Agent skill

Cleanup

by go-to-k in go-to-k/cdkd

Detect and delete leftover AWS resources from cdkd integration tests.

Apache-2.0Auto-check passedTesting & QA

Install Cleanup

skills CLI
$ npx skills add go-to-k/cdkd --skill cleanup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install go-to-k/cdkd cleanup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/go-to-k/cdkd.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cleanup .claude/skills/cleanup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cleanup
GitHub stars
146
Token cost
~3.2k tokens
SKILL.md length
1,372 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect and delete leftover AWS resources from cdkd integration tests.

  • Works in 3 steps: Determine stack name prefixes to scan:… → Resolve region and account: scan… → Check S3 state: aws s3 ls…
  • Tasks that involve Integration testing
  • SKILL.md covers Safety, Arguments, Steps and Important
  • Calls aws

What it does

Cleanup is an agent skill from go-to-k/cdkd. Detect and delete leftover AWS resources from cdkd integration tests. Only targets resources matching known cdkd stack name patterns.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Integration testing. It works with Amazon Web Services, AWS CloudFormation and Amazon S3. The repository describes itself as: Drop-in CDK CLI for existing CDK apps — up to 15x faster deploys via direct AWS SDK calls instead of CloudFormation. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Integration testing

Example prompts

  • “/cleanup”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Determine stack name prefixes to scan: the given prefix, else discover every integ stack name by synthesizing or reading bin/app.ts in…
  2. Resolve region and account: scan us-east-1, ap-northeast-1 AND us-west-2 — the benchmark suite runs its variant stacks in the third, and…
  3. Check S3 state: aws s3 ls s3://cdkd-state-{accountId}/cdkd/ --recursive --region us-east-1 | grep state.json (also the legacy…

What it can do on your machine

Read from SKILL.md and the folder at commit aefb343. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cleanup loads about 3.2k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 1,372 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from go-to-k/cdkd at commit aefb343, republished under its Apache-2.0 licence (© go-to-k). 1,372 words, ~3,186 tokens.

Download SKILL.mdSave it as .claude/skills/cleanup/SKILL.md (or your agent's skills folder).
name
cleanup
description
Detect and delete leftover AWS resources from cdkd integration tests. Only targets resources matching known cdkd stack name patterns.
argument-hint
[stack-name-prefix] [--detect-only]

Leftover Resource Cleanup

Detect and optionally delete AWS resources left behind by cdkd integration tests.

Safety

  • ONLY targets resources whose names match a cdkd integ stack prefix; NEVER one that does not match a known cdkd naming pattern.
  • Always show what will be deleted and confirm via AskUserQuestion first.
  • Detect-only is the DEFAULT.

Arguments

  • stack-name-prefix: one prefix (e.g. EcrStack); absent, scan all known cdkd test stack prefixes.
  • --detect-only: list only, the default.

Steps

  1. Determine stack name prefixes to scan: the given prefix, else discover every integ stack name by synthesizing or reading bin/app.ts in each tests/integration/*/ — the construct ID is the second argument to new *Stack(app, '<id>').

  2. Resolve region and account: scan us-east-1, ap-northeast-1 AND us-west-2 — the benchmark suite runs its variant stacks in the third, and its leftovers (billed PROVISIONED Kinesis streams, Lambda log groups) are invisible to a two-region scan. Derive any further regions from the state-bucket key layout (aws s3 ls recursively, collect the distinct {region} segments) so a fixture pinned elsewhere is not missed. Account id via aws sts get-caller-identity; IAM is global, so one query.

  3. Check S3 state: aws s3 ls s3://cdkd-state-{accountId}/cdkd/ --recursive --region us-east-1 | grep state.json (also the legacy cdkd-state-{accountId}-{region} bucket if it exists)

3.5. Bulk-sweep orphaned deployment-event stores: cdkd destroy / cdkd state destroy removes state.json but, unless --purge-events was passed, INTENTIONALLY leaves the cdkd/{stack}/{region}/deployments/ event store behind (post-mortem history). After a long integ campaign those orphaned event stores accumulate across dozens of already-destroyed stacks, so aws s3 ls .../cdkd/ is never empty even when there are no real state / resource leaks. This step bulk-removes them. Safety: only a prefix that has a deployments/ child AND NO state.json under any region is an orphan — a prefix that still has a state.json is an ACTIVE (deployed, not destroyed) stack and MUST be left untouched (its deployments/ is live history).

