Terravision Cloud Diagrams
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
This skill should be used when the user asks to "analyze this codebase", "document this service", "generate technical docs", "I inherited this code", "help me understand this system", "create docs…
$ npx skills add awslabs/agent-plugins --skill document-service -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awslabs/agent-plugins document-service --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/codebase-documentor-for-aws/skills/document-service .claude/skills/document-service && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "document-service" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/codebase-documentor-for-aws/skills/document-service into .claude/skills/document-service/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "document-service", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/awslabs/agent-plugins/tree/main/plugins/codebase-documentor-for-aws/skills/document-serviceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add awslabs/agent-plugins --skill document-service -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awslabs/agent-plugins document-service --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/codebase-documentor-for-aws/skills/document-service .agents/skills/document-service && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "document-service" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/codebase-documentor-for-aws/skills/document-service into .agents/skills/document-service/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "document-service", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awslabs/agent-plugins --skill document-service -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awslabs/agent-plugins document-service --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/codebase-documentor-for-aws/skills/document-service .cursor/skills/document-service && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "document-service" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/codebase-documentor-for-aws/skills/document-service into .cursor/skills/document-service/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "document-service", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/awslabs/agent-plugins.git --path plugins/codebase-documentor-for-aws/skills/document-service--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add awslabs/agent-plugins --skill document-service -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awslabs/agent-plugins document-service --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/codebase-documentor-for-aws/skills/document-service .gemini/skills/document-service && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "document-service" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/codebase-documentor-for-aws/skills/document-service into .gemini/skills/document-service/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "document-service", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awslabs/agent-plugins document-serviceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awslabs/agent-plugins --skill document-service -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/codebase-documentor-for-aws/skills/document-service .github/skills/document-service && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "document-service" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/codebase-documentor-for-aws/skills/document-service into .github/skills/document-service/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "document-service", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awslabs/agent-plugins --skill document-service -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awslabs/agent-plugins document-service --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awslabs/agent-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/codebase-documentor-for-aws/skills/document-service .opencode/skills/document-service && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "document-service" agent skill from https://github.com/awslabs/agent-plugins/tree/main/plugins/codebase-documentor-for-aws/skills/document-service into .opencode/skills/document-service/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "document-service", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
document-serviceThis skill should be used when the user asks to "analyze this codebase", "document this service", "generate technical docs", "I inherited this code", "help me understand this system", "create docs…
Document Service is an agent skill from awslabs/agent-plugins, published by the product's own GitHub organization. This skill should be used when the user asks to "analyze this codebase", "document this service", "generate technical docs", "I inherited this code", "help me understand this system", "create docs for this project", "what does this system look like", "onboard me to this codebase", "this codebase has no docs", "visualize the architecture from code", or any explicit request to produce structured documentation or architecture diagrams from an existing codebase. Specifically optimized for AWS workloads (CDK…
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/business-context.md`, `references/citation-format.md` and `references/discovery-patterns.md`).
It sits in DevOps & Cloud, covering Infrastructure as code, Diagrams and Citation management. It works with Amazon Web Services, AWS CloudFormation and Terraform. The repository describes itself as: Agent Plugins for AWS equip AI coding agents with the skills to help you architect, deploy, and operate on AWS. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit da51970. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Document Service loads about 4.4k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 174 tokens; SKILL.md has 1,858 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from awslabs/agent-plugins at commit da51970, republished under its Apache-2.0 licence (© awslabs). 1,858 words, ~4,378 tokens.
.claude/skills/document-service/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Analyze codebases to produce structured technical documentation and architecture diagrams with source-of-truth citations. Every finding links back to the exact file and line it was derived from. Optimized for AWS workloads but works with any codebase.
[RATIONALE UNKNOWN].file:line citations for every finding. See citation-format.md. Verify citations precisely — re-read the cited file and confirm the line number is within ±3 lines. Anchor with function/variable names.[UNKNOWN] for items not inferable from code, [RISK] for unhandled failure modes, [INFERRED] for educated guesses, [RATIONALE UNKNOWN] for unexplained architecture choices. Omitting markers undermines trust.The workflow runs autonomously from Step 2 onward. Step 1 is the only interactive step.
