Agent skill

AWS Cloudwatch Monitoring

by Hack23 in Hack23/cia

AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

Apache-2.0Auto-check passedDevOps & Cloud

Install AWS Cloudwatch Monitoring

skills CLI
$ npx skills add Hack23/cia --skill aws-cloudwatch-monitoring -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia aws-cloudwatch-monitoring --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/aws-cloudwatch-monitoring .claude/skills/aws-cloudwatch-monitoring && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-cloudwatch-monitoring
GitHub stars
239
Token cost
~1.9k tokens
SKILL.md length
326 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

  • DevOps & Cloud work in your project
  • SKILL.md covers Purpose, When to Use, Patterns & Examples and ISMS Compliance Mapping, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

AWS Cloudwatch Monitoring is an agent skill from Hack23/cia. AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Amazon Web Services. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/aws-cloudwatch-monitoring”

What it can do on your machine

Read from SKILL.md and the folder at commit 677b32c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java, yaml, json and sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Cloudwatch Monitoring loads about 1.9k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 326 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 677b32c, republished under its Apache-2.0 licence (© Hack23). 326 words, ~1,914 tokens.

Download SKILL.mdSave it as .claude/skills/aws-cloudwatch-monitoring/SKILL.md (or your agent's skills folder).
name
aws-cloudwatch-monitoring
description
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
license
Apache-2.0

AWS CloudWatch Monitoring

Purpose

This skill provides guidance for monitoring the CIA platform using AWS CloudWatch, including metrics collection, alarm configuration, dashboard creation, log analysis, and performance troubleshooting. Ensures proactive detection of issues and compliance with monitoring requirements.

When to Use

✅ Use this skill when:
  • Setting up monitoring for new services or features
  • Creating custom metrics for business KPIs
  • Configuring alarms for critical thresholds
  • Building operational dashboards
  • Analyzing application logs for errors
  • Troubleshooting performance issues
  • Implementing distributed tracing
  • Meeting compliance monitoring requirements
❌ Don't use this skill for:
  • Application code implementation (use stack-specialist)
  • Security incident response (use threat-modeling)
  • Database performance tuning (use postgresql-operations)
  • CI/CD pipeline configuration (use github-actions-workflows)

Patterns & Examples

Custom Metrics for Political Data
java
// Spring Boot - Micrometer integration with CloudWatch
@Service
public class PoliticianMetricsService {
    private final MeterRegistry meterRegistry;
    
    @Autowired
    public PoliticianMetricsService(MeterRegistry meterRegistry) {
        this.meterRegistry = meterRegistry;
    }
    
    public void recordRiskScoreCalculation(String politicianId, double score) {
        // Custom metric: risk score distribution
        meterRegistry.gauge("cia.politician.risk_score", 
            Tags.of("politician_id", politicianId), 
            score);
            
        // Counter: total risk calculations
        meterRegistry.counter("cia.risk_calculations.total",
            Tags.of("result", score > 70 ? "high" : "normal"))
            .increment();
    }
    
    public void recordDataSourceRefresh(String source, boolean success) {
        // Timer: data source refresh duration
        Timer.builder("cia.datasource.refresh.duration")
            .tag("source", source)
            .tag("status", success ? "success" : "failure")
            .register(meterRegistry)
            .record(() -> {
                // Refresh logic here
            });
    }
}
CloudWatch Alarms Configuration
yaml
# CloudFormation/Terraform - Critical Alarms
Resources:
  HighErrorRateAlarm:
    Type: AWS::CloudWatch::Alarm
    Properties:
      AlarmName: CIA-HighErrorRate
      AlarmDescription: Alert when error rate exceeds 5%
      MetricName: Errors
      Namespace: AWS/Lambda
      Statistic: Sum
      Period: 300
      EvaluationPeriods: 2
      Threshold: 50
      ComparisonOperator: GreaterThanThreshold
      AlarmActions:
        - !Ref SNSTopicARN
      
  DatabaseConnectionPoolExhausted:
    Type: AWS::CloudWatch::Alarm
    Properties:
      AlarmName: CIA-DBConnectionPoolExhausted
      MetricName: DatabaseConnectionsInUse
      Namespace: CIA/Database
      Statistic: Maximum
      Period: 60
      EvaluationPeriods: 1
      Threshold: 90  # 90% of max connections
      ComparisonOperator: GreaterThanThreshold
      
