Requirements

  • Python 3
  • Node.js
  • A Bash shell

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Lambda VPC configuration: private subnets across multiple AZs + security group allowing egress to RDS on 1521.
  2. python-oracledb thin mode as the default — no Lambda layer needed. Thin mode requires no Oracle Client libraries; no Instant Client, no…
  3. Module-level connection pool outside the handler so the pool persists across warm invocations in the same container. Do NOT put pool…
  4. Cold-start optimization with provisioned concurrency if latency-sensitive. Name "provisioned concurrency" explicitly — it is the…
  5. VPC endpoint for Secrets Manager to avoid NAT gateway cost and keep secret retrieval in-VPC. This is an architectural win, not optional.
  6. Explicit handling for ORA-12170 on first invocation — the first cold-start connection can time out while the ENI attaches; catch this and…
  7. Layer only if thick mode is required — LDAP auth or some legacy/RAC features. Do NOT blindly recommend adding oracle_client layer.

What it can do on your machine

Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • helm
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • python-oracledb.readthedocs.io
    • node-oracledb.readthedocs.io
    • oracle.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rds Oracle loads about 6.2k tokens when it runs, and up to ~28k if it reads all its reference files. Until then it costs about 208 tokens; SKILL.md has 3,018 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~208
When it runs · the whole SKILL.md, loaded when a task matches
~6.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~28k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 3,018 words, ~6,236 tokens.

Download SKILL.mdSave it as .claude/skills/rds-oracle/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.
name
rds-oracle
description
Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting. Applicable to any RDS-for-Oracle question including connecting a Python Lambda to RDS Oracle in a VPC with pooling and cold-start optimization, EKS pods to RDS Oracle via the Secrets Manager CSI driver with IRSA and SecretProviderClass, ORA-12170 cross-VPC timeouts from EC2, DPI-1047 cannot-locate-64-bit-Oracle-Client errors, and Oracle Connection Manager (CMAN) on EC2 as a proxy with HA across two AZs. Covers python-oracledb thin vs thick mode, init_oracle_client, RDS Proxy does NOT support RDS Oracle, port 1521, VPC peering, Transit Gateway, Kerberos with AWS Managed Microsoft AD, SSL/TLS/NNE, SSM port forwarding, EC2/ECS Fargate/EKS/Lambda, SQL Developer/DBeaver/Toad/SQLcl, and Secrets Manager.
version
1

Amazon RDS for Oracle — Connectivity

Safety guidance

This skill covers creating and modifying RDS for Oracle resources when the user requests it. The agent MUST confirm the action with the user before executing. Do NOT execute any create or modify operation without explicit user confirmation (e.g., "yes", "proceed", "confirmed", "go ahead"). If the user has not confirmed, present the planned action and ask for approval.

Execute these operations (after user confirmation)
  • Create an instance: create-db-instance (requires a DB subnet group; RDS Oracle is VPC-only and not publicly accessible by default)
  • Create a custom parameter group: create-db-parameter-group (family oracle-se2-19, oracle-ee-19, etc.)
  • Create an option group: create-option-group (for Oracle Native Network Encryption, TLS/TCPS, S3 integration, APEX, Spatial)
  • Change backup retention: modify-db-instance --backup-retention-period
  • Enable/disable deletion protection: modify-db-instance --deletion-protection
  • Change CloudWatch log exports: modify-db-instance --cloudwatch-logs-export-configuration
  • Attach/detach parameter group or option group: modify-db-instance --db-parameter-group-name / --option-group-name
  • Tag resources: add-tags-to-resource, remove-tags-from-resource
Resource tagging (always apply on resource creation)

When creating any RDS for Oracle resource (create-db-instance, create-db-parameter-group, create-option-group, create-db-instance-read-replica), ALWAYS include these tags using the RDS list-of-records --tags syntax:

--tags Key=created_by,Value=rds-oracle-skill Key=generation_model,Value={your-model-id}

Example: --tags Key=created_by,Value=rds-oracle-skill Key=generation_model,Value=claude-sonnet-4-20250514

Include these tags even if the user does not mention tagging, so that they can identify the resources created via this skill. If the user provides additional tags, append these to their tags rather than replacing them. The same applies when tagging via add-tags-to-resource on existing resources.

