Trailmark Graph Evolution
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.
$ npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/agent-toolkit-for-aws remediating-with-aws-security-agent --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent .claude/skills/remediating-with-aws-security-agent && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "remediating-with-aws-security-agent" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent into .claude/skills/remediating-with-aws-security-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediating-with-aws-security-agent", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/agent-toolkit-for-aws/tree/main/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/agent-toolkit-for-aws remediating-with-aws-security-agent --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent .agents/skills/remediating-with-aws-security-agent && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "remediating-with-aws-security-agent" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent into .agents/skills/remediating-with-aws-security-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediating-with-aws-security-agent", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/agent-toolkit-for-aws remediating-with-aws-security-agent --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent .cursor/skills/remediating-with-aws-security-agent && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "remediating-with-aws-security-agent" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent into .cursor/skills/remediating-with-aws-security-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediating-with-aws-security-agent", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/agent-toolkit-for-aws.git --path plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/agent-toolkit-for-aws remediating-with-aws-security-agent --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent .gemini/skills/remediating-with-aws-security-agent && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "remediating-with-aws-security-agent" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent into .gemini/skills/remediating-with-aws-security-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediating-with-aws-security-agent", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/agent-toolkit-for-aws remediating-with-aws-security-agentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent .github/skills/remediating-with-aws-security-agent && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "remediating-with-aws-security-agent" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent into .github/skills/remediating-with-aws-security-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediating-with-aws-security-agent", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/agent-toolkit-for-aws remediating-with-aws-security-agent --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent .opencode/skills/remediating-with-aws-security-agent && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "remediating-with-aws-security-agent" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent into .opencode/skills/remediating-with-aws-security-agent/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediating-with-aws-security-agent", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
remediating-with-aws-security-agentPull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.
Remediating With AWS Security Agent is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. Use this whenever the user mentions Security Agent, security findings, pentest or penetration test results, code review findings, vulnerabilities found in their AWS account, "what did the security scan find", remediating or triaging security risks, or wants to start fixing reported vulnerabilities — even if they don't name the service explicitly. Trigger it for phrases like "get my security findings", "what…
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Cloud security, Code review and Penetration testing. It works with Amazon Web Services and Git. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit df2ab44. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awsgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Remediating With AWS Security Agent loads about 2.9k tokens when it runs. Until then it costs about 213 tokens; SKILL.md has 1,302 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/agent-toolkit-for-aws at commit df2ab44, republished under its Apache-2.0 licence (© aws). 1,302 words, ~2,897 tokens.
.claude/skills/remediating-with-aws-security-agent/SKILL.md (or your agent's skills folder).AWS Security Agent is a frontier agent that runs on-demand penetration tests and code reviews against a customer's applications and reports verified security risks. This skill takes you from "I have findings somewhere in AWS" to "I'm actively fixing the most important ones," while keeping the sensitive exploit detail out of source control.
The flow has four stages, and they matter in order:
Findings contain working attack scripts, reproduction steps, file paths, and sometimes
leaked secrets or environment details. If that lands in a Git repo, a customer can
accidentally commit and publish a step-by-step exploit for their own production system.
So the non-negotiable rule is: findings are written only to .security-agent/, and that
path is gitignored before anything is written.
Find out what the account has. All commands are read-only list-* operations.
AWS Security Agent organizes data as a hierarchy — work down it:
Application (account + Region)
└── Agent Space (workspace for design review, code review, and pentests)
├── Penetration test → Pentest job → Findings
└── Code review → Code review job → FindingsRun these to orient yourself and show the user what exists:
aws securityagent list-agent-spaces
aws securityagent list-pentests --agent-space-id <as-...>
aws securityagent list-code-reviews --agent-space-id <as-...>
aws securityagent list-pentest-jobs-for-pentest --agent-space-id <as-...> --pentest-id <pt-...>
aws securityagent list-code-review-jobs-for-code-review --agent-space-id <as-...> --code-review-id <cr-...>Job status is one of IN_PROGRESS, STOPPING, STOPPED, FAILED, COMPLETED. Only
COMPLETED jobs have a stable, full set of findings.