Resolve the state bucket(s) (cdkd-state-{accountId} current default; also the legacy cdkd-state-{accountId}-{region} if present), then per bucket:

bash
BUCKET="cdkd-state-{accountId}"
# List each top-level prefix under cdkd/ (one per stack), skip the exports index.
for p in $(aws s3 ls "s3://${BUCKET}/cdkd/" --region us-east-1 | awk '{print $2}' | grep '/$' | grep -v '^_index/'); do
  listing=$(aws s3 ls "s3://${BUCKET}/cdkd/${p}" --recursive --region us-east-1 2>/dev/null)
  has_state=$(echo "$listing" | grep -c 'state.json')
  has_dep=$(echo "$listing" | grep -c 'deployments/')
  # An ACTIVE stack still has a state.json somewhere under the prefix.
  if [ "$has_state" -eq 0 ] && [ "$has_dep" -gt 0 ]; then
    echo "ORPHAN event store (no state.json): cdkd/${p}"
  fi
done

Report the orphan list, confirm via AskUserQuestion (unless --detect-only), then delete each confirmed orphan prefix with aws s3 rm "s3://${BUCKET}/cdkd/${p}" --recursive --region us-east-1. Re-run the has_state check immediately before each delete to guard against a concurrent deploy that re-created the stack. The per-stack product-level equivalent (for a user who knows the stack name) is cdkd events prune '<stack>' --all; this skill step is the bucket-wide bulk sweep for integ-test hygiene.

  1. Scan AWS resources for each stack name prefix, in both exact case and lowercase (some services lowercase names). Every command below takes --region <region> for each region from step 2 — it is omitted from the rows to keep them readable, and IAM is global.

