Amazon Opensearch Service
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS…
$ npx skills add elastic/agent-skills --skill cloud-provisioning -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills cloud-provisioning --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/provisioning .claude/skills/cloud-provisioning && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cloud-provisioning" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/provisioning into .claude/skills/cloud-provisioning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-provisioning", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/cloud/provisioningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill cloud-provisioning -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills cloud-provisioning --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/provisioning .agents/skills/cloud-provisioning && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cloud-provisioning" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/provisioning into .agents/skills/cloud-provisioning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-provisioning", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill cloud-provisioning -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills cloud-provisioning --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/provisioning .cursor/skills/cloud-provisioning && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cloud-provisioning" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/provisioning into .cursor/skills/cloud-provisioning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-provisioning", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/cloud/provisioning--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill cloud-provisioning -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills cloud-provisioning --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/provisioning .gemini/skills/cloud-provisioning && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cloud-provisioning" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/provisioning into .gemini/skills/cloud-provisioning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-provisioning", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills cloud-provisioningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill cloud-provisioning -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/provisioning .github/skills/cloud-provisioning && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cloud-provisioning" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/provisioning into .github/skills/cloud-provisioning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-provisioning", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill cloud-provisioning -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills cloud-provisioning --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/provisioning .opencode/skills/cloud-provisioning && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cloud-provisioning" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/cloud/provisioning into .opencode/skills/cloud-provisioning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-provisioning", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cloud-provisioningProvision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS…
Cloud Provisioning is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS PrivateLink network security); and manage the lifecycle of Elastic Cloud Hosted deployments. Use when creating or performing day-2 operations on serverless projects or hosted deployments, or restricting their network access.
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/api-reference.md`, `references/credentials-and-context.md` and `references/hosted-deployments.md`). Compatibility notes: Requires the elastic CLI (= 0.2) with cloud serverless and cloud hosted support and network access to the Elastic Cloud API (api.elastic-cloud.com)…
It sits in Backend & APIs, covering Serverless, Deployment and Search implementation. It works with Elasticsearch and Amazon Web Services. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comcloud.elastic.coFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires the `elastic` CLI (>= 0.2) with `cloud serverless` and `cloud hosted` support and network access to the Elastic Cloud API (api.elastic-cloud.com). Serverless operations apply to Elastic Cloud Serverless; deployment operations apply to Elastic Cloud Hosted. Depends on a configured Cloud context (see cloud-onboarding).
From compatibility in the SKILL.md frontmatter.
Cloud Provisioning loads about 5.4k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 2,140 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 2,140 words, ~5,417 tokens.
.claude/skills/cloud-provisioning/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Provision and run Elastic Cloud infrastructure through the Cloud API: Serverless projects (create and day-2 operations), traffic filters (network security for those projects), and Elastic Cloud Hosted deployments. For configuring Cloud authentication and managing organization access, use the cloud-onboarding skill.
<!-- begin-partial: cloud-preamble -->
This skill operates the Elastic Cloud control plane through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, bypass the CLI to call the HTTP API directly, or attempt other workarounds.
Control-plane operations authenticate against the Elastic Cloud API (organization scope), not a single stack deployment.
The elastic CLI reads this from its active context, which stores an Elastic Cloud API key in the OS keychain. If a
control-plane call fails with an authentication error, the context is missing or lacks a Cloud API key — instruct the
user to add one, and never ask the user to paste an API key into the chat:
"Configure an Elastic Cloud context for the
elasticCLI, then re-run. Generate an Organization-level key at Elastic Cloud API keys and register it without echoing the secret in chat."
This skill references control-plane operations in HTTP-shorthand form with the cloud: prefix (e.g.,
GET cloud:/api/v1/organizations, POST cloud:/api/v1/serverless/projects/elasticsearch). The
Operations table at the end of this document maps each shorthand to the equivalent elastic cloud
command — always use the CLI rather than calling the HTTP API directly. Discover the organization ID from
GET cloud:/api/v1/organizations; do not ask the user for it.
<!-- end-partial: cloud-preamble -->
admin password returned on creation or reset exists solely to create a
scoped API key. Never use admin credentials for ongoing Elasticsearch operations — mint a scoped key first.initializing; wait until initialized before using it.| Type | Description | Included services |
|---|---|---|
elasticsearch | Search, analytics, and vector workloads | Elasticsearch, Kibana |
observability | Logs, metrics, traces, and APM | Elasticsearch, Kibana, APM, OTLP |
security | SIEM, endpoint protection, cloud security | Elasticsearch, Kibana, OTLP |
Map the user's request to the correct type; never silently default — infer from context and confirm, or ask when
ambiguous. "search"/"elasticsearch"/vector search → elasticsearch; "o11y"/logs/metrics/traces/APM → observability;
"SIEM"/detections/endpoint → security.