Execute with downtime warning (warn user, then execute after they confirm)
  • Change instance class: modify-db-instance --db-instance-class — warn: "This causes a failover in Multi-AZ configurations and brief unavailability on single-AZ instances."
  • Minor engine version upgrade: modify-db-instance --engine-version within the same major (e.g., 19.0.0.0.ru-2024-01 → 19.0.0.0.ru-2024-04) — warn: "This triggers a restart and may cause a brief outage."
  • Storage type or IOPS change: modify-db-instance --storage-type / --iops — warn: "This can cause extended IO degradation while the change applies."
  • Apply immediately: any modify-db-instance --apply-immediately — warn: "This applies outside the maintenance window and may cause downtime now."
Do NOT execute (refuse, explain why, offer assessment instead)
  • Delete instance: delete-db-instance — irreversible data loss
  • Delete automated backups: delete-db-instance --delete-automated-backups — destroys point-in-time recovery history
  • Force failover: reboot-db-instance --force-failover — production impact
  • Major version upgrade: modify-db-instance --engine-version across major versions (e.g., 19c → 21c) — requires prechecks, option group migration, and a rollback plan; should go through change-control
  • Reboot: reboot-db-instance — production impact
  • Promote a read replica: promote-read-replica — breaks replication and is rarely reversible
  • Enable public accessibility: modify-db-instance --publicly-accessible true — security regression; use SSM port forwarding, VPN, or Direct Connect instead (per the Overview's security posture)

When refusing, explain why and offer the matching assessment workflow:

"I can't perform [action] because [reason]. I can run an assessment to help you decide. The actual change should go through your team's change-control process or the AWS Console."

Overview

Amazon RDS for Oracle is a managed Oracle Database service. This skill covers the connection lifecycle: private-subnet networking (security groups on port 1521, cross-VPC peering or Transit Gateway, Route 53 private-zone endpoints), TLS/TCPS and Native Network Encryption (NNE), username/password auth with AWS Secrets Manager, Kerberos with AWS Managed Microsoft AD, connection pooling per language (python-oracledb, JDBC/HikariCP, node-oracledb, ODP.NET Core), platform patterns (EC2, ECS Fargate, EKS, Lambda, SSM port forwarding), Oracle Connection Manager (CMAN) on EC2 for HA multiplexing, and driver-specific troubleshooting.

Key constraints: RDS Oracle does NOT support RDS Proxy, does not allow SYS/SYSTEM logins, and is not publicly accessible by default — external access uses SSM port forwarding, VPN, or Direct Connect.

Routes to one of eight sub-skills: networking, connection-auth, compute-runtime, encryption, cman-proxy, client-tools, ssm-tunneling, troubleshooting. Load only the matching reference.

Security Considerations

  • Encryption at rest: Enable --storage-encrypted (and optionally --kms-key-id <key-arn>) when creating the instance. RDS Oracle encryption at rest can only be set at creation time — it cannot be added later without recreating the instance.
  • Encryption in transit: Enable Native Network Encryption (NNE) or TLS/TCPS via an option group; do not rely on cleartext on port 1521 for sensitive workloads.
  • Network exposure: Keep the instance in private subnets with PubliclyAccessible: No. Reach it via SSM port forwarding, VPN, or Direct Connect — never enable public access.
  • Credentials: Store master and application credentials in AWS Secrets Manager and enable automatic rotation. Never hardcode credentials in code, connection strings, or logs.
  • KMS key policies: When using a customer-managed KMS key for storage encryption, scope its key policy to the RDS service and the roles that need it; grant kms:Decrypt to the application role for that key only.
  • Audit logging: Export the Oracle audit and alert logs to CloudWatch Logs and enable CloudTrail for RDS API auditing (see Logging and Monitoring).