    • IAM Roles: aws iam list-roles --query 'Roles[?contains(RoleName, \{Prefix}`)].{Name:RoleName,Arn:Arn}'`
    • IAM Policies: aws iam list-policies --scope Local --query 'Policies[?contains(PolicyName, \{Prefix}`)].{Name:PolicyName,Arn:Arn}'`
    • Lambda Functions: aws lambda list-functions --query 'Functions[?contains(FunctionName, \{Prefix}`)].FunctionName'`
    • S3 Buckets: aws s3api list-buckets --query 'Buckets[?contains(Name, \{prefix}`)].Name'`
    • DynamoDB Tables: aws dynamodb list-tables --query 'TableNames[?contains(@, \{Prefix}`)]'`
    • ECR Repositories: aws ecr describe-repositories --query 'repositories[?contains(repositoryName, \{prefix}`)].repositoryName'`
    • SQS Queues: aws sqs list-queues --queue-name-prefix {Prefix} (if supported)
    • SNS Topics: aws sns list-topics then filter by prefix
    • CloudWatch Log Groups: aws logs describe-log-groups --log-group-name-prefix /aws/lambda/{Prefix}, and also --log-group-name-prefix /cdkd-integ/ — a fixture needing a sweepable, fixture-owned name puts its log groups there rather than under cdkd's generated /cdkd/, which is shared with every fixture and cannot be swept safely. One under /cdkd-integ/ whose fixture is not running is a leftover. Check deletionProtectionEnabled first: aws logs delete-log-group on a protected group fails with InvalidParameterException ... LogGroup has delete protection enabled, so clear it —
      bash
      aws logs put-log-group-deletion-protection \
        --log-group-identifier {name} --no-deletion-protection-enabled
      aws logs delete-log-group --region us-east-1 --log-group-name {name}
      A run killed between a fixture's protect and destroy phases leaves exactly that shape, and without the flip-off it is unreachable by every other step here.
    • Security Groups: aws ec2 describe-security-groups --filters "Name=group-name,Values=*{Prefix}*" --query 'SecurityGroups[].{Id:GroupId,Name:GroupName}'
    • VPCs: aws ec2 describe-vpcs --filters "Name=tag:Name,Values=*{Prefix}*" --query 'Vpcs[].{Id:VpcId,Name:Tags[?Key==\Name`].Value|[0]}'`
    • Kinesis Data Streams: aws kinesis list-streams --query 'StreamNames[?contains(@, \{Prefix}`)]'. **Provisioned streams bill continuously**, so surface these first. Delete: aws kinesis delete-stream --stream-name {name}`.
    • Kinesis Firehose delivery streams: aws firehose list-delivery-streams --query 'DeliveryStreamNames[?contains(@, \{Prefix}`)]'. Delete: aws firehose delete-delivery-stream --delivery-stream-name {name}`.
    • EventBridge Pipes: aws pipes list-pipes --query 'Pipes[?contains(Name, \{Prefix}`)].Name'. Delete: aws pipes delete-pipe --name {name}`.
    • EventBridge Scheduler schedules: aws scheduler list-schedules --query 'Schedules[?contains(Name, \{Prefix}`)].Name'. Delete: aws scheduler delete-schedule --name {name}`.
    • Synthetics canaries: aws synthetics describe-canaries --query 'Canaries[?contains(Name, \{prefix}`)].{Name:Name,Id:Id}'(canary names are lowercased). Stop if running, then delete withaws synthetics delete-canary --name {name}`.
    • Cognito User Pools: aws cognito-idp list-user-pools --max-results 60 --query 'UserPools[?contains(Name, \{Prefix}`)].{Name:Name,Id:Id}'. Delete: aws cognito-idp delete-user-pool --user-pool-id {id}`.
    • Secrets Manager secrets: aws secretsmanager list-secrets --query 'SecretList[?contains(Name, \{Prefix}`)].{Name:Name,Arn:ARN}'. Delete: aws secretsmanager delete-secret --secret-id {arn} --force-delete-without-recovery`.
    • Step Functions state machines: aws stepfunctions list-state-machines --query 'stateMachines[?contains(name, \{Prefix}`)].{Name:name,Arn:stateMachineArn}'. Delete: aws stepfunctions delete-state-machine --state-machine-arn {arn}`.
    • FSx final backups: a destroyed AWS::FSx::FileSystem may leave a chargeable final backup behind — cdkd's destroy keeps CFn parity (DeleteFileSystem with API defaults, which TAKE one), and AutomaticBackupRetentionDays: 0 does NOT prevent it. They usually carry NO tags, so the prefix scans miss them. List ALL backups:
      bash
      aws fsx describe-backups \
        --query 'Backups[].{Id:BackupId,FsId:FileSystem.FileSystemId,Type:FileSystem.FileSystemType,Cap:FileSystem.StorageCapacity,Created:CreationTime,BackupTags:Tags,FsTags:FileSystem.Tags}'
      Safety (FSx-specific): a backup is delete-eligible ONLY when its own Tags or the persisted FileSystem.Tags match a cdkd fixture pattern (aws:cdk:path, a Cdkd* stack name). Never auto-delete an untagged one — tags are unreliable here by design and the backup may be an intentional safety net; SURFACE it in the report (BackupId, FileSystemId, type, capacity, creation time) for the maintainer to decide. Delete a confirmed leftover: aws fsx delete-backup --backup-id {id}.
    • Backup vaults: aws backup list-backup-vaults --query 'BackupVaultList[?contains(BackupVaultName, \{Prefix}`)].BackupVaultName'. A vault with recovery points cannot be deleted until they are removed (list-recovery-points-by-backup-vault→delete-recovery-point), then aws backup delete-backup-vault --backup-vault-name {name}`.
    • KMS customer keys: enumerate then filter — these are never auto-deleted and each enabled key bills ~$1/mo:
      bash
      for id in $(aws kms list-keys --query 'Keys[].KeyId' --output text); do
        meta=$(aws kms describe-key --key-id "$id" \
          --query 'KeyMetadata.{Mgr:KeyManager,State:KeyState,Desc:Description}' --output json)
        # Keep only CUSTOMER-managed, Enabled keys whose Description matches a cdkd pattern
        echo "$meta" | grep -q '"Mgr": "CUSTOMER"' || continue
        echo "$meta" | grep -q '"State": "Enabled"' || continue
        echo "$meta" | grep -qi 'cdkd\|bughunt' || continue
        echo "KMS candidate: $id -> $meta"
      done
      Safety (KMS-specific, MUST hold): only KeyManager==CUSTOMER AND KeyState==Enabled keys (never touch AWS-managed keys, and skip anything already PendingDeletion); match cdkd origin via the key Description (integ keys carry descriptions like ... cdkd #609 integ / bughunt sweep11 key A) or tags (aws kms list-resource-tags). Skip any key that is the active API Gateway account CloudWatch role key, or that has active grants (aws kms list-grants --key-id {id}) or aliases (aws kms list-aliases --key-id {id}). KMS keys cannot be deleted immediately — schedule deletion with aws kms schedule-key-deletion --key-id {id} --pending-window-in-days 7 (7 is the minimum window) and surface the returned DeletionDate in the report.
    • IAM Roles — API Gateway account-level CloudWatch roles survive stack destroy: they are referenced by the account-level apigateway CloudWatch-role-ARN setting, not the stack. They match the general IAM-role scan, but before deleting one confirm via aws apigateway get-account that it is not the ARN currently set on the account; if it is, unset it there first.
  2. Report findings: a table of detected resources grouped by type.

