Official agent skill

AWS Well Architected Review

by github in github/awesome-copilot

Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

OfficialMITAuto-check passedDevOps & Cloud

Install AWS Well Architected Review

skills CLI
$ npx skills add github/awesome-copilot --skill aws-well-architected-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot aws-well-architected-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aws-well-architected-review .claude/skills/aws-well-architected-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-well-architected-review
GitHub stars
40k
Token cost
~1.9k tokens
SKILL.md length
698 words
Files
1
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

  • Works in 7 steps: Load Well-Architected Framework Reference → Discover IaC & Architecture → Pillar-by-Pillar Review → …
  • Tasks that involve Cloud architecture
  • SKILL.md covers Prerequisites, Workflow Steps, Error Handling and Success Criteria
  • Calls aws; reaches docs.aws.amazon.com

What it does

AWS Well Architected Review is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud architecture and Infrastructure as code. It works with Amazon Web Services and GitHub. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud architecture
  • Tasks that involve Infrastructure as code

Example prompts

  • “/aws-well-architected-review”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Load Well-Architected Framework Reference
  2. Discover IaC & Architecture
  3. Pillar-by-Pillar Review
  4. Risk Classification
  5. User Confirmation
  6. Create Individual Finding Issues
  7. Create EPIC Tracking Issue

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Well Architected Review loads about 1.9k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 698 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 698 words, ~1,891 tokens.

Download SKILL.mdSave it as .claude/skills/aws-well-architected-review/SKILL.md (or your agent's skills folder).
name
aws-well-architected-review
description
Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

AWS Well-Architected Review

This workflow performs a structured AWS Well-Architected Framework (WAF) review against your workload's IaC files and deployed infrastructure. It identifies risks across all 6 WAF pillars and creates GitHub issues to track remediation.

Prerequisites

  • AWS CLI configured and authenticated
  • IaC files present in the repository (Terraform, CloudFormation, CDK, or SAM)
  • GitHub MCP server configured and authenticated

Workflow Steps

Step 1: Load Well-Architected Framework Reference

Fetch current AWS WAF best practices:

  • https://docs.aws.amazon.com/wellarchitected/latest/framework/welcome.html
  • Pillar-specific lenses relevant to the workload type (Serverless, SaaS, etc.)
Step 2: Discover IaC & Architecture

Scan the repository for IaC files:

  • Terraform: **/*.tf
  • CloudFormation/SAM: **/*.yaml, **/*.json (CFn templates)
  • CDK: lib/**/*.ts, bin/**/*.ts, cdk.json

Identify key AWS services in use (compute, data, networking, security, observability) and generate a Mermaid architecture diagram.