Tiers and optimization. Elasticsearch: set optimized_for to general_purpose (default) unless the user explicitly
requests vector. Observability: set product_tier to complete (default) or logs_essentials. Security: set
product_types tiers to complete (default) or essentials per product line (security, cloud, endpoint). See
references/api-reference.md for the full request-body schema of each type.
gcp-us-central1), and the tier/optimization for the type — and get explicit confirmation. If the region is
uncertain, list options with GET cloud:/api/v1/serverless/regions first; only regions with
project_creation_enabled: true accept new projects. Region is permanent.POST cloud:/api/v1/serverless/projects/{type} with the confirmed body. Wait for the
initialized phase and persist the returned credentials into a named CLI context (the password goes to the OS
keychain, never to stdout or chat).GET cloud:/api/v1/serverless/projects/{type}/{id}/status until phase is initialized. The Elasticsearch and
Kibana endpoints in the creation response are safe to share; the password is not.POST /_security/api_key (the project's Elasticsearch endpoint), then rely on that key
for all data-plane work. If the elasticsearch-authn skill is available, use it for full key lifecycle handling.Use this when the user asks to query or manage a project not created in the current session. It applies to Elastic Cloud Serverless projects only — if the cluster is self-managed or Elastic Cloud Hosted, use the Hosted deployment workflow or skip. If unsure, ask: "Is your Elasticsearch instance an Elastic Cloud Serverless project?"
GET cloud:/api/v1/serverless/projects/{type}. Match
the user's reference (name or alias). If multiple or none match, present candidates and ask.GET cloud:/api/v1/serverless/projects/{type}/{id} to get
its Elasticsearch and Kibana endpoints, and select or create a CLI context bound to it.GET /_security/_authenticate
(expect "authentication_type": "api_key"). If none works, confirm with the user, reset the admin bootstrap
credentials with POST cloud:/api/v1/serverless/projects/{type}/{id}/_reset-credentials, use the admin password once
to create a scoped key via POST /_security/api_key, persist it to the context, re-verify, and drop the admin
credentials.GET cloud:/api/v1/serverless/projects/{type}.GET cloud:/api/v1/serverless/projects/{type}/{id}.PATCH cloud:/api/v1/serverless/projects/{type}/{id}.POST cloud:/api/v1/serverless/projects/{type}/{id}/_reset-credentials.DELETE cloud:/api/v1/serverless/projects/{type}/{id}.initialized:
POST cloud:/api/v1/serverless/projects/{type}/{id}/_resume.Update fields and their risks. Supported PATCH fields: name, alias, metadata.tags, traffic_filters, and —
for Elasticsearch — search_lake.search_power (28–3000) and search_lake.boost_window (1–180 days); for Security —
data-retention limits.
GET first and include any the user wants to keep.search_power drives cost. Higher values increase VCU consumption. Warn and confirm before raising it (presets:
28 on-demand, 100 performant, 250 high availability).Traffic filters restrict network access to Serverless projects. The Elastic Cloud UI calls this network security;
the Cloud API uses traffic filters (traffic-filters in paths, traffic_filters in project JSON). The two types
are IP filters (type ip, allowlist IPs/CIDRs) and VPC filters (type vpce, AWS PrivateLink endpoint IDs).
Private connectivity in AWS is accepted by default. A VPC filter is only needed to restrict traffic to specific endpoint IDs. If you only need private connectivity (not filtering), create the VPC endpoint and DNS record in AWS — no filter is required. Use
GET cloud:/api/v1/serverless/traffic-filters/metadatato look up the PrivateLink service name for a region before creating the endpoint in AWS.
GET cloud:/api/v1/serverless/traffic-filters (optionally scoped
by region). If a filter already covers the same sources for the same purpose, reuse it — filters are
region-scoped and can attach to many projects.POST cloud:/api/v1/serverless/traffic-filters with the type, region, and rules.
The response contains the generated filter id.PATCH cloud:/api/v1/serverless/projects/{type}/{id} with a traffic_filters array). Provide the complete list
of filter IDs; any ID omitted is disassociated.GET the project to confirm the change took effect.Filter guidance: filters are region-scoped (a filter can only attach to projects in its region). Updating rules
replaces the entire rule set — include all existing rules plus the new one. A filter cannot be deleted while still
associated with a project — disassociate first, then DELETE cloud:/api/v1/serverless/traffic-filters/{id}.
include_by_default auto-attaches a filter to all new projects in the region — use with caution. See
references/traffic-filters.md for the full schemas.
