Official agent skill

Support Cases

by aws in aws/tools-for-devops-agent

ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

OfficialApache-2.0Auto-check passedDevelopment

Install Support Cases

skills CLI
$ npx skills add aws/tools-for-devops-agent --skill support-cases -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/tools-for-devops-agent support-cases --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/tools-for-devops-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/support-cases .claude/skills/support-cases && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
support-cases
GitHub stars
100
Token cost
~2.2k tokens
SKILL.md length
908 words
Files
11 (incl. references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

  • Works in 5 steps: Identify the Current Incident Context → Search for Related Support Cases → Review Case Communications → …
  • Tasks that involve Root cause analysis
  • SKILL.md covers When to Use This Skill, Prerequisites, Step 1: Identify the Current… and Step 2: Search for Related…, plus 5 more sections
  • Calls aws

What it does

Support Cases is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting. This skill retrieves and analyzes AWS Support cases (open and resolved) to find historical incidents with similar symptoms, error patterns, or affected services. Activate this skill when investigating an issue and you observe service degradation, elevated error rates, latency spikes, connection failures, throttling, capacity issues, deployment-related failures, alarms, or any operational…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including reference files (for example `.skilleval.yaml`, `CHANGELOG.md` and `README.md`).

It sits in Development, covering Root cause analysis. It works with Amazon Web Services. The repository describes itself as: Open-source tools for AWS DevOps Agent - extend DevOps Agent with ready-to-use skills, custom agents, and other tools, for incident response, root cause analysis, and operational…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Root cause analysis

Example prompts

  • “Use the support-cases skill to alway use this skill in the beginning of any incident investigation, root cause analysis, or operational…”
  • “/support-cases”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify the Current Incident Context
  2. Search for Related Support Cases
  3. Review Case Communications
  4. Correlate Findings with Current Incident
  5. Summarize Findings

What it can do on your machine

Read from SKILL.md and the folder at commit ddda70b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Support Cases loads about 2.2k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 187 tokens; SKILL.md has 908 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~187
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/tools-for-devops-agent at commit ddda70b, republished under its Apache-2.0 licence (© aws). 908 words, ~2,194 tokens.

Download SKILL.mdSave it as .claude/skills/support-cases/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
support-cases
description
ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting. This skill retrieves and analyzes AWS Support cases (open and resolved) to find historical incidents with similar symptoms, error patterns, or affected services. Activate this skill when investigating an issue and you observe service degradation, elevated error rates, latency spikes, connection failures, throttling, capacity issues, deployment-related failures, alarms, or any operational event or issue. This skill searches past support cases by service, time window, severity, and error keywords to surface prior root causes, proven remediations, and recurring patterns that inform the current investigation.
metadata.author
udid-aws
metadata.version
1.0.0
metadata.aws-devops-agent-skills.agent-t
Chat tasks, Incident RCA
metadata.aws-devops-agent-skills.aws-ser
AWS Support
metadata.aws-devops-agent-skills.technic
Operations

Support Case Review

Use this skill when investigating an incident and you need to review AWS Support cases — either the current case associated with the incident or historical cases that may contain relevant context, similar symptoms, or proven remediation steps.

When to Use This Skill

  • An active incident shares symptoms with previously resolved issues.
  • You need to check if a similar support case was filed in the past 24 months.
  • You want to correlate the current incident with known AWS service events.
  • You need to retrieve communications and resolution details from a prior case.
  • You want to identify recurring patterns across multiple support cases.

Prerequisites

  • The AWS account must have a Business Support+, Enterprise Support, or Unified Operations plan (required for the AWS Support API).
  • The agent must have permissions to call support:DescribeCases and support:DescribeCommunications in the target account.
  • Support case data is available for 24 months after creation. Cases older than 24 months cannot be retrieved via the API.

Step 1: Identify the Current Incident Context

Before searching support cases, gather key details from the current incident:

  1. Affected AWS services (e.g., EC2, RDS, Lambda, ELB).
  2. Error messages or error codes observed in logs or alarms.
  3. Timeframe of the incident (start time, duration).
  4. Affected resources (instance IDs, ARNs, endpoint names).
  5. Symptoms (latency spikes, 5xx errors, connection timeouts, throttling).

Use these details as search criteria when filtering support cases.


Use the AWS Support API to retrieve cases that may be relevant.