Gather from the user:
If existing docs are provided, read them first to establish baseline context. If the target directory and context are already known (e.g., provided via automation or a pre-configured prompt), skip the interactive step and proceed directly to Step 2.
Check whether CODEBASE_ANALYSIS.md already exists at the output path. If so, ask the user: "Overwrite or write to a different filename?" Resolve this before proceeding — the rest of the workflow runs autonomously.
.gitignore.git branch -a) for strategic context (e.g., a dev/rust branch signals a language migration in progress). Note active branches in the Architecture Overview.Produce a hierarchical outline mapping each documentation section to specific source files:
## Documentation Outline
1. Architecture Overview → [entry points, IaC stack files] — explain WHY, not just WHAT
2. [Module A: detected name] → [source files for module A]
3. [Module B: detected name] → [source files for module B]
4. Shared Utilities → [shared/common source files]
5. Request Lifecycle → [trace end-to-end flows through the system]
6. Domain Logic Deep-Dive → [core services at implementation level: algorithms, parameters, edge cases]
7. Startup and Initialization → [boot sequence, model loading, cache warmup, dependency checks]
8. API Contracts → [route definitions, OpenAPI specs]
9. Data Models → [schema files, ORM models]
10. Deployment → [IaC files, Dockerfiles]
11. Configuration → [config files, .env.example, prompt templates, YAML configs, secrets refs]
12. Monitoring and Observability → [log groups, metrics, tracing, alarms, dashboards]
13. Security → [auth, encryption, IAM, network isolation]
14. Local Development → [how to run/test locally, CPU fallback, dev environment setup]
15. Discrepancies → (cross-reference README/metadata vs actual code)
16. Failure Modes → (cross-cutting — include detection + recovery)
17. Timeout and Dependency Chain → (map cascading timeouts across layers)Follow the section structure in technical-doc-template.md but adapt to the actual codebase — add sections for significant modules, skip sections that don't apply. Aim for balance: each section should map to a meaningful subset of files. If a module maps to more than ~30 files, consider splitting it into sub-sections.
Do NOT pause for user review. Proceed immediately to analysis.
Two core analysis paths:
For each outline section, read mapped source files and extract:
Consult framework-patterns.md for framework-specific extraction patterns.
When IaC files are detected (CDK, CloudFormation, Terraform, Serverless Framework):
awsiac to confirm resource interpretations, awsknowledge for service descriptions.When no IaC is found, infer infrastructure from application code (SDK clients, connection strings, environment variables) and mark components as [INFERRED].
Note on CDK projects: In CDK codebases, the IaC IS application code (TypeScript/Python constructs). Process CDK files in a single pass covering both Path A and Path B rather than treating them as separate analyses. Extract both the resource definitions (Path B) and the application logic interleaved with them (Lambda bundling, environment wiring, IAM grants — Path A) simultaneously.
For each outline section:
[UNUSED] potential dead code.Process cross-cutting sections (Failure Modes, Configuration, Security, Discrepancies) last, drawing on accumulated knowledge.
Discrepancy detection: After analyzing the codebase, re-read the README, CLAUDE.md, package.json description, and any project metadata. Flag every claim that does not match the actual code — features referenced but not implemented, resource types that differ, architecture components that don't exist. For legacy codebases, this "trust but verify" pass is the single most valuable output.
Actionable failure modes: For each failure mode, include the detection method (CloudWatch metric, log pattern, symptom) and recovery steps (actual commands), not just a description. The reader is an on-call engineer at 3am.
Do not attempt a single-pass skim. For each module or service, use iterative deepening:
For codebases with multiple top-level modules, deep nesting, or hundreds of source files:
.codebase-documentor-progress.md task board to track progress through sections, enabling resumability if interrupted. This works on all platforms (Claude Code, Cursor, Codex, or any coding assistant).See recursive-analysis.md for detailed instructions on both approaches.