Agent spaces, pentests, and code reviews are named after the application they target. Before asking the user to pick from a raw list, make an informed guess about which scan corresponds to this repository — the user is working in a codebase for a reason, and the relevant findings are almost always for the app in front of them.
Infer the app identity from the workspace using cheap, high-signal sources:
git remote -v).name/description (package.json, pyproject.toml,
*.csproj, go.mod, Cargo.toml).Compare those signals against the agent space / scan names (case-insensitive, allow partial and fuzzy matches). Then always confirm before exporting — present your best guess and your reasoning, and let the user correct it:
"This repo looks like
<product>(from<signal>), which matches the<name>agent space. Use that, or pick another? [Other Agent Space names, ...]"
If nothing matches with reasonable confidence, say so plainly and show the full list rather than forcing a wrong guess. Never export from a guessed scan without the user's confirmation.
.security-agent/ (gitignored)Pull findings using AWS CLI commands. Write everything into .security-agent/ in the repo —
never to chat or stdout — because findings include working attack scripts, reproduction
steps, and sometimes leaked secrets.
mkdir -p .security-agent
echo '*' > .security-agent/.gitignoreYou should already have the agentSpaceId and the pentest/code-review id from Stage 1.
List jobs for the chosen scan:
# Pentest jobs:
aws securityagent list-pentest-jobs-for-pentest \
--agent-space-id <as-...> --pentest-id <pt-...>
# Code review jobs:
aws securityagent list-code-review-jobs-for-code-review \
--agent-space-id <as-...> --code-review-id <cr-...>Paginate by passing --next-token from the previous response until absent. Filter the
job summaries to status == "COMPLETED". If none are COMPLETED, stop and tell the user
"No completed jobs found. Please wait for a job to complete or check job statuses."
Otherwise, pick the COMPLETED job with the greatest createdAt timestamp.
# Pentest findings:
aws securityagent list-findings \
--agent-space-id <as-...> --pentest-job-id <pj-...>
# Code review findings:
aws securityagent list-findings \
--agent-space-id <as-...> --code-review-job-id <cj-...>Paginate on --next-token until exhausted. Confidence values from weakest to strongest:
FALSE_POSITIVE, UNCONFIRMED, LOW, MEDIUM, HIGH.
Keep only HIGH and MEDIUM by default. Widen only when the user explicitly asks.
batch-get-findings accepts at most 25 ids per call. Chunk the filtered finding ids into
groups of 25:
aws securityagent batch-get-findings \
--agent-space-id <as-...> \
--finding-ids <fid-1> <fid-2> ... <fid-25>Tag each returned finding with its source (pentest or code-review) before writing,
so triage in Stage 3 can tell them apart.
.security-agent/Group findings by job id. For each job, write a full markdown report to
.security-agent/findings_<jobId>.md with ALL fields returned by the API (findingId,
name, description, riskLevel, riskType, confidence, status, codeLocations, remediationCode,
and any other fields). Do not leave off any fields.
aws sts get-caller-identity and
check the Region (default us-east-1; Security Agent is regional).Rank by risk, because remediation time is finite and a CRITICAL unauthenticated RCE
outranks a LOW informational finding every time. Read the exported findings_*.md
files from .security-agent/ and sort them deterministically.
Sort ascending by this composite key (lower wins, i.e. more urgent first):
CRITICAL (0) → HIGH (1) → MEDIUM (2) → LOW (3) → INFORMATIONAL (4) →
UNKNOWN / missing (5).riskScore is a numeric string on pentest findings
(e.g. "10.0"), often absent on code-review findings — treat missing as the lowest
possible score so it sorts after scored findings of the same level.HIGH (0) → MEDIUM (1) → LOW (2) → UNCONFIRMED (3) → FALSE_POSITIVE (4).Also compute a severity-count summary across all findings (e.g. 2 CRITICAL · 5 HIGH · 3 MEDIUM) for the header of the report.