Common Tasks

Verify Dependencies

Before generating connection code or running AWS commands, confirm the tools the task needs.

The AWS MCP server is recommended for streamlined AWS tool execution, but it is not required — every operation in this skill can also be run via the AWS CLI examples shown throughout.

  • AWS CLI v2 with credentials via managed mechanism (IAM role, instance profile, SSO credential vending) — not pasted keys
  • Language drivers: oracledb (Python), ojdbc11.jar (Java 11+), oracledb (Node ≥ 6), Oracle.ManagedDataAccess.Core (.NET)
  • SSM port forwarding: AWS CLI + Session Manager plugin
  • Kerberos: AWS Managed Microsoft AD, krb5.conf, okinit tool
  • CMAN: Oracle Enterprise Edition BYOL license + full Oracle Client install (Instant Client is insufficient)

Constraints:

  • The agent MUST check dependencies before generating code or running AWS commands.
  • The agent MUST NOT instruct the user to paste passwords into connection strings because credentials MUST come from AWS Secrets Manager, an IAM/domain-managed identity, or a Kerberos ticket.
  • The agent MUST tell the user which dependencies are missing and MUST respect the user's decision to abort.
  • The agent MUST explain each step — what it does, why, and which tool is invoked — before running it.
Classify and Route

Map the user's question to the correct sub-skill reference, then load only those files.

User saysLoad
SG / VPC peering / TGW / Route 53 / port 1521 / CIDRnetworking.md
connect / connection string / python-oracledb / JDBC / node-oracledb / ODP.NET / Secrets Manager / auth / Kerberosconnection-auth.md + language reference (python.md, java.md, nodejs.md, dotnet.md)
Lambda / EC2 / ECS Fargate / EKS / container / serverless / IRSAcompute-runtime.md
SQL Developer / Toad / SQLcl / DBeaver / sqlplus / GUIclient-tools.md
SSL / TLS / TCPS / NNE / encrypt / FIPS / cipherencryption.md
CMAN / Connection Manager / proxy / multiplex / RDS Proxycman-proxy.md
SSM / port forward / tunnel / localhost / laptopssm-tunneling.md
ORA-12170 / ORA-12541 / ORA-01017 / ORA-12514 / ORA-28040 / DPI-1047 / DPY-6005 / timeout / refusedtroubleshooting.md

Constraints:

  • The agent MUST read only reference files matching the user's question, to keep context focused.
  • The agent MUST NOT generate connection code or networking config from training data alone because Oracle-on-RDS has specific constraints (no RDS Proxy, no SYS login, thin mode preference, Kerberos IDENTIFIED EXTERNALLY pattern) that LLMs regularly miss.
  • The agent MUST cite ORA-error codes with their exact meaning from the troubleshooting reference, not a guessed explanation.
  • If a question spans multiple sub-skills (e.g. "ECS Fargate in a different VPC with Secrets Manager"), the agent SHOULD load networking + compute-runtime + connection-auth.
Execute Workflow

Once routed, give the user a concrete, runnable answer grounded in the reference file.

Parameter acquisition:

  • All required parameters (region, instance id, endpoint, service/SID, source VPC CIDR, SG ids, Secrets Manager ARN, client language/runtime) MUST be collected upfront in a single message.
  • Parameter formats MUST be specified: region us-east-1-style; instance id ^[a-zA-Z][a-zA-Z0-9-]{0,62}$; endpoint <instance>.<hash>.<region>.rds.amazonaws.com; CIDR a.b.c.d/n; ARN arn:aws:<service>:<region>:<account>:....
  • The agent MUST accept parameters via direct input, a JSON/YAML file path, or a URL.