  3. If deletion is requested (not --detect-only): show the full list and confirm via AskUserQuestion, delete in reverse dependency order (Lambda before IAM Role, Subnet before VPC), and report each result.

    • IAM Roles: detach all policies first. For an API Gateway account CloudWatch role, confirm via aws apigateway get-account that it is not the active account-level ARN.
    • S3 Buckets: empty first, only when the name matches a cdkd pattern.
    • ECR Repositories: --force.
    • KMS keys: deletion is scheduled, not immediate — schedule-key-deletion --pending-window-in-days 7 returns a DeletionDate; report it. Never touch AWS-managed keys or keys with grants / aliases.
    • Backup vaults: delete all recovery points first.
    • Synthetics canaries: stop a running canary first.
Show full SKILL.md (95 more words)Show less

Important

  • INTEGRATION TEST resources only; never one that could belong to another project, and when in doubt ask via AskUserQuestion.
  • A /aws/lambda/ log group is created by Lambda itself and is safe to remove when the function name matches.
  • Cost-bearing leftovers come first in the report: Kinesis provisioned streams, enabled KMS customer keys and FSx final backups all bill continuously and are not auto-deleted on stack destroy. The FSx ones are the sneakiest — usually untagged and invisible to a prefix scan.
  • KMS is scheduled-deletion only — 7 days minimum, billing throughout, so always report the DeletionDate.

© go-to-k, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/cleanup of go-to-k/cdkd.

Open the folder on GitHubat commit aefb343

Compare with similar skills

Cleanup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cleanup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cleanup this skillgo-to-k/cdkd146—~3.2kAutomated safety check: PassApache-2.0
New Event Sourceaws/aws-lambda-dotnet1.7k—~3kAutomated safety check: PassApache-2.0
Review Testshashicorp/terraform-provider-aws11k—~908Automated safety check: PassMPL-2.0
Review Tests Helpershashicorp/terraform-provider-aws11k—~994Automated safety check: PassMPL-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Extend Commands APIredis/lettuce5.8k—~7.7kAutomated safety check: NotesMIT

Similar skills

  • New Event Source

    aws/aws-lambda-dotnet

    Official

    Add a new AWS event source attribute (e.g., Kinesis, Kafka, MQ) to the Lambda .NET Annotations framework, including the attribute class, source generator integration, CloudFormation writer, unit…

