Official agent skill

Transitgateway

by aws in aws/agent-toolkit-for-aws

Configures AWS Transit Gateway: creating a hub and attaching VPCs, segmenting traffic with route tables, centralizing egress and inspection through a hub (appliances or a Gateway Load Balancer…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Transitgateway

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill transitgateway -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws transitgateway --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/networking-and-content-delivery-skills/transitgateway .claude/skills/transitgateway && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
transitgateway
GitHub stars
2.8k
Token cost
~2k tokens
SKILL.md length
867 words
Files
9 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configures AWS Transit Gateway: creating a hub and attaching VPCs, segmenting traffic with route tables, centralizing egress and inspection through a hub (appliances or a Gateway Load Balancer…

  • Tasks that involve Cloud networking
  • SKILL.md covers Overview, Which Transit Gateway task do…, Routing notes and Security considerations, plus 1 more section
  • Calls aws

What it does

Transitgateway is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Configures AWS Transit Gateway: creating a hub and attaching VPCs, segmenting traffic with route tables, centralizing egress and inspection through a hub (appliances or a Gateway Load Balancer endpoint), forcing east-west traffic between VPCs through AWS Network Firewall, connecting on-premises networks over the transit-gateway side of a Site-to-Site VPN or Direct Connect attachment (including ECMP to aggregate bandwidth across multiple VPN tunnels), peering transit gateways across Regions, migrating from a VPC…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/centralizing-egress-and-inspection.md`, `references/connecting-on-premises-networks.md` and `references/creating-a-transit-gateway-and-attaching-vpcs.md`).

It sits in DevOps & Cloud, covering Cloud networking. It works with Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cloud networking

Example prompts

  • “Use the transitgateway skill to configure AWS Transit Gateway: creating a hub and attaching VPCs, segmenting traffic with route tables, centralizing…”
  • “/transitgateway”

What it can do on your machine

Read from SKILL.md and the folder at commit bd49cc8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • aws.amazon.com
    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Transitgateway loads about 2k tokens when it runs, and up to ~33k if it reads all its reference files. Until then it costs about 245 tokens; SKILL.md has 867 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~245
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~33k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit bd49cc8, republished under its Apache-2.0 licence (© aws). 867 words, ~1,953 tokens.

Download SKILL.mdSave it as .claude/skills/transitgateway/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
transitgateway
description
Configures AWS Transit Gateway: creating a hub and attaching VPCs, segmenting traffic with route tables, centralizing egress and inspection through a hub (appliances or a Gateway Load Balancer endpoint), forcing east-west traffic between VPCs through AWS Network Firewall, connecting on-premises networks over the transit-gateway side of a Site-to-Site VPN or Direct Connect attachment (including ECMP to aggregate bandwidth across multiple VPN tunnels), peering transit gateways across Regions, migrating from a VPC peering mesh, and routing IP multicast. Applicable when connecting many VPCs through one router, isolating environments, forcing VPC-to-VPC traffic through a central Network Firewall, reaching on-premises over the hub, linking Regions, or moving off a peering mesh. Not applicable for single-VPC routing, VPC peering between two VPCs (vpcpeering skill), Direct Connect gateway or virtual interface setup (directconnect skill), or Route 53 DNS work.
version
1

AWS Transit Gateway

Overview

Domain expertise for configuring AWS Transit Gateway, the Regional network hub that connects many VPCs and on-premises networks through a single router instead of a mesh of point-to-point connections. Covers building the hub and attaching VPCs, segmenting traffic with route tables, centralizing egress and inspection, east-west inspection with AWS Network Firewall, hybrid connectivity over Site-to-Site VPN and Direct Connect, inter-Region peering, migrating off a VPC peering mesh, and IP multicast.

This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting, then follow its constraints and steps. The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to the AWS CLI otherwise. All CLI operations require least-privilege, ephemeral credentials (an assumed IAM role through AWS STS or AWS IAM Identity Center / SSO), never long-lived IAM user access keys. A transit gateway is a Regional resource: run each aws ec2 transit gateway command in the Region that holds the hub.