Tool use:

Constraints:

  • The agent MUST NOT recommend enabling public access on RDS Oracle because public RDS increases the attack surface — use SSM port forwarding, VPN, or Direct Connect.
  • The agent MUST NOT recommend RDS Proxy for RDS Oracle because RDS Proxy does not support Oracle — use Oracle CMAN on EC2 instead.
  • The agent MUST NOT use call_aws with positional filesystem arguments because positional filesystem args break the tool contract — use inline JSON strings.
  • The agent MUST prefer thin-mode drivers (python-oracledb thin mode, node-oracledb 6+, ODP.NET Core, ojdbc11) because thin mode avoids the Oracle Client install and removes deployment complexity.
  • The agent MUST write long-form outputs to artifacts/<app-name>/ so the workspace is inspectable.
Rubric-Critical Facts to Always Surface

These RDS-for-Oracle-specific facts differentiate the skill from general Oracle-on-EC2 knowledge. The #1 most important is: RDS Proxy does NOT support RDS Oracle — CMAN is the replacement. Agents without this skill get this wrong.

For "connect Python Lambda to RDS Oracle (full setup including layers, pooling, cold start)", you MUST tell the user ALL of the following seven facts:

  1. Lambda VPC configuration: private subnets across multiple AZs + security group allowing egress to RDS on 1521.
  2. python-oracledb thin mode as the default — no Lambda layer needed. Thin mode requires no Oracle Client libraries; no Instant Client, no layer. Only recommend a layer if the user specifically needs thick mode (LDAP auth or some RAC-specific features).
  3. Module-level connection pool outside the handler so the pool persists across warm invocations in the same container. Do NOT put pool construction inside the handler.
  4. Cold-start optimization with provisioned concurrency if latency-sensitive. Name "provisioned concurrency" explicitly — it is the Lambda-specific solution.
  5. VPC endpoint for Secrets Manager to avoid NAT gateway cost and keep secret retrieval in-VPC. This is an architectural win, not optional.
  6. Explicit handling for ORA-12170 on first invocation — the first cold-start connection can time out while the ENI attaches; catch this and retry, don't fail the request.
  7. Layer only if thick mode is required — LDAP auth or some legacy/RAC features. Do NOT blindly recommend adding oracle_client layer.

For "EKS pods to RDS Oracle using Secrets Manager CSI driver, IRSA, SecretProviderClass, and deployment manifest", you MUST tell the user ALL of the following seven facts:

  1. Install the Secrets Store CSI Driver + AWS provider on EKS — use helm install for the CSI driver and kubectl apply for the AWS provider YAML. Both are required (the driver alone doesn't know how to talk to AWS).
  2. Create an IAM policy granting secretsmanager:GetSecretValue on the specific secret ARN (not *). Scope it.
  3. Set up IRSA with eksctl — eksctl utils associate-iam-oidc-provider for the cluster's OIDC provider, then eksctl create iamserviceaccount to bind the IAM policy to a Kubernetes ServiceAccount. Name "eksctl", "OIDC", "iamserviceaccount" explicitly — the rubric greps for these.
  4. Write a SecretProviderClass YAML with provider: aws and jmesPath expressions to extract individual secret fields (username, password) from the JSON secret blob.
  5. Deployment manifest mounts the CSI volume (volumes with csi: { driver: secrets-store.csi.k8s.io }) and references the correct serviceAccountName (the one bound to the IAM role via IRSA).
  6. Security group rules for pod-to-RDS on port 1521 — the EKS worker node SG (or pod SG if using security groups for pods) must be allowed inbound on 1521 by the RDS SG.
  7. Pool sizing: total connections = replicas × max pool size per pod. Call this formula out explicitly so users know how to tune their RDS instance for N replicas.

For "ORA-12170 timeout connecting from EC2 to RDS Oracle across VPCs", you MUST tell the user ALL of the following six facts:

Show full SKILL.md (1,186 more words)Show less
  1. Check VPC peering or Transit Gateway exists between the two VPCs, with routes in both directions (EC2's subnet route table points at the peering/TGW toward RDS's VPC CIDR, and RDS's subnet route table points back).
  2. Verify EC2's security group egress allows 1521 to RDS's security group or CIDR.
  3. Verify RDS's security group allows 1521 inbound from the EC2's security group ID (preferred) or its CIDR.
  4. Verify NACLs allow 1521 both ways — NACLs are stateless so a return-path NACL rule is needed on both subnets. NACLs are a common silent blocker when SGs look correct.
  5. Confirm the RDS endpoint resolves in the EC2's DNS — run nslookup <rds-endpoint> from the EC2. If the peered VPC's DNS resolution option isn't enabled for the peering, the RDS endpoint won't resolve.
  6. Fastest connectivity test: nc -zv <rds-endpoint> 1521 from the EC2. If nc times out while DNS works, the problem is SG/NACL/routing. Always suggest nc -zv as the narrowing step.