Retrieve all recent cases (open and resolved)
aws support describe-cases \
  --include-resolved-cases \
  --include-communications \
  --after-time "<ISO-8601-start>" \
  --before-time "<ISO-8601-end>" \
  --language "en"
Filter by specific case IDs (if known)
aws support describe-cases \
  --case-id-list "case-123456789010-muen-2024" \
  --include-communications
Key filtering strategies
StrategyHow to Apply
By time windowUse --after-time and --before-time to scope cases to the relevant period (e.g., past 30 days, or around a previous incident date), because recent cases are more likely to reflect current infrastructure state.
By serviceReview the serviceCode field in returned cases to match the affected service (e.g., amazon-elastic-compute-cloud, amazon-rds), because the same service often exhibits recurring failure patterns.
By severityCheck the severityCode field — focus on urgent and critical cases for major incidents, because higher-severity cases tend to have more detailed root cause analysis from AWS Support.
By statusUse --include-resolved-cases to include closed cases, because resolved cases contain the root cause and remediation steps that are most valuable for correlating with the current incident.
By subject keywordsScan the subject field of returned cases for keywords matching the current incident symptoms, because similar symptoms often share underlying causes.

Step 3: Review Case Communications

The describe-cases response with includeCommunications: true returns the most recent communications for each case in the recentCommunications field (up to 5 messages). Since root cause analysis and resolution steps are typically in the final messages of a resolved case, this is usually sufficient.

If the recentCommunications field includes a nextToken, the case has additional older messages. Only paginate using describe-communications if the recent messages do not contain a clear root cause or resolution — for example, if the last messages are follow-up questions rather than a final answer.

aws support describe-communications \
  --case-id "case-123456789010-muen-2024" \
  --max-results 10 \
  --next-token "<nextToken-from-recentCommunications>"

When reviewing communications, look for:

  1. Root cause statements — AWS Support engineers often summarize the root cause in their final response.
  2. Remediation steps — Specific actions taken to resolve the issue (e.g., "increased max_connections", "applied security group rule", "scaled up instance type").
  3. Configuration recommendations — Best practices or tuning suggestions provided by AWS.
  4. Escalation notes — If the case was escalated, check for deeper technical analysis from specialized teams.

Show full SKILL.md (332 more words)Show less

Step 4: Correlate Findings with Current Incident

After reviewing relevant cases, correlate the findings:

Pattern matching checklist
  • Do past cases share the same affected service and resource type?
  • Are the error messages or codes identical or similar?
  • Did past incidents occur at a similar time of day or day of week (indicating load patterns)?
  • Was the root cause a configuration issue that may still be present?
  • Was the resolution a temporary workaround that has since expired or been reverted?
  • Did AWS identify a service-side issue that may be recurring?
Relevance scoring

Rate each historical case on relevance to the current incident:

ScoreCriteria
HighSame service, same error, same resource type, similar timeframe
MediumSame service, different error but related symptoms
LowDifferent service but similar architectural pattern or failure mode

Step 5: Summarize Findings

Provide a structured summary including:

  1. Number of related cases found — How many past cases matched the search criteria.
  2. Most relevant case(s) — Case ID, subject, status, and creation date of the top matches.
  3. Historical root causes — What caused similar issues in the past.
  4. Past resolutions — What remediation steps were applied and whether they were permanent fixes or temporary workarounds.
  5. Recommendations — Based on historical patterns, suggest investigation paths or remediation steps for the current incident.
  6. Recurring pattern alert — If the same issue has occurred multiple times, flag it as a recurring problem requiring a permanent fix or architectural change.

Decision Tree: Case Search Strategy

Is there a known case ID associated with the current incident?
├── YES → Retrieve that specific case and its communications (Step 2, filter by case ID)
└── NO → Continue below

Is the affected AWS service known?
├── YES → Search cases in the past 90 days for that service, then expand to 12 months if needed
└── NO → Search all cases in the past 30 days and filter by error keywords

Were relevant historical cases found?
├── YES → Review communications (Step 3), correlate findings (Step 4), summarize (Step 5)
└── NO → Broaden search criteria:
         - Expand time window
         - Search by related services (e.g., if ELB is affected, also check EC2 and Target Group cases)
         - Search by error code or symptom keywords in case subjects

Tips for Effective Case Review

  • Start narrow, then broaden: Begin with specific filters (service + time window) and expand only if no relevant cases are found.
  • Check resolved cases: The most valuable information often comes from resolved cases where root cause and fix are documented.
  • Note case severity patterns: If past cases for the same issue were filed at critical severity, the current incident may warrant similar urgency.
  • Cross-reference with deployments: If a past case was caused by a deployment, check if a similar deployment occurred before the current incident.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in skills/support-cases of aws/tools-for-devops-agent.