Two types of diagrams serve different purposes:
Sequence/flow diagrams — inline Mermaid. For request lifecycle traces and data pipeline flows identified in Step 4, generate Mermaid sequenceDiagram or flowchart blocks inline in the relevant CODEBASE_ANALYSIS.md sections. Mermaid is the community standard for simple flow diagrams and renders natively on GitHub. Keep these focused — one diagram per major request path or data flow.
Architecture diagram — always attempt the aws-architecture-diagram skill first. For the system-level architecture diagram (services, infrastructure, boundaries): invoke the aws-architecture-diagram skill (part of the deploy-on-aws plugin) with "analyze [target-directory]" to trigger Mode A. It produces a validated draw.io diagram (docs/*.drawio) with official AWS4 icons and professional styling. Only if the skill is genuinely unavailable (not installed, invocation fails), fall back to a Mermaid flowchart TD architecture overview directly in the Architecture Overview section. Include all major services, data stores, external dependencies, and infrastructure boundaries (VPC/subnets as subgraphs when IaC is present).
After diagram generation, try to export to PNG for embedding in the report. Run drawio -x -f png -b 10 -o docs/<name>.drawio.png docs/<name>.drawio. If drawio is not on PATH, skip the PNG export — the report will link to the .drawio file directly instead of embedding an image.
Cross-reference the diagram against the Architecture Overview text. Update documentation or diagram if they diverge.
Assemble all sections into CODEBASE_ANALYSIS.md following technical-doc-template.md
Embed the architecture diagram as an image with a link to the editable source:

> Editable source: [`docs/<name>.drawio`](./docs/<name>.drawio)If PNG export was not possible, link to the .drawio file directly. Mermaid flow diagrams go inline in relevant sections.
When the codebase reveals clear business capabilities (API contracts, domain models, data flows, SLA configs), include a Business Context section at the end of CODEBASE_ANALYSIS.md following business-context.md. Skip only for pure libraries or infrastructure-only code. Do NOT include speculative content — but a README describing the product IS sufficient business context.
Tag items not inferable from code with [UNKNOWN]
Write CODEBASE_ANALYSIS.md to the target directory
Remove .codebase-documentor-progress.md if it was created during analysis
Present summary: components documented, APIs found, unknowns tagged, citations included
| File | Purpose |
|---|---|
CODEBASE_ANALYSIS.md | Single output — technical docs, business context, citations, and flow diagrams |
docs/*.drawio | Architecture diagram source (editable in draw.io) |
docs/*.drawio.png | Architecture diagram image (embedded in report, if CLI export available) |
| Setting | Default | Override |
|---|---|---|
| Primary output | CODEBASE_ANALYSIS.md | - |
| Flow diagrams | Mermaid inline (sequenceDiagram / flowchart) | "skip diagrams" |
| Architecture diagram | draw.io via aws-architecture-diagram skill (Mermaid fallback if missing) | "skip diagrams" |
| IaC reading | Read-only (never modify) | - |
| AWS enrichment | Enabled when AWS services detected | "skip AWS" |
| Scope | User-specified directory | - |
See error-scenarios.md for handling of empty directories, missing entry points, missing IaC, existing output files, and MCP server failures.
Consult when AWS services are detected. Use for enrichment (adding official service descriptions and documentation links to CODEBASE_ANALYSIS.md) and validation (confirming the analysis interpretation is correct). When the codebase is self-explanatory, validation is more valuable than enrichment — do not add MCP content just because the server is available.
Example queries: search for "Amazon ECS on EC2 GPU instances" to confirm GPU support patterns, or read the official service page for an unfamiliar AWS service to get a one-line description.
Consult when CDK or CloudFormation files are detected. Use primarily for validation — confirm that the interpretation of a construct or resource type matches its actual behavior. Particularly useful for complex constructs with non-obvious defaults.