Step 3: Pillar-by-Pillar Review
Pillar 1: Operational Excellence
  • All infrastructure defined as IaC (no manual console changes)
  • Consistent tagging strategy applied across all resources
  • CloudWatch alarms defined for key metrics
  • Automated deployment pipeline present (no manual deployments)
  • CloudTrail enabled for audit logging
  • Runbooks or operational documentation present
Pillar 2: Security
  • IAM roles use least-privilege policies (no * actions without justification)
  • No hardcoded credentials in IaC or code
  • Secrets managed via Secrets Manager or SSM Parameter Store
  • S3 buckets have public access blocked and server-side encryption enabled
  • Sensitive resources placed in private subnets
  • Security groups restrict inbound to minimum required ports/CIDRs
  • KMS encryption enabled for sensitive data stores (RDS, EBS, S3, SQS, DynamoDB)
  • SSL/TLS enforced on all endpoints (enforceSSL: true)
  • GuardDuty enabled (aws guardduty list-detectors)
  • AWS WAF configured on public-facing APIs and CloudFront distributions
  • MFA delete enabled on critical S3 buckets
Pillar 3: Reliability
  • Multi-AZ deployments for production databases (RDS Multi-AZ, DynamoDB Global Tables)
  • Auto Scaling configured with appropriate policies for EC2/ECS
  • S3 versioning and lifecycle policies configured
  • RDS automated backups enabled with appropriate retention period
  • DynamoDB Point-in-Time Recovery (PITR) enabled
  • Dead Letter Queues (DLQ) configured for Lambda, SQS, SNS
  • Route 53 health checks configured for DNS failover
  • Lambda reserved concurrency set to prevent noisy-neighbor throttling
Pillar 4: Performance Efficiency
  • Right-sized instance types (Lambda memory, EC2 type, RDS class)
  • Graviton/ARM instances used where available (Lambda arm64, EC2 Graviton)
  • Caching implemented (ElastiCache, DAX, CloudFront, API Gateway caching)
  • CloudFront used for global static content delivery
  • Aurora Serverless or DynamoDB On-Demand for variable load patterns
  • Lambda Provisioned Concurrency for latency-critical synchronous paths
Pillar 5: Cost Optimization
  • EC2 Reserved Instances or Savings Plans for steady-state workloads
  • S3 lifecycle policies moving data to cheaper storage tiers
  • Lambda arm64 architecture adopted (20% cost reduction)
  • VPC Endpoints for S3/DynamoDB to avoid NAT Gateway charges
  • gp2 EBS volumes migrated to gp3 (same performance, 20% cheaper)
  • Development/test environments have auto-shutdown schedules
  • AWS Budgets and Cost Anomaly Detection configured
  • Unattached EBS volumes and idle EC2 instances identified
Show full SKILL.md (250 more words)Show less
Pillar 6: Sustainability
  • Graviton/ARM instances selected where available
  • Serverless/managed services preferred over always-on EC2
  • S3 lifecycle policies reduce unnecessary long-term data storage
  • Auto Scaling configured to avoid over-provisioning
  • Region selection considers AWS renewable energy commitments
Step 4: Risk Classification

For each finding, classify:

  • High Risk: Security vulnerability, single point of failure, no backup/recovery
  • Medium Risk: Suboptimal reliability, cost inefficiency, performance concern
  • Low Risk: Best practice deviation, minor optimization opportunity
Step 5: User Confirmation
🏗️ AWS Well-Architected Review Summary

📊 Review Results:
• IaC Files Analyzed: X
• AWS Services Identified: Y
• Total Findings: Z
  • High Risk: A (immediate action required)
  • Medium Risk: B (should address soon)
  • Low Risk: C (nice to have)

🔴 Top High Risk Findings:
1. [Pillar]: [Finding] — [Why it matters]
2. [Pillar]: [Finding] — [Why it matters]

💡 This will create Z individual GitHub issues + 1 EPIC issue.

❓ Proceed with creating GitHub issues? (y/n)
Step 6: Create Individual Finding Issues

Label with "well-architected" and the pillar name (e.g., "security", "reliability").

Title: [WAF-<PILLAR>] [Brief Finding] — [Risk Level]

Body:

markdown
## 🏗️ Well-Architected Finding: [Brief Title]

**Pillar**: [Name] | **Risk Level**: [High/Medium/Low] | **Effort**: [Low/Medium/High]

### 📋 Description
[Clear explanation of the finding and why it matters]

### 🔧 Remediation

**IaC Fix** (preferred):
```hcl
# Terraform example
resource "aws_s3_bucket_server_side_encryption_configuration" "example" {
  bucket = aws_s3_bucket.example.id
  rule {
    apply_server_side_encryption_by_default {
      sse_algorithm = "aws:kms"
    }
  }
}
```

**AWS CLI fallback**:
```bash
aws s3api put-bucket-encryption --bucket <name> \
  --server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"aws:kms"}}]}'
```

### 📚 AWS Reference
- [WAF Best Practice Link]
- [AWS Documentation Link]

### ✅ Validation
- [ ] Change implemented in IaC and deployed
- [ ] AWS Config rule passes (if applicable)
- [ ] Security Hub finding resolved (if applicable)

**Well-Architected Question**: [WAF question this maps to]
Step 7: Create EPIC Tracking Issue

Label with "well-architected" and "epic".