    1.7k GitHub stars~3k tokensUpdated today
    Testing & QAAuto-check passed
  • Review Tests

    hashicorp/terraform-provider-aws

    Official

    Review Terraform AWS Provider acceptance and unit test basics: required basic and disappears tests, TestAcc naming, TestCase essentials (PreCheck/ErrorCheck/ProtoV5ProviderFactories/CheckDestroy)…

    11k GitHub stars~908 tokensUpdated today
    Testing & QAAuto-check passed
  • Review Tests Helpers

    hashicorp/terraform-provider-aws

    Official

    Review Terraform AWS Provider test helpers: Exists/Destroy check functions, exportstest.go wiring, create.Error wrapping, data source tests, list resource tests (querycheck + Terraform version…

    11k GitHub stars~994 tokensUpdated today
    Testing & QAAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Extend Commands API

    redis/lettuce

    Official

    Add or extend Redis commands in the Lettuce client API end-to-end — a new core command, a family of new commands, an extension to an existing command's options, or a module/area command…

    5.8k GitHub stars~7.7k tokensUpdated today
    DatabasesAuto-check: notes
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from go-to-k/cdkd

All 14 skills in this repo
  • Hunt Bugs

    go-to-k/cdkd

    Proactively hunt for cdkd bugs by deploying real CDK apps that exercise common-but-untested AWS resources, configs, and CloudFormation notations against real AWS, then fix what breaks.

    146 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Use Cdkd

    go-to-k/cdkd

    Build the current cdkd checkout and use it from another CDK project.

    146 GitHub stars~669 tokensUpdated today
    Auto-check passed
  • Verify PR

    go-to-k/cdkd

    Comprehensive PR readiness check before merge. An agent skill from go-to-k/cdkd.

    146 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Work Issues

    go-to-k/cdkd

    Work through already-filed GitHub issues (typically the bug-hunt's output) end to end — triage safely, pick as many FILE-DISJOINT issues as the run can carry, claim each on the issue before starting…

    146 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Cdkd

    go-to-k/cdkd

    Install cdkd and use it safely from an AWS CDK project. An agent skill from go-to-k/cdkd.

    146 GitHub stars~7k tokensUpdated today
    Auto-check: notes
  • Run Integ

    go-to-k/cdkd

    Run integration tests (deploy + destroy) against real AWS. An agent skill from go-to-k/cdkd.

    146 GitHub stars~5.8k tokensUpdated today
    Auto-check passed

Questions about Cleanup

What does Cleanup do?

Detect and delete leftover AWS resources from cdkd integration tests. Cleanup is an agent skill from go-to-k/cdkd. Detect and delete leftover AWS resources from cdkd integration tests.

When should I use Cleanup?

Cleanup fits situations like: tasks that involve Integration testing.

How do I install Cleanup in Claude Code?

Run `npx skills add go-to-k/cdkd --skill cleanup -a claude-code`. Or copy the skill folder (.claude/skills/cleanup in go-to-k/cdkd) into .claude/skills/cleanup in your project. Claude Code loads it when a task matches its description.

How do I install Cleanup in Codex?

Run `npx skills add go-to-k/cdkd --skill cleanup -a codex`. Or copy the skill folder (.claude/skills/cleanup in go-to-k/cdkd) into .agents/skills/cleanup in your project. Codex loads it when a task matches its description.

Can I use Cleanup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add go-to-k/cdkd --skill cleanup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cleanup, .gemini/skills/cleanup, .github/skills/cleanup and .opencode/skills/cleanup in your project.

What does Cleanup need to run?

Going by SKILL.md and its folder, Cleanup needs the command-line tools its instructions call (aws).

Does Cleanup access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cleanup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cleanup use?

Cleanup is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cleanup use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cleanup?

Skills that share tags, products or a category with Cleanup: New Event Source (aws/aws-lambda-dotnet, 1.7k stars), Review Tests (hashicorp/terraform-provider-aws, 11k stars), Review Tests Helpers (hashicorp/terraform-provider-aws, 11k stars) and AWS Cdk Development (zxkane/aws-skills, 367 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cleanup?

go-to-k (a GitHub user) maintains it in go-to-k/cdkd, which has 146 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.

Source: go-to-k/cdkd on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.