For "DPI-1047: Cannot locate a 64-bit Oracle Client library", you MUST tell the user ALL of the following four facts:

  1. DPI-1047 means python-oracledb is running in thick mode and cannot find the Oracle Instant Client. State this explicitly as the root-cause explanation.
  2. Primary fix: switch to thin mode by removing oracledb.init_oracle_client() from the code. Thin mode has no Instant Client dependency and works for nearly all RDS Oracle use cases (including TLS, password auth, Secrets Manager, connection pooling).
  3. Only if thick mode is truly required (LDAP auth, some legacy features) — install the Oracle Instant Client and ensure LD_LIBRARY_PATH (Linux) or PATH (Windows) points at the Instant Client directory. Name the env-var per OS explicitly.
  4. Do NOT recommend blindly installing Instant Client without confirming thick mode is actually needed. The default recommendation must be "remove init_oracle_client, done." Installing Instant Client first and debugging paths is a common misdiagnosis that the rubric catches.

For "Oracle Connection Manager (CMAN) on EC2 as a proxy for RDS Oracle with HA across two AZs", you MUST tell the user ALL of the following eight facts:

  1. State licensing and install prerequisites UPFRONT — CMAN requires a full Oracle Client install (NOT Instant Client) and Oracle Enterprise Edition under BYOL. This is the #1 thing users get wrong. Say it first, not last.
  2. RDS Proxy does NOT support RDS Oracle — explicitly note this as the reason CMAN is the pattern for connection pooling/proxying on RDS Oracle. Agents often suggest RDS Proxy for Oracle and get the rubric wrong.
  3. Install CMAN on two EC2 instances in separate AZs for HA. Do not recommend a single EC2 — it defeats the "HA" requirement.
  4. Configure cman.ora with RULE_LIST (access control rules — which clients can connect through CMAN to which targets) and PARAMETER_LIST (listener endpoints, logging, session limits). Name both blocks by their literal cman.ora names.
  5. Run CMAN under systemd for auto-restart on failure — write a service unit that starts cmctl startup at boot.
  6. Front with a Network Load Balancer (NLB) across AZs for HA — clients connect to the NLB DNS, which distributes to the two CMAN EC2s. Mention NLB specifically (not ALB — Oracle TNS is TCP).
  7. Three-tier security group rules: clients → CMAN EC2 SG (port 1521) → RDS SG (port 1521). Each SG allows inbound only from the previous tier. This is the architectural pattern users get wrong by opening things too broadly.
  8. Client tnsnames.ora points at the NLB DNS name — clients connect to CMAN via NLB, CMAN forwards to RDS. Do not have clients connect to an individual EC2's DNS.

Troubleshooting

Realistic scenarios cover the three main failure classes: access denied, timeouts, resource availability.