Which Transit Gateway task do you need?

GoalReference
Create a Regional hub and connect VPCs to itcreating a transit gateway and attaching VPCs
Isolate some VPCs while letting others share servicessegmenting traffic with route tables
Send all spoke traffic out through one inspected egress VPCcentralizing egress and inspection
Inspect traffic between VPCs with AWS Network Firewallinspecting east-west traffic with Network Firewall
Reach on-premises networks over Site-to-Site VPN or Direct Connectconnecting on-premises networks
Link transit gateways in two Regions over the AWS networkpeering transit gateways across Regions
Move off a VPC peering mesh without dropping trafficmigrating from VPC peering
Distribute IP multicast across attached VPCsrouting multicast traffic

Routing notes

  • Decide segmentation before you build. "Default route table association" and "Default route table propagation" are on by default, which wires every attachment into one open mesh. If the customer plans isolated environments, the creating reference disables the defaults up front and hands off to the segmenting reference. Retrofitting isolation onto an open hub is a re-architect.
  • North-south egress vs east-west inspection. Centralizing egress sends spoke traffic out to the internet through a central VPC. East-west inspection keeps traffic between spokes internal and forces it through a firewall on the way. They look similar but use different route table recipes. Match the reference to the direction of traffic the customer actually has.
  • Appliance vs Gateway Load Balancer for inspection. Raw third-party appliances and a Gateway Load Balancer (GWLB) endpoint are two paths to the same goal. GWLB is the recommended approach for new designs. Both live in the centralizing-egress reference; appliance mode and the GWLB endpoint route table entries differ and the reference covers each.
  • Appliance mode is required for stateful cross-Availability-Zone inspection, with a tradeoff. Appliance mode keeps each flow on one Availability Zone's appliance so request and response do not split. It also disables cross-Availability-Zone failover for that attachment, so the inspection design must pair it with health-check-based failover. Both the egress and east-west references carry this.
  • Transit gateway side vs Direct Connect side. The connecting-on-premises reference covers the transit gateway side: Site-to-Site VPN attachment options, route propagation, and equal-cost multi-path (ECMP). The Direct Connect gateway and virtual interface setup belongs to the separate directconnect skill. Do not restate the Direct Connect side here.
Show full SKILL.md (299 more words)Show less

Security considerations

A transit gateway is the central routing point for many VPCs and on-premises networks, so a misconfiguration here has blast radius across every attached network. Apply these controls regardless of the specific task; each per-task reference carries the detail.

  • You MUST enable Transit Gateway Flow Logs for traffic visibility, audit, and incident response across the hub, and MUST enable encryption at rest on the destination (a KMS key on the CloudWatch log group, or SSE-KMS on the S3 bucket).
  • You MUST, when a KMS key encrypts a flow log destination (CloudWatch log group or S3 bucket) or a CloudTrail destination, scope the KMS key policy with condition keys (aws:SourceArn, aws:SourceAccount, and kms:ViaService) so only the specific log group, bucket, or trail in the expected account and service can use the key, preventing cross-account or cross-service misuse.
  • You SHOULD apply least-privilege IAM for transit gateway administration, avoiding service wildcards and FullAccess policies, restricting who can create attachments, modify route tables, and change associations or propagations.
  • You SHOULD ensure Site-to-Site VPN tunnels use strong encryption (for example AES-256-GCM with IKEv2) and enable tunnel logging to CloudWatch Logs with encryption enabled (a KMS key) to protect sensitive connection state and IKE negotiation detail from unauthorized access (see the connecting on-premises networks reference).
  • You MUST treat a misconfigured transit gateway route table as a security risk, since wrong associations or propagations can expose workloads across environments meant to stay isolated (see the segmenting traffic reference).
  • You MUST enable AWS CloudTrail to detect unauthorized changes to transit gateway route tables, associations, and propagations, MUST enable encryption at rest on the CloudTrail destination (a KMS key), and use AWS Config rules to detect drift from the intended design.

