AWS Cdk Development
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
Provides AWS CloudFormation patterns for IAM roles, policies, managed policies, permission boundaries, and trust relationships.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-cloudformation-iam --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam .claude/skills/aws-cloudformation-iam && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aws-cloudformation-iam" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam into .claude/skills/aws-cloudformation-iam/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-cloudformation-iam", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iamType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-cloudformation-iam --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam .agents/skills/aws-cloudformation-iam && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aws-cloudformation-iam" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam into .agents/skills/aws-cloudformation-iam/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-cloudformation-iam", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-cloudformation-iam --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam .cursor/skills/aws-cloudformation-iam && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aws-cloudformation-iam" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam into .cursor/skills/aws-cloudformation-iam/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-cloudformation-iam", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/giuseppe-trisciuoglio/developer-kit.git --path plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-cloudformation-iam --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam .gemini/skills/aws-cloudformation-iam && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aws-cloudformation-iam" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam into .gemini/skills/aws-cloudformation-iam/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-cloudformation-iam", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-cloudformation-iamInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam .github/skills/aws-cloudformation-iam && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aws-cloudformation-iam" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam into .github/skills/aws-cloudformation-iam/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-cloudformation-iam", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-cloudformation-iam --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam .opencode/skills/aws-cloudformation-iam && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aws-cloudformation-iam" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam into .opencode/skills/aws-cloudformation-iam/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-cloudformation-iam", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aws-cloudformation-iamProvides AWS CloudFormation patterns for IAM roles, policies, managed policies, permission boundaries, and trust relationships.
AWS Cloudformation Iam is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides AWS CloudFormation patterns for IAM roles, policies, managed policies, permission boundaries, and trust relationships. Use when modeling least-privilege access, cross-account assumptions, service roles, or reusable IAM stacks that other CloudFormation templates consume.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/reference.md`).
It sits in DevOps & Cloud, covering Infrastructure as code. It works with AWS CloudFormation. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteBashFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awsFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AWS Cloudformation Iam loads about 1.5k tokens when it runs, and up to ~24k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 503 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Write, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 503 words, ~1,468 tokens.
.claude/skills/aws-cloudformation-iam/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Use this skill to model IAM with CloudFormation in a way that stays secure, auditable, and maintainable.
The most important design concerns are:
Do not treat SKILL.md as a full IAM encyclopedia. Use the bundled references for larger policy examples and service-specific variants.
Identify who or what assumes the role (service principal, cross-account principal, or federated identity), then write the trust policy with explicit principals and conditions before adding permissions.
Use inline policies for role-specific access; use managed policies for shared patterns across principals. Scope actions and resources tightly, and use conditions where possible.
Use permission boundaries when teams create or extend roles in their own stacks, when guardrails are needed around privileged services (IAM, KMS, Organizations), or to separate maximum allowed permissions from application-specific policies.
Name roles and policies consistently so stack outputs and audits remain easy to trace.
For cross-account roles: trust only the exact source account or principal, add sts:ExternalId conditions when appropriate, keep permission and trust policies separate, and export only the ARNs that consuming accounts need.
Before rollout, use these commands to verify the template and IAM behavior:
# Validate CloudFormation template syntax
aws cloudformation validate-template --template-body file://template.yaml
# Preview changes before applying
aws cloudformation create-change-set \
--stack-name <stack-name> \
--template-body file://template.yaml \
--change-set-type CREATE
# Simulate whether a principal can perform specific actions
aws iam simulate-principal-policy \
--policy-source-arn arn:aws:iam::123456789012:role/LambdaExecutionRole \
--action-names dynamodb:GetItem dynamodb:PutItem
# Check for wildcards in IAM policies within the template
aws cloudformation list-stack-resources --stack-name <stack-name>After deployment, confirm policy attachments and stack outputs match the intended security model.