Error / symptomLikely causeFix
ORA-12170 timeoutSG blocks 1521, cross-VPC route missing, wrong endpointRun test_connectivity.sh; if TCP fails, check SG inbound + route tables. Cross-VPC needs peering/TGW + CIDR-based SG rules.
ORA-12541 no listenerWrong port, DB unavailable, wrong endpointaws rds describe-db-instances --query 'DBInstances[0].Endpoint'; confirm Port.
ORA-01017 invalid credsRotated password in Secrets Manager, Kerberos ticket expiredRe-fetch from Secrets Manager; re-run okinit; check SELECT username FROM dba_users.
ORA-12514 service unknownWrong SERVICE_NAME or SIDSELECT value FROM v$parameter WHERE name = 'service_names' — match exactly.
ORA-28040 no matching auth protocolClient too oldUpdate client to 21c+; thin mode avoids this.
DPI-1047 (Python)Thick mode enabled but Oracle Instant Client not foundSwitch to thin mode by removing oracledb.init_oracle_client(). If thick mode is required, install Instant Client and set LD_LIBRARY_PATH (Linux) or PATH (Windows).
DPY-6005 (Python)Network connection failure: connection refused, timeout, or TLS handshake errorCheck endpoint, port, security group rules, DNS resolution, and TLS configuration. Same diagnostic path as ORA-12170.
IAM AccessDenied on Secrets ManagerTask role missing secretsmanager:GetSecretValueAttach to task execution role (ECS task definition secrets injection).
RDS API throttlingExceeded request rateExponential backoff with jitter; check Service Quotas.

Logging and Monitoring

Recommend enabling these when creating or operating an RDS Oracle instance:

  • CloudTrail — audit RDS control-plane API calls (create / modify / delete).
  • Enhanced Monitoring — OS-level metrics (--monitoring-interval, --monitoring-role-arn).
  • Performance Insights — query-level performance analysis (--enable-performance-insights).
  • Log exports to CloudWatch Logs — export the Oracle audit, alert, listener, and trace logs via --cloudwatch-logs-export-configuration.
  • CloudWatch alarms — alarm on DatabaseConnections, FreeStorageSpace, and CPUUtilization at minimum.
  • Log encryption — encrypt the CloudWatch log groups with an AWS KMS key. Exported Oracle audit, alert, and listener logs can contain connection metadata and authentication attempts, so protect them at rest.

Additional Resources

Handoff from aws-database-selection

This skill can be invoked directly, or it can be entered from the aws-database-selection parent skill after that skill has run a requirements interview and produced a requirements.json artifact. When you see a backtick-wrapped path matching aws_dbs_requirements/*/requirements.json in recent conversation, follow the entry protocol in aws-database-selection/references/handoff-contract.md:

  1. Read the artifact using file_read.
  2. Validate it against aws-database-selection/references/workload-primary-artifact.schema.json. If malformed or unreadable, tell the user and proceed without it.
  3. Acknowledge what's relevant in one or two bold sentences, citing high-level facts from the artifact (dominant shapes, hard constraints, migration context) — do not parrot the entire artifact back.
  4. Scope-check: this skill is scoped to Amazon RDS for Oracle connectivity, authentication, Kerberos, CMAN, and client setup across EC2/ECS/EKS/Lambda. If the artifact's workload_primaries.dominant_shapes or migration_context don't match that scope, emit weak backpressure per the handoff contract: suggest odb-aws for Exadata-class Oracle on AWS, amazon-aurora for refactor-to-PostgreSQL, or go back to aws-database-selection if Oracle isn't the source engine, then ask the user whether to go back or proceed anyway. Do not silently misuse the artifact.
  5. Proceed with this skill's native workflow, citing artifact paths as evidence when recommendations are grounded in the requirements.

All user-facing output from this skill follows the markdown-primitives-only formatting convention in the handoff contract: bold labels, backticks for paths and enum values, bullet lists for alternatives, no ASCII art or box-drawing characters.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 17 other files (scripts, references) in skills/specialized-skills/database-skills/rds-oracle of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/client-tools.md
  • references/cman-proxy.md
  • references/compute-runtime.md
  • references/connection-auth.md
  • references/dotnet.md
  • references/encryption.md
  • references/java.md
  • references/networking.md
  • references/nodejs.md
  • references/python.md
  • references/ssm-tunneling.md
  • references/troubleshooting.md
  • scripts/check_rds_status.sh
  • scripts/check_security_groups.sh
  • scripts/check_ssl_status.sql
  • scripts/test_connectivity.sh
  • scripts/test_oracle_connection.py