Example queries: confirm properties of ecs.FargateService vs ecs.Ec2Service or verify CloudFormation resource relationships. Terraform files are still analyzed by the skill itself (see discovery-patterns.md IaC Detection), just without this MCP server's schema validation.
© awslabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (references) in plugins/codebase-documentor-for-aws/skills/document-service of awslabs/agent-plugins.
Open the folder on GitHubat commit da51970
Document Service next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Document Service this skillawslabs/agent-plugins | 912 | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| AWS Cloud Advisortech-leads-club/agent-skills | 7k | — | ~2.1k | Automated safety check: Pass | CC-BY-4.0 | |
| AWS Sst Developmentzxkane/aws-skills | 367 | — | ~2.7k | Automated safety check: Warn | MIT | |
| Iac Securityhardw00t/ai-security-arsenal | 104 | — | ~2.4k | Automated safety check: Pass | None | |
| AWS Solution Architectborghei/Claude-Skills | 874 | — | ~1.8k | Automated safety check: Pass | MIT |
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
tech-leads-club/agent-skills
Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.
zxkane/aws-skills
SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.
hardw00t/ai-security-arsenal
Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.
borghei/Claude-Skills
Design AWS serverless architectures for startups with IaC. An agent skill from borghei/Claude-Skills.
seb1n/awesome-ai-agent-skills
Define, deploy, and manage cloud infrastructure as code using tools like Terraform, Pulumi, CloudFormation, and CDK, ensuring consistency, repeatability, and version control.
awslabs/agent-plugins
Validates dataset formatting and quality for SageMaker model fine-tuning (SFT, DPO, or RLVR).
awslabs/agent-plugins
Generates code that transforms datasets between ML schemas for model training or evaluation.
awslabs/agent-plugins
Selects a fine-tuning technique (SFT, DPO, RLVR, or RLAIF) for the user's use case and validates it against the selected model's available recipes.
awslabs/agent-plugins
Evaluate, configure, and migrate workloads to AWS Lambda Managed Instances (LMI).
awslabs/agent-plugins
Generate comprehensive issue reports from HyperPod clusters (EKS and Slurm) by collecting diagnostic logs and configurations for troubleshooting and AWS Support cases.
awslabs/agent-plugins
Diagnose performance issues on Amazon SageMaker HyperPod clusters — uneven NCCL bandwidth across nodes and poor filesystem throughput.
Categories
This skill should be used when the user asks to "analyze this codebase", "document this service", "generate technical docs", "I inherited this code", "help me understand this system", "create docs…. Document Service is an agent skill from awslabs/agent-plugins, published by the product's own GitHub organization. This skill should be used when the user asks to "analyze this codebase", "document this service", "generate technical docs", "I inherited this code", "help me understand this system", "create docs for this project", "what does this system look like", "onboard me to this codebase", "this codebase has no docs", "visualize the architecture from code", or any explicit request to produce structured documentation or architecture diagrams from an existing codebase.
Document Service fits situations like: asks to analyze this codebase; document this service; generate technical docs; I inherited this code.
Run `npx skills add awslabs/agent-plugins --skill document-service -a claude-code`. Or copy the skill folder (plugins/codebase-documentor-for-aws/skills/document-service in awslabs/agent-plugins) into .claude/skills/document-service in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awslabs/agent-plugins --skill document-service -a codex`. Or copy the skill folder (plugins/codebase-documentor-for-aws/skills/document-service in awslabs/agent-plugins) into .agents/skills/document-service in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awslabs/agent-plugins --skill document-service -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/document-service, .gemini/skills/document-service, .github/skills/document-service and .opencode/skills/document-service in your project.
Going by SKILL.md and its folder, Document Service needs the command-line tools its instructions call (git). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Document Service is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Document Service: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars), AWS Sst Development (zxkane/aws-skills, 367 stars) and Iac Security (hardw00t/ai-security-arsenal, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awslabs (a GitHub organization, an official publisher) maintains it in awslabs/agent-plugins, which has 912 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 5, 2026.
Source: awslabs/agent-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.