Resources:
LambdaExecutionRole:
Type: AWS::IAM::Role
Properties:
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
Service: lambda.amazonaws.com
Action: sts:AssumeRole
Policies:
- PolicyName: DynamoDbWritePolicy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- dynamodb:GetItem
- dynamodb:PutItem
Resource: !GetAtt OrdersTable.ArnResources:
PartnerReadRole:
Type: AWS::IAM::Role
Properties:
AssumeRolePolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
AWS: arn:aws:iam::123456789012:role/partner-reader
Action: sts:AssumeRole
Condition:
StringEquals:
sts:ExternalId: partner-contract-001Keep the trust relationship narrow and pair it with a separate read-only permission policy.
references/ instead of bloating the root skill.references/examples.mdreferences/reference.mdaws-cloudformation-securityaws-cloudformation-ec2aws-cloudformation-ecsaws-cloudformation-lambda© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam of giuseppe-trisciuoglio/developer-kit.
Open the folder on GitHubat commit fe73fb3
AWS Cloudformation Iam next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AWS Cloudformation Iam this skillgiuseppe-trisciuoglio/developer-kit | 357 | — | ~1.5k | Automated safety check: Notes | MIT | |
| AWS Cdk Developmentzxkane/aws-skills | 367 | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| AWS Cloud Advisortech-leads-club/agent-skills | 7k | — | ~2.1k | Automated safety check: Pass | CC-BY-4.0 | |
| AWS Native Runtime Investigationpulumi/pulumi-aws-native | 108 | — | ~753 | Automated safety check: Pass | Apache-2.0 | |
| Cloudformationitsmostafa/aws-agent-skills | 1.2k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Hunt Bugsgo-to-k/cdkd | 146 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 |
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
tech-leads-club/agent-skills
Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.
pulumi/pulumi-aws-native
Use after triage or repository evidence establishes that an issue involves Pulumi AWS Native runtime behavior across the Pulumi provider protocol, generated CloudFormation metadata, and AWS Cloud…
itsmostafa/aws-agent-skills
AWS CloudFormation infrastructure as code for stack management.
go-to-k/cdkd
Proactively hunt for cdkd bugs by deploying real CDK apps that exercise common-but-untested AWS resources, configs, and CloudFormation notations against real AWS, then fix what breaks.
cyberful/cyberful
Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.
giuseppe-trisciuoglio/developer-kit
Generates complete CRUD modules for NestJS applications with Drizzle ORM.
giuseppe-trisciuoglio/developer-kit
Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.
giuseppe-trisciuoglio/developer-kit
Provides and generates complete CRUD workflows for Spring Boot 3 services.
giuseppe-trisciuoglio/developer-kit
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…
giuseppe-trisciuoglio/developer-kit
Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.
giuseppe-trisciuoglio/developer-kit
Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.
Works with
Categories
Provides AWS CloudFormation patterns for IAM roles, policies, managed policies, permission boundaries, and trust relationships. AWS Cloudformation Iam is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides AWS CloudFormation patterns for IAM roles, policies, managed policies, permission boundaries, and trust relationships.
AWS Cloudformation Iam fits situations like: modeling least-privilege access; cross-account assumptions; reusable IAM stacks that other CloudFormation templates consume.
Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a claude-code`. Or copy the skill folder (plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam in giuseppe-trisciuoglio/developer-kit) into .claude/skills/aws-cloudformation-iam in your project. Claude Code loads it when a task matches its description.
Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a codex`. Or copy the skill folder (plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam in giuseppe-trisciuoglio/developer-kit) into .agents/skills/aws-cloudformation-iam in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-iam -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-cloudformation-iam, .gemini/skills/aws-cloudformation-iam, .github/skills/aws-cloudformation-iam and .opencode/skills/aws-cloudformation-iam in your project.
Going by SKILL.md and its folder, AWS Cloudformation Iam needs the command-line tools its instructions call (aws). Its frontmatter pre-approves these tools: Read, Write, Bash.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
AWS Cloudformation Iam is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AWS Cloudformation Iam: AWS Cdk Development (zxkane/aws-skills, 367 stars), AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars), AWS Native Runtime Investigation (pulumi/pulumi-aws-native, 108 stars) and Cloudformation (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.
Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.