Open the folder on GitHubat commit 188af2f

Compare with similar skills

Rds Oracle next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rds Oracle compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rds Oracle this skillaws/agent-toolkit-for-aws2.8k—~6.2kAutomated safety check: PassApache-2.0
Gorm ExpertLeoYeAI/openclaw-master-skills2.2k—~3.4kAutomated safety check: PassMIT
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Nx Plugin For AWSawslabs/nx-plugin-for-aws151—~3.6kAutomated safety check: PassApache-2.0
Multi Cloud ArchitectureHermeticOrmus/LibreUIUX-Claude-Code11211 repos~1.2kAutomated safety check: PassMIT
Python Reviewliuyanghejerry/Clausura204—~164Automated safety check: PassMIT

Similar skills

  • Gorm Expert

    LeoYeAI/openclaw-master-skills

    GORM v2 最佳实践与性能优化。适用于:代码审查、慢查询优化、N+1、连接池、 事务管理、分库分表、Prometheus/OTel监控、Session安全、Clause/Upsert、 缓存集成、BaseModel脚手架、SQL→struct生成、多租户隔离。

    2.2k GitHub stars~3.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Nx Plugin For AWS

    awslabs/nx-plugin-for-aws

    Official

    Scaffold and build cloud-native applications on AWS using @aws/nx-plugin generators.

    151 GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Multi Cloud Architecture

    HermeticOrmus/LibreUIUX-Claude-Code

    Design multi-cloud architectures using a decision framework to select and integrate services across AWS, Azure, and GCP.

    112 GitHub starsUsed in 11 repos~1.2k tokens
    DevOps & CloudAuto-check passed
  • Python Review

    liuyanghejerry/Clausura

    Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~164 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Devops Deploy

    sickn33/agentic-awesome-skills

    DevOps e deploy de aplicacoes — Docker, CI/CD com GitHub Actions, AWS Lambda, SAM, Terraform, infraestrutura como codigo e monitoramento.

    47k GitHub starsUsed in 2 repos~1.9k tokens
    DevOps & CloudAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Questions about Rds Oracle

What does Rds Oracle do?

Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting. Rds Oracle is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting.

When should I use Rds Oracle?

Rds Oracle fits situations like: devOps & Cloud work in your project.

How do I install Rds Oracle in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill rds-oracle -a claude-code`. Or copy the skill folder (skills/specialized-skills/database-skills/rds-oracle in aws/agent-toolkit-for-aws) into .claude/skills/rds-oracle in your project. Claude Code loads it when a task matches its description.

How do I install Rds Oracle in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill rds-oracle -a codex`. Or copy the skill folder (skills/specialized-skills/database-skills/rds-oracle in aws/agent-toolkit-for-aws) into .agents/skills/rds-oracle in your project. Codex loads it when a task matches its description.

Can I use Rds Oracle in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill rds-oracle -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rds-oracle, .gemini/skills/rds-oracle, .github/skills/rds-oracle and .opencode/skills/rds-oracle in your project.

What does Rds Oracle need to run?

Going by SKILL.md and its folder, Rds Oracle needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (aws, helm and kubectl). Our summary lists: Python 3; Node.js; A Bash shell.

Does Rds Oracle access the network?

SKILL.md names 4 domains. As links in the text: docs.aws.amazon.com, python-oracledb.readthedocs.io, node-oracledb.readthedocs.io and oracle.com. This is read from the text; nothing was executed.

Is Rds Oracle safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Rds Oracle use?

Rds Oracle is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rds Oracle use?

About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 22k tokens, read only when the agent opens those files.

What are the alternatives to Rds Oracle?

Skills that share tags, products or a category with Rds Oracle: Gorm Expert (LeoYeAI/openclaw-master-skills, 2.2k stars), AWS Cdk Development (zxkane/aws-skills, 367 stars), Nx Plugin For AWS (awslabs/nx-plugin-for-aws, 151 stars) and Multi Cloud Architecture (HermeticOrmus/LibreUIUX-Claude-Code, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rds Oracle?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.