  • SKILL.md
  • .skilleval.yaml
  • CHANGELOG.md
  • README.md
  • evals/benchmark.json
  • evals/eval_queries.json
  • evals/evals.json
  • evals/report.json
  • evals/trigger_report.json
  • references/case-review-patterns.md
  • references/support-api-reference.md

Open the folder on GitHubat commit ddda70b

Compare with similar skills

Support Cases next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Support Cases compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Support Cases this skillaws/tools-for-devops-agent100—~2.2kAutomated safety check: PassApache-2.0
Debugging Lambda Timeoutsaws/agent-toolkit-for-aws2.8k—~502Automated safety check: PassApache-2.0
Troubleshooting Application Failuresaws/agent-toolkit-for-aws2.8k—~334Automated safety check: PassApache-2.0
Debugging Mwaa Workflowaws/agent-toolkit-for-aws2.8k—~2.3kAutomated safety check: PassApache-2.0
AWS Cloudformationaws/agent-toolkit-for-aws2.8k—~3.6kAutomated safety check: PassApache-2.0
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone

Similar skills

  • Debugging Lambda Timeouts

    aws/agent-toolkit-for-aws

    Official

    Debugs AWS Lambda function timeout failures by systematically analyzing function configuration, CloudWatch logs and metrics, VPC/networking, cold starts, memory constraints, and downstream…

    2.8k GitHub stars~502 tokensUpdated today
    DevelopmentAuto-check passed
  • Troubleshooting Application Failures

    aws/agent-toolkit-for-aws

    Official

    Troubleshoots failing applications by discovering and analyzing CloudWatch log groups to identify error patterns, root causes, and actionable solutions.

    2.8k GitHub stars~334 tokensUpdated today
    DevelopmentAuto-check passed
  • Debugging Mwaa Workflow

    aws/agent-toolkit-for-aws

    Official

    Diagnoses and root-causes Amazon MWAA workflow failures across Provisioned (Python DAG) and Serverless (YAML workflow) environments.

    2.8k GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • AWS Cloudformation

    aws/agent-toolkit-for-aws

    Official

    Authors, validates, and troubleshoots AWS CloudFormation templates.

    2.8k GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Bumps the build-time and installed Node.js versions in the RStudio repository, uploads the binaries to S3, verifies the install and opens a PR.

    5.1k GitHub stars~2.7k tokensUpdated today
    DevelopmentAuto-check passed

More from aws/tools-for-devops-agent

All 31 skills in this repo
  • Sagemaker AI Ops Review

    aws/tools-for-devops-agent

    Official

    Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.

    100 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Aiml GPU Training Cluster Investigation

    aws/tools-for-devops-agent

    Official

    A skill your agent uses for GPU training or inference clusters on SageMaker HyperPod (Slurm or EKS), ParallelCluster, or self-managed EC2/EKS GPU instances.

    100 GitHub stars~5.4k tokensUpdated today
    Auto-check passed
  • AWS Health Events

    aws/tools-for-devops-agent

    Official

    ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

    100 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Database Migration Service Expertise

    aws/tools-for-devops-agent

    Official

    AWS Database Migration Service (DMS) operational review and troubleshooting skill.

    100 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    100 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    100 GitHub stars~4.8k tokensUpdated today
    Auto-check passed

Questions about Support Cases

What does Support Cases do?

ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting. Support Cases is an agent skill from aws/tools-for-devops-agent, published by the product's own GitHub organization. ALWAYS use this skill in the beginning of any incident investigation, root cause analysis, or operational troubleshooting.

When should I use Support Cases?

Support Cases fits situations like: tasks that involve Root cause analysis.

How do I install Support Cases in Claude Code?

Run `npx skills add aws/tools-for-devops-agent --skill support-cases -a claude-code`. Or copy the skill folder (skills/support-cases in aws/tools-for-devops-agent) into .claude/skills/support-cases in your project. Claude Code loads it when a task matches its description.

How do I install Support Cases in Codex?

Run `npx skills add aws/tools-for-devops-agent --skill support-cases -a codex`. Or copy the skill folder (skills/support-cases in aws/tools-for-devops-agent) into .agents/skills/support-cases in your project. Codex loads it when a task matches its description.

Can I use Support Cases in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/tools-for-devops-agent --skill support-cases -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/support-cases, .gemini/skills/support-cases, .github/skills/support-cases and .opencode/skills/support-cases in your project.

What does Support Cases need to run?

Going by SKILL.md and its folder, Support Cases needs the command-line tools its instructions call (aws).

Does Support Cases access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Support Cases safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Support Cases use?

Support Cases is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Support Cases use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Support Cases?

Skills that share tags, products or a category with Support Cases: Debugging Lambda Timeouts (aws/agent-toolkit-for-aws, 2.8k stars), Troubleshooting Application Failures (aws/agent-toolkit-for-aws, 2.8k stars), Debugging Mwaa Workflow (aws/agent-toolkit-for-aws, 2.8k stars) and AWS Cloudformation (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Support Cases?

aws (a GitHub organization, an official publisher) maintains it in aws/tools-for-devops-agent, which has 100 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 8, 2026.

Source: aws/tools-for-devops-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.