Additional Resources

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in skills/specialized-skills/networking-and-content-delivery-skills/transitgateway of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/centralizing-egress-and-inspection.md
  • references/connecting-on-premises-networks.md
  • references/creating-a-transit-gateway-and-attaching-vpcs.md
  • references/inspecting-east-west-traffic-with-network-firewall.md
  • references/migrating-from-vpc-peering.md
  • references/peering-transit-gateways-across-regions.md
  • references/routing-multicast-traffic.md
  • references/segmenting-traffic-with-route-tables.md

Open the folder on GitHubat commit bd49cc8

Compare with similar skills

Transitgateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Transitgateway compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Transitgateway this skillaws/agent-toolkit-for-aws2.8k—~2kAutomated safety check: PassApache-2.0
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0
Hybrid Cloud Networkingwshobson/agents40k10 repos~1.5kAutomated safety check: PassMIT
Dt Obs AWSDynatrace/dynatrace-for-ai161—~4.2kAutomated safety check: PassApache-2.0
AWS Ecs Fargatesickn33/agentic-awesome-skills47k2 repos~3kAutomated safety check: PassMIT
AWS Vpcsickn33/agentic-awesome-skills47k2 repos~4kAutomated safety check: PassMIT

Similar skills

  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Configure secure, high-performance connectivity between on-premises infrastructure and cloud platforms using VPN and dedicated connections.

    40k GitHub starsUsed in 10 repos~1.5k tokens
    DevOps & CloudAuto-check passed
  • Dt Obs AWS

    Dynatrace/dynatrace-for-ai

    AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.

    161 GitHub stars~4.2k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • AWS Ecs Fargate

    sickn33/agentic-awesome-skills

    Deploy containers on ECS and Fargate. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3k tokens
    DevOps & CloudAuto-check passed
  • AWS Vpc

    sickn33/agentic-awesome-skills

    Design and implement VPCs and networking. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4k tokens
    DevOps & CloudAuto-check passed
  • Load Balancing

    sickn33/agentic-awesome-skills

    Configure load balancers and traffic distribution. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.9k tokens
    DevOps & CloudAuto-check: notes

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Categories

Questions about Transitgateway

What does Transitgateway do?

Configures AWS Transit Gateway: creating a hub and attaching VPCs, segmenting traffic with route tables, centralizing egress and inspection through a hub (appliances or a Gateway Load Balancer…. Transitgateway is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization.

When should I use Transitgateway?

Transitgateway fits situations like: tasks that involve Cloud networking.

How do I install Transitgateway in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill transitgateway -a claude-code`. Or copy the skill folder (skills/specialized-skills/networking-and-content-delivery-skills/transitgateway in aws/agent-toolkit-for-aws) into .claude/skills/transitgateway in your project. Claude Code loads it when a task matches its description.

How do I install Transitgateway in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill transitgateway -a codex`. Or copy the skill folder (skills/specialized-skills/networking-and-content-delivery-skills/transitgateway in aws/agent-toolkit-for-aws) into .agents/skills/transitgateway in your project. Codex loads it when a task matches its description.

Can I use Transitgateway in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill transitgateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/transitgateway, .gemini/skills/transitgateway, .github/skills/transitgateway and .opencode/skills/transitgateway in your project.

What does Transitgateway need to run?

Going by SKILL.md and its folder, Transitgateway needs the command-line tools its instructions call (aws).

Does Transitgateway access the network?

SKILL.md names 2 domains. As links in the text: aws.amazon.com and docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Transitgateway safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Transitgateway use?

Transitgateway is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Transitgateway use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 31k tokens, read only when the agent opens those files.

What are the alternatives to Transitgateway?

Skills that share tags, products or a category with Transitgateway: Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars), Hybrid Cloud Networking (wshobson/agents, 40k stars), Dt Obs AWS (Dynatrace/dynatrace-for-ai, 161 stars) and AWS Ecs Fargate (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Transitgateway?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,816 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.