Elastic Cloud Hosted deployments are full stack deployments (Elasticsearch, Kibana, and optional APM/Integrations Server/Enterprise Search) sized from a deployment template, distinct from Serverless projects. Manage their lifecycle through the Cloud API's deployment endpoints.
GET cloud:/api/v1/deployments/templates for the
target region and confirm the template and stack version with the user. Region is permanent.POST cloud:/api/v1/deployments with the resource definition (or a template_id).
The response returns the deployment ID and a one-time elastic user password and endpoints — persist the credentials
into a CLI context (keychain), never to chat.GET cloud:/api/v1/deployments/{id} until healthy, then mint a
scoped Elasticsearch API key via POST /_security/api_key and stop using the bootstrap elastic password. See
references/hosted-deployments.md for the create body and template schema.GET cloud:/api/v1/deployments.GET cloud:/api/v1/deployments/{id}.PUT cloud:/api/v1/deployments/{id}.POST cloud:/api/v1/deployments/{id}/_shutdown.POST cloud:/api/v1/deployments/{id}/_restore.Hosted deployments use their own traffic-filter rulesets, managed separately from the Serverless traffic filters above — do not mix the two. See references/hosted-deployments.md.
"Create a search project called acme-search" — confirm type elasticsearch, present the summary (name
acme-search, region gcp-us-central1, optimized_for general_purpose), and on confirmation call
POST cloud:/api/v1/serverless/projects/elasticsearch, wait for initialized, persist credentials, then create a
scoped API key with POST /_security/api_key.
"List my security projects" — call GET cloud:/api/v1/serverless/projects/security and present the names and IDs;
treat it as a read-only day-2 request.
"Connect to my search project prod-search" — list Elasticsearch projects, match prod-search, GET it for
endpoints, then verify or mint a scoped Elasticsearch API key before any data-plane work.
"Bump search power to 500 on my search project" — warn about the cost increase, confirm, then
PATCH cloud:/api/v1/serverless/projects/elasticsearch/{id} with search_lake.search_power = 500.
"Only allow our office network 203.0.113.0/24 to projects in us-east-1" — list existing filters for us-east-1,
create an ip filter with POST cloud:/api/v1/serverless/traffic-filters (rule source 203.0.113.0/24), then attach
the filter ID to the target projects via PATCH cloud:/api/v1/serverless/projects/{type}/{id}.
"Spin up a hosted deployment in us-east-1" — list templates with GET cloud:/api/v1/deployments/templates, confirm
the template and stack version, then POST cloud:/api/v1/deployments, wait until healthy, and mint a scoped API key.
general_purpose optimization and the complete
tier; only change on explicit request.| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET cloud:/api/v1/serverless/regions | elastic cloud serverless regions list-regions |
POST cloud:/api/v1/serverless/projects/elasticsearch | elastic cloud serverless projects search create --input-file <json> --wait --save-as <ctx> |
POST cloud:/api/v1/serverless/projects/observability | elastic cloud serverless projects observability create --input-file <json> --wait --save-as <ctx> |
POST cloud:/api/v1/serverless/projects/security | elastic cloud serverless projects security create --input-file <json> --wait --save-as <ctx> |
GET cloud:/api/v1/serverless/projects/elasticsearch | elastic cloud serverless projects search list |
GET cloud:/api/v1/serverless/projects/elasticsearch/{id} | elastic cloud serverless projects search get --id <id> |
GET cloud:/api/v1/serverless/projects/elasticsearch/{id}/status | elastic cloud serverless projects search get-status --id <id> |
PATCH cloud:/api/v1/serverless/projects/elasticsearch/{id} | elastic cloud serverless projects search patch --id <id> --input-file <json> |
DELETE cloud:/api/v1/serverless/projects/elasticsearch/{id} | elastic cloud serverless projects search delete --id <id> |
POST cloud:/api/v1/serverless/projects/elasticsearch/{id}/_reset-credentials | elastic cloud serverless projects search reset-credentials --id <id> --save-as <ctx> |
POST cloud:/api/v1/serverless/projects/elasticsearch/{id}/_resume | elastic cloud serverless projects search resume --id <id> |
GET cloud:/api/v1/serverless/traffic-filters | elastic cloud serverless traffic-filters list-traffic-filters --region <region> |
POST cloud:/api/v1/serverless/traffic-filters | elastic cloud serverless traffic-filters create-traffic-filter --input-file <json> |
GET cloud:/api/v1/serverless/traffic-filters/{id} | elastic cloud serverless traffic-filters get-traffic-filter --id <id> |
PATCH cloud:/api/v1/serverless/traffic-filters/{id} | elastic cloud serverless traffic-filters patch-traffic-filter --id <id> --input-file <json> |
DELETE cloud:/api/v1/serverless/traffic-filters/{id} | elastic cloud serverless traffic-filters delete-traffic-filter --id <id> |
