Encrypted Saved Objects
elastic/kibana
Encrypted Saved Objects (ESO) in Kibana — registration, AAD attribute choices, partial update safety, model version migrations with createModelVersion, canEncrypt checks, and Serverless constraints.
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
$ npx skills add elastic/agent-skills --skill cloud-onboarding -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills cloud-onboarding --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/onboarding .claude/skills/cloud-onboarding && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cloud-onboarding" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/onboarding into .claude/skills/cloud-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-onboarding", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/cloud/onboardingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill cloud-onboarding -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills cloud-onboarding --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/onboarding .agents/skills/cloud-onboarding && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cloud-onboarding" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/onboarding into .agents/skills/cloud-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-onboarding", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill cloud-onboarding -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills cloud-onboarding --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/onboarding .cursor/skills/cloud-onboarding && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cloud-onboarding" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/onboarding into .cursor/skills/cloud-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-onboarding", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/cloud/onboarding--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill cloud-onboarding -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills cloud-onboarding --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/onboarding .gemini/skills/cloud-onboarding && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cloud-onboarding" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/onboarding into .gemini/skills/cloud-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-onboarding", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills cloud-onboardingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill cloud-onboarding -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/onboarding .github/skills/cloud-onboarding && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cloud-onboarding" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/onboarding into .github/skills/cloud-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-onboarding", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill cloud-onboarding -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills cloud-onboarding --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/onboarding .opencode/skills/cloud-onboarding && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cloud-onboarding" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/onboarding into .opencode/skills/cloud-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-onboarding", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cloud-onboardingOnboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Cloud Onboarding is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and create or revoke Cloud API keys. Use when setting up Cloud authentication or when granting, modifying, or auditing user access to an organization and its projects.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/api-reference.md`). Compatibility notes: Requires the elastic CLI (= 0.2) with cloud support and network access to the Elastic Cloud API (api.elastic-cloud.com). Custom-role operations additionally…
It sits in Backend & APIs, covering Serverless. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.elastic-cloud.comAlso links to:
cloud.elastic.cogithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires the `elastic` CLI (>= 0.2) with `cloud` support and network access to the Elastic Cloud API (api.elastic-cloud.com). Custom-role operations additionally need an Elasticsearch context on the target Serverless project with `manage_security`. Targets the Elastic Cloud control plane; not applicable to self-managed clusters.
From compatibility in the SKILL.md frontmatter.
Cloud Onboarding loads about 4.1k tokens when it runs, and up to ~9.3k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 1,669 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,669 words, ~4,102 tokens.
.claude/skills/cloud-onboarding/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Stand up access to an Elastic Cloud organization end to end: configure the elastic CLI so it can operate the control
plane, then manage identity and access — invite users, assign predefined or custom roles to Serverless projects, and
manage Cloud API keys. For creating and operating projects and deployments, use the cloud-provisioning skill.
This skill configures the elastic CLI itself, so its setup lives here rather than being assumed. If the
elastic CLI is not installed, tell the user what it is needed for.
Cloud control-plane access is authenticated by an Elastic Cloud API key (organization scope), stored in a CLI context. Register it without ever having the user paste the secret into the chat:
elastic config context add cloud --cloud-url https://api.elastic-cloud.com --cloud-api-key <KEY>, then make it
active with elastic config current-context set cloud.Do not guess credentials, bypass the CLI to call the HTTP API directly, or ask the user to reveal the key. This skill
references control-plane operations in HTTP-shorthand form with the cloud: prefix (for example,
GET cloud:/api/v1/organizations); the Operations table maps each to the equivalent elastic cloud
command.
For detailed API schemas (role assignments, Cloud API keys, custom roles), see references/api-reference.md. For Elasticsearch-level role management beyond Cloud roles (native users, role mappings, DLS/FLS) see elasticsearch-authz.
application_rolesValidate the Cloud context. Confirm the active context can reach the control plane by calling
GET cloud:/api/v1/organizations. A successful response lists the organizations the key belongs to and yields the
organization ID other steps need. If it returns an authentication error, the context is missing or the key is invalid
or expired — return to Environment Configuration and register a valid key. Do not
proceed until validation succeeds, and never ask the user for the organization ID — discover it here.
Establish a default region (optional). When the user plans to create projects, list the available regions with
GET cloud:/api/v1/serverless/regions and confirm a default. Default to gcp-us-central1 unless the user requests
otherwise; only regions with project_creation_enabled: true accept new projects. Region choice is permanent per
project, so surface it early.
This skill does not pre-check roles; it attempts the operation and lets the API enforce authorization. On a 403, stop
and ask the user to verify the API key's permissions.
| Operation | Required permission |
|---|---|
| Invite / remove members | Organization owner (organization-admin) |
| Assign or remove roles | Organization owner (organization-admin) |
| Create / revoke Cloud API keys | Organization owner (organization-admin) |
| List members, invitations, or keys | Any organization member |
| Create / delete custom roles | manage_security cluster privilege on the project ES endpoint |
Prefer predefined roles; only create a custom role when they lack the required granularity.