  RiskScoreCalculationLatency:
    Type: AWS::CloudWatch::Alarm
    Properties:
      AlarmName: CIA-RiskScoreHighLatency
      MetricName: RiskScoreCalculationDuration
      Namespace: CIA/Application
      Statistic: p99
      Period: 300
      EvaluationPeriods: 2
      Threshold: 5000  # 5 seconds
      ComparisonOperator: GreaterThanThreshold
CloudWatch Dashboard
json
{
  "widgets": [
    {
      "type": "metric",
      "properties": {
        "title": "CIA Platform Health",
        "metrics": [
          [ "CIA/Application", "RequestCount", { "stat": "Sum" } ],
          [ ".", "ErrorCount", { "stat": "Sum", "color": "#d62728" } ],
          [ ".", "ResponseTime", { "stat": "Average" } ]
        ],
        "period": 300,
        "region": "eu-north-1",
        "yAxis": {
          "left": { "min": 0 }
        }
      }
    },
    {
      "type": "metric",
      "properties": {
        "title": "Political Data Processing",
        "metrics": [
          [ "CIA/DataIngestion", "RiksdagenAPICallsTotal" ],
          [ ".", "ValDataRefreshSuccess" ],
          [ ".", "WorldBankDataSync" ]
        ]
      }
    },
    {
      "type": "log",
      "properties": {
        "title": "Recent Errors",
        "query": "SOURCE '/aws/lambda/cia-app' | fields @timestamp, @message | filter @message like /ERROR/ | sort @timestamp desc | limit 20",
        "region": "eu-north-1"
      }
    }
  ]
}
Log Insights Queries
sql
-- Top 10 slowest API endpoints
fields @timestamp, request.path, request.duration_ms
| filter request.duration_ms > 1000
| sort request.duration_ms desc
| limit 10

-- Error rate by endpoint
fields request.path, response.status_code
| filter response.status_code >= 500
| stats count() as error_count by request.path
| sort error_count desc

-- Risk score calculation performance
fields @timestamp, politician_id, calculation_duration_ms
| filter event_type = "risk_score_calculated"
| stats avg(calculation_duration_ms) as avg_duration, 
        max(calculation_duration_ms) as max_duration,
        count() as total_calculations
  by bin(5m)

ISMS Compliance Mapping

ISO 27001:2022 Annex A Controls

A.8.16 - Monitoring activities

  • Continuous monitoring of system activities
  • Log aggregation and analysis
  • Anomaly detection and alerting

A.8.15 - Logging

  • Centralized log management
  • Log retention policies (90 days minimum)
  • Log integrity and protection

A.8.8 - Management of technical vulnerabilities

  • Performance degradation monitoring
  • Capacity planning metrics
  • Availability tracking
NIST Cybersecurity Framework 2.0

Detect (DE)

  • DE.CM-01: Network monitored for anomalous activity
  • DE.CM-07: Monitoring for unauthorized activity
  • DE.AE-03: Event data aggregated and correlated

Respond (RS)

  • RS.AN-03: Analysis performed to establish impact
  • RS.CO-02: Incidents reported per established criteria
CIS Controls v8

Control 8: Audit Log Management

  • 8.2: Collect audit logs
  • 8.3: Standardize time synchronization
  • 8.11: Conduct audit log reviews

Control 12: Network Infrastructure Management

  • 12.8: Establish and maintain dedicated network infrastructure

Hack23 ISMS Policy References

References

Internal CIA Documentation
AWS Documentation

Remember

  • Proactive monitoring: Set alarms before incidents occur
  • Context-rich metrics: Tag metrics with relevant dimensions
  • Cost optimization: Use metric filters to reduce costs
  • Log retention: Comply with 90-day minimum retention
  • Dashboard visibility: Operational dashboards for NOC
  • Alerting hygiene: Reduce false positives, tune thresholds

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/aws-cloudwatch-monitoring of Hack23/cia.

Open the folder on GitHubat commit 677b32c

Compare with similar skills

AWS Cloudwatch Monitoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Cloudwatch Monitoring compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Cloudwatch Monitoring