Title: [EPIC] AWS Well-Architected Review — X findings across 6 pillars

Body: Executive summary with pillar breakdown table (finding counts by pillar and risk level), Mermaid architecture diagram, prioritized checklist linking all individual issues (High → Medium → Low), and success criteria:

  • All High-risk findings resolved
  • Medium findings have accepted mitigation plans
  • No regression in existing CloudWatch alarms or Config rules

Error Handling

  • No IaC Files Found: Limit review to live resource discovery via AWS CLI and note the gap
  • Insufficient AWS Permissions: List required read-only permissions for the review
  • GitHub Creation Failure: Output all findings as formatted markdown to console

Success Criteria

  • ✅ All 6 WAF pillars reviewed against IaC and live infrastructure
  • ✅ All findings classified by risk level and pillar
  • ✅ Actionable remediation steps with IaC examples for each finding
  • ✅ GitHub issues created for team tracking
  • ✅ Architecture diagram generated for EPIC context
  • ✅ AWS documentation references included

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/aws-well-architected-review of github/awesome-copilot.

Open the folder on GitHubat commit 727ff2e

Compare with similar skills

AWS Well Architected Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Well Architected Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Well Architected Review this skillgithub/awesome-copilot40k—~1.9kAutomated safety check: PassMIT
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0
AWS Solution Architectalirezarezvani/claude-skills28k1 repos~2.5kAutomated safety check: PassMIT
Terraform Module Librarywshobson/agents40k10 repos~1.3kAutomated safety check: PassMIT
Cloud Architectdavila7/claude-code-templates32k7 repos~1.9kAutomated safety check: PassMIT
Terraform EngineerJeffallan/claude-skills12k—~1.4kAutomated safety check: PassMIT

Similar skills

  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated 17 days ago
    DevOps & CloudAuto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    DevOps & CloudAuto-check passed
  • Build reusable, tested Terraform modules for AWS, Azure, GCP and OCI, with a standard file layout, an AWS VPC example, versioning rules and Terratest checks.

    40k GitHub starsUsed in 10 repos~1.3k tokens
    DevOps & CloudAuto-check passed
  • Cloud Architect

    davila7/claude-code-templates

    Expert cloud architect specializing in AWS/Azure/GCP multi-cloud infrastructure design, advanced IaC (Terraform/OpenTofu/CDK), FinOps cost optimization, and modern architectural patterns.

    32k GitHub starsUsed in 7 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Terraform Engineer

    Jeffallan/claude-skills

    Writes reusable Terraform modules and manages state, providers and environments across AWS, Azure and GCP, with validation, plan review and explicit apply approval.

    12k GitHub stars~1.4k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • AWS Architecture Diagram

    awslabs/agent-plugins

    Official

    Generate validated AWS architecture diagrams as draw.io XML using official AWS4 icon libraries.

    912 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about AWS Well Architected Review

What does AWS Well Architected Review do?

Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements. AWS Well Architected Review is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

When should I use AWS Well Architected Review?

AWS Well Architected Review fits situations like: tasks that involve Cloud architecture; tasks that involve Infrastructure as code.

How do I install AWS Well Architected Review in Claude Code?

Run `npx skills add github/awesome-copilot --skill aws-well-architected-review -a claude-code`. Or copy the skill folder (skills/aws-well-architected-review in github/awesome-copilot) into .claude/skills/aws-well-architected-review in your project. Claude Code loads it when a task matches its description.

How do I install AWS Well Architected Review in Codex?

Run `npx skills add github/awesome-copilot --skill aws-well-architected-review -a codex`. Or copy the skill folder (skills/aws-well-architected-review in github/awesome-copilot) into .agents/skills/aws-well-architected-review in your project. Codex loads it when a task matches its description.

Can I use AWS Well Architected Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill aws-well-architected-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-well-architected-review, .gemini/skills/aws-well-architected-review, .github/skills/aws-well-architected-review and .opencode/skills/aws-well-architected-review in your project.

What does AWS Well Architected Review need to run?

Going by SKILL.md and its folder, AWS Well Architected Review needs the command-line tools its instructions call (aws).

Does AWS Well Architected Review access the network?

SKILL.md names 1 domain. In commands or code: docs.aws.amazon.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is AWS Well Architected Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Well Architected Review use?

AWS Well Architected Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Well Architected Review use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AWS Well Architected Review?

Skills that share tags, products or a category with AWS Well Architected Review: AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars), AWS Solution Architect (alirezarezvani/claude-skills, 28k stars), Terraform Module Library (wshobson/agents, 40k stars) and Cloud Architect (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Well Architected Review?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.