Organization: organization-admin (full admin), billing-admin (billing only).
Serverless project roles (assign at invitation or via role-assignment update):
| Role | role_id | Available on |
|---|---|---|
| Admin | admin | Search, Obs, Security |
| Developer | developer | Search |
| Viewer | viewer | Search, Obs, Security |
| Editor | editor | Obs, Security |
| Analysts | t1_analyst, t2_analyst, t3_analyst, soc_manager, rule_author | Security |
See references/api-reference.md for the full role_assignments schema (organization,
deployment, and project scopes) and the complete Security role list.
When the user describes access in natural language (for example, "add Alice to my search project as a developer"), break it down before executing.
Identify components. Who (new invite vs existing member), what (which project or org-level), access level (predefined vs custom role), and whether an API key is also needed.
Check existing state first. List members with GET cloud:/api/v1/organizations/{org_id}/members and, for key
requests, existing keys with GET cloud:/api/v1/users/auth/keys. If the user is already a member, update their roles
instead of inviting. If an active key already exists for the same purpose with the right roles and enough
remaining lifetime, reuse it.
Execute the smallest sufficient change.
POST cloud:/api/v1/organizations/{org_id}/invitations (include project role
assignments, or invite without roles when a custom role will follow).POST cloud:/api/v1/users/{user_id}/role_assignments; remove with the
DELETE variant.DELETE cloud:/api/v1/organizations/{org_id}/members/{user_ids} (confirm first).POST cloud:/api/v1/users/auth/keys; revoke with
DELETE cloud:/api/v1/users/auth/keys (confirm first). Confirm destructive actions (remove member, revoke key)
with the user before executing.Verify. List members or keys again to confirm the change took effect.
When predefined roles lack the granularity, create a custom role in the project via the Elasticsearch security API and
assign it through the Cloud API's application_roles:
PUT /_security/role/{name} (runs against the project's Elasticsearch endpoint;
requires manage_security). Role names must start with a letter or digit and contain only letters, digits, _, -,
.. Run-as privileges are not available in Serverless.application_roles on a project-scoped role assignment
(POST cloud:/api/v1/users/{user_id}/role_assignments) with role_id set to the project-type viewer
(elasticsearch-viewer, observability-viewer, security-viewer).Do not also assign a predefined Cloud role for the same project. A custom role already grants Viewer-level Cloud access; adding
viewer(or another predefined role) gives the user the union of both, widening access beyond what the custom role intends.
Cloud API keys can also call Elasticsearch and Kibana APIs on Serverless projects by including application_roles in
their role_assignments. Unlike users, API keys never inherit stack roles from role_id — without
application_roles the key has Cloud-API-only access and receives 403 on ES/Kibana calls.
project key) so the key only reaches named projects or all projects of a
type.organization key) grant ES/Kibana access to all current and future projects
— the broadest data-plane scope. Only use it for genuine cross-project automation, and confirm with the user first.application_roles must exist in each target project, or the key silently gets no access there.
Predefined roles (admin, developer, viewer) exist in every project by default."Set up my cloud environment" — verify a Cloud context exists, then validate it with
GET cloud:/api/v1/organizations. If it fails, walk the user through generating an Organization-level Cloud API key and
registering it as a context (never in chat), then re-validate and report the discovered organization.
"Set up cloud in the EU region" — after validating the context, list regions with
GET cloud:/api/v1/serverless/regions, pick an EU region (for example aws-eu-west-1), and confirm it as the default
for subsequent project creation.
"Add alice@example.com to my search project with read-only access" — check members with
GET cloud:/api/v1/organizations/{org_id}/members; if Alice is new,
POST cloud:/api/v1/organizations/{org_id}/invitations with a project-scoped viewer role for the Elasticsearch
project.
"Create a 30-day CI key that can index into our search projects" — list keys with
GET cloud:/api/v1/users/auth/keys to avoid duplicates, then POST cloud:/api/v1/users/auth/keys with a project-scoped
developer role assignment including application_roles: ["developer"] and expiration: "30d". The secret is shown
once — never repeat it in chat.
"Give bob@example.com read-only access to marketing-* on my search project" — create a custom role with
PUT /_security/role/marketing-reader (read on marketing-*), invite Bob without project roles, then assign the custom
role via application_roles on POST cloud:/api/v1/users/{user_id}/role_assignments. Do not also assign viewer.
"Show who has access to my organization" — GET cloud:/api/v1/organizations/{org_id}/members and present each
member's ID, email, and roles.
GET cloud:/api/v1/organizations — do not ask for
it.gcp-us-central1 — only change it when the user requests a different region.expiration matching the task lifetime; prompt the
user to revoke keys no longer needed. Each organization supports up to 500 active keys; default expiration is 3
months. Invitations expire after 72 hours by default. Cloud API keys inherit roles at creation and cannot be updated —
revoke and recreate to change roles.| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET cloud:/api/v1/organizations | elastic cloud orgs list-organizations |
GET cloud:/api/v1/serverless/regions | elastic cloud serverless regions list-regions |
GET cloud:/api/v1/organizations/{org_id}/members | elastic cloud orgs list-organization-members --organization-id <org_id> |
POST cloud:/api/v1/organizations/{org_id}/invitations | elastic cloud orgs create-organization-invitations --organization-id <org_id> --input-file <json> |
GET cloud:/api/v1/organizations/{org_id}/invitations | elastic cloud orgs list-organization-invitations --organization-id <org_id> |
DELETE cloud:/api/v1/organizations/{org_id}/invitations/{tokens} | elastic cloud orgs delete-organization-invitations --organization-id <org_id> --invitation-tokens <csv> |
DELETE cloud:/api/v1/organizations/{org_id}/members/{user_ids} | elastic cloud orgs delete-organization-memberships --organization-id <org_id> --user-ids <csv> |
POST cloud:/api/v1/users/{user_id}/role_assignments | elastic cloud users add-role-assignments --user-id <user_id> --input-file <json> |
DELETE cloud:/api/v1/users/{user_id}/role_assignments | elastic cloud users remove-role-assignments --user-id <user_id> --input-file <json> |
POST cloud:/api/v1/users/auth/keys | elastic cloud auth create-api-key --input-file <json> |
GET cloud:/api/v1/users/auth/keys | elastic cloud auth get-api-keys |
DELETE cloud:/api/v1/users/auth/keys | elastic cloud auth delete-api-keys --input-file <json> |
PUT /_security/role/{name} | elastic es security put-role --name <name> --input-file <json> |
GET /_security/role | elastic es security get-role |
DELETE /_security/role/{name} | elastic es security delete-role --name <name> |
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/cloud/onboarding of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Cloud Onboarding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cloud Onboarding this skillelastic/agent-skills | 592 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Encrypted Saved Objectselastic/kibana | 21k | — | ~4.3k | Automated safety check: Pass | Custom licence | |
| Amazon Opensearch Serviceaws/agent-toolkit-for-aws | 2.8k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Arcgis To Portaljsdatopian/portaljs | 2.4k | 1 repos | ~2k | Automated safety check: Pass | MIT | |
| AWS Serverless Edazxkane/aws-skills | 367 | 4 repos | ~3.2k | Automated safety check: Pass | MIT | |
| AI Model NodejsTencentCloudBase/CloudBase-AI-Toolkit | 1.1k | 3 repos | ~5k | Automated safety check: Pass | MIT |
elastic/kibana
Encrypted Saved Objects (ESO) in Kibana — registration, AAD attribute choices, partial update safety, model version migrations with createModelVersion, canEncrypt checks, and Serverless constraints.
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
datopian/portaljs
Migrate a whole ArcGIS Hub site into a PortalJS Arc portal end-to-end.
zxkane/aws-skills
AWS serverless and event-driven architecture expert based on Well-Architected Framework.
TencentCloudBase/CloudBase-AI-Toolkit
A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.
elastic/kibana
A skill your agent uses when debugging OpenAPI (OAS) issues for a specific API area in Kibana by scoping validation output with one or more --path filters, then separating structural invalid-OAS…
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Create and manage Elastic ML anomaly detection jobs via the API.
Works with
Categories
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…. Cloud Onboarding is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and create or revoke Cloud API keys.
Cloud Onboarding fits situations like: setting up Cloud authentication; auditing user access to an organization and its projects.
Run `npx skills add elastic/agent-skills --skill cloud-onboarding -a claude-code`. Or copy the skill folder (skills/cloud/onboarding in elastic/agent-skills) into .claude/skills/cloud-onboarding in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill cloud-onboarding -a codex`. Or copy the skill folder (skills/cloud/onboarding in elastic/agent-skills) into .agents/skills/cloud-onboarding in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill cloud-onboarding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-onboarding, .gemini/skills/cloud-onboarding, .github/skills/cloud-onboarding and .opencode/skills/cloud-onboarding in your project.
SKILL.md names no scripts, command-line tools or credentials: Cloud Onboarding is instructions for the agent only. Compatibility (from SKILL.md): Requires the `elastic` CLI (>= 0.2) with `cloud` support and network access to the Elastic Cloud API (api.elastic-cloud.com). Custom-role operations additionally need an Elasticsearch context on the target Serverless project with `manage_security`. Targets the Elastic Cloud control plane; not applicable to self-managed clusters. .
SKILL.md names 3 domains. In commands or code: api.elastic-cloud.com; the agent is likely to contact it when it follows the instructions. As links in the text: cloud.elastic.co and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cloud Onboarding is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Cloud Onboarding: Encrypted Saved Objects (elastic/kibana, 21k stars), Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Arcgis To Portaljs (datopian/portaljs, 2.4k stars) and AWS Serverless Eda (zxkane/aws-skills, 367 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.