GET cloud:/api/v1/serverless/traffic-filters/metadata | elastic cloud serverless traffic-filters get-traffic-filter-metadata --region <region> |
GET cloud:/api/v1/deployments/templates | elastic cloud hosted deployment-templates get-deployment-templates-v2 |
GET cloud:/api/v1/deployments | elastic cloud hosted deployments list-deployments |
POST cloud:/api/v1/deployments | elastic cloud hosted deployments create-deployment --input-file <json> |
GET cloud:/api/v1/deployments/{id} | elastic cloud hosted deployments get-deployment --deployment-id <id> |
PUT cloud:/api/v1/deployments/{id} | elastic cloud hosted deployments update-deployment --deployment-id <id> --input-file <json> |
POST cloud:/api/v1/deployments/{id}/_shutdown | elastic cloud hosted deployments shutdown-deployment --deployment-id <id> |
POST cloud:/api/v1/deployments/{id}/_restore | elastic cloud hosted deployments restore-deployment --deployment-id <id> |
GET /_security/_authenticate | elastic es security authenticate |
POST /_security/api_key | elastic es security create-api-key --input-file <json> |
Use the matching projects observability … / projects security … commands for observability and security project
types.
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/cloud/provisioning of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Cloud Provisioning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cloud Provisioning this skillelastic/agent-skills | 592 | — | ~5.4k | Automated safety check: Pass | Apache-2.0 | |
| Amazon Opensearch Serviceaws/agent-toolkit-for-aws | 2.8k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Model Deploymentawslabs/agent-plugins | 912 | 1 repos | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| AWS Serverless Deploymentawslabs/agent-plugins | 912 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Log Forwarding With Fluentdmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~697 | Automated safety check: Pass | Apache-2.0 | |
| AWS Sam Bootstrapgiuseppe-trisciuoglio/developer-kit | 355 | — | ~954 | Automated safety check: Notes | MIT |
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
awslabs/agent-plugins
Generates code that deploys fine-tuned models from SageMaker Serverless Model Customization to SageMaker endpoints or Bedrock.
awslabs/agent-plugins
AWS SAM and AWS CDK deployment for serverless applications. An agent skill from awslabs/agent-plugins.
mukul975/Anthropic-Cybersecurity-Skills
Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for…
giuseppe-trisciuoglio/developer-kit
Provides AWS SAM bootstrap patterns: generates template.yaml and samconfig.toml for new projects via sam init, creates SAM templates for existing Lambda/CloudFormation code migration, validates…
serithemage/serverless-openclaw
Deploys Serverless OpenClaw CDK stacks to AWS. An agent skill from serithemage/serverless-openclaw.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Works with
Categories
Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS…. Cloud Provisioning is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS PrivateLink network security); and manage the lifecycle of Elastic Cloud Hosted deployments.
Cloud Provisioning fits situations like: performing day-2 operations on serverless projects; hosted deployments; restricting their network access.
Run `npx skills add elastic/agent-skills --skill cloud-provisioning -a claude-code`. Or copy the skill folder (skills/cloud/provisioning in elastic/agent-skills) into .claude/skills/cloud-provisioning in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill cloud-provisioning -a codex`. Or copy the skill folder (skills/cloud/provisioning in elastic/agent-skills) into .agents/skills/cloud-provisioning in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill cloud-provisioning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-provisioning, .gemini/skills/cloud-provisioning, .github/skills/cloud-provisioning and .opencode/skills/cloud-provisioning in your project.
SKILL.md names no scripts, command-line tools or credentials: Cloud Provisioning is instructions for the agent only. Compatibility (from SKILL.md): Requires the `elastic` CLI (>= 0.2) with `cloud serverless` and `cloud hosted` support and network access to the Elastic Cloud API (api.elastic-cloud.com). Serverless operations apply to Elastic Cloud Serverless; deployment operations apply to Elastic Cloud Hosted. Depends on a configured Cloud context (see cloud-onboarding). .
SKILL.md names 2 domains. As links in the text: github.com and cloud.elastic.co. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cloud Provisioning is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Cloud Provisioning: Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Model Deployment (awslabs/agent-plugins, 912 stars), AWS Serverless Deployment (awslabs/agent-plugins, 912 stars) and Implementing Log Forwarding With Fluentd (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 2, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.