For each finding, derive a single short location string:
filePath is set, use it as-is.codeLocations[0]. Strip the scanner's sandbox prefix from filePath
(everything up to and including that marker) so the path is repo-relative; if that
marker isn't present, fall back to the basename. Append :<lineStart> when present.Write a compact summary for the user:
## Security Agent triage — <agent space name>
<N> findings exported (<P pentest, C code review>) · confidence: <levels> · severity: <counts>
### Priority order
1. [CRITICAL · score 10.0 · HIGH confidence] <finding name>
- Type: <riskType> · Source: <pentest|code-review>
- Where: <file:line or endpoint, if present>
- Impact: <one-line plain-language summary>
2. [HIGH · ...] ...
### Recommended remediation order
<short rationale: which to fix first and why — e.g. "1 and 3 are both
unauthenticated RCE on internet-facing endpoints; fix those before the
stored-XSS issues.">If more than ~10 findings, show the top N in detail and summarize the rest as a count by severity at the bottom.
The full description, reasoning, and attackScript stay in the gitignored files —
they contain working exploit detail. In the chat summary keep impact lines to one line
each, in plain language. Code-review findings usually carry a filePath/location and a
suggestedFix; call those out since they map directly to repo changes. Pentest findings
describe endpoints and attack chains; map them to the responsible code where you can.
Look for findings that corroborate each other (a pentest and a code review flagging the
same root cause) — those are strong signals for what to fix first.
After presenting the triage, offer to start fixing — don't silently begin editing code.
Ask the user something like: "Want me to start fixing the top finding(s)? I'd recommend
starting with #1 (<name>)." If they agree, work top-down by priority:
{filePath}:{lineStart}."If the user wants to handle several findings, fix one at a time (or one cluster of related findings) so each change stays reviewable, and proceed in the priority order from Stage 3.
IN_PROGRESS. Tell the user; offer to re-check
later rather than exporting a partial job.© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent of aws/agent-toolkit-for-aws.
Open the folder on GitHubat commit df2ab44
Remediating With AWS Security Agent next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Remediating With AWS Security Agent this skillaws/agent-toolkit-for-aws | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Trailmark Graph Evolutiontrailofbits/skills | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Trailmark Review Gatetrailofbits/skills | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Differential Security Reviewtrailofbits/skills | 7.4k | — | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Security ReviewerAratKruglik/claude-laravel | 155 | 1 repos | ~1.1k | Automated safety check: Notes | None | |
| Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit | 260 | — | ~2k | Automated safety check: Pass | Custom licence |
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Compares before and after Trailmark graphs of a branch, pull request or release diff to flag new entry points, tainted paths, removed validation and other structural security regressions.
trailofbits/skills
Reviews a pull request, commit or diff for security problems, using git history, caller counts and test coverage, and writes a markdown report.
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
aws/agent-toolkit-for-aws
Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.
aws/agent-toolkit-for-aws
A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.
aws/agent-toolkit-for-aws
Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.
aws/agent-toolkit-for-aws
Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.
aws/agent-toolkit-for-aws
Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…
aws/agent-toolkit-for-aws
A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.
Works with
Categories
Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. Remediating With AWS Security Agent is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.
Remediating With AWS Security Agent fits situations like: mentions Security Agent; security findings; penetration test results; code review findings.
Run `npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a claude-code`. Or copy the skill folder (plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent in aws/agent-toolkit-for-aws) into .claude/skills/remediating-with-aws-security-agent in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a codex`. Or copy the skill folder (plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent in aws/agent-toolkit-for-aws) into .agents/skills/remediating-with-aws-security-agent in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill remediating-with-aws-security-agent -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/remediating-with-aws-security-agent, .gemini/skills/remediating-with-aws-security-agent, .github/skills/remediating-with-aws-security-agent and .opencode/skills/remediating-with-aws-security-agent in your project.
Going by SKILL.md and its folder, Remediating With AWS Security Agent needs the command-line tools its instructions call (aws and git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Remediating With AWS Security Agent is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Remediating With AWS Security Agent: Trailmark Graph Evolution (trailofbits/skills, 7.4k stars), Trailmark Review Gate (trailofbits/skills, 7.4k stars), Differential Security Review (trailofbits/skills, 7.4k stars) and Security Reviewer (AratKruglik/claude-laravel, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,830 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 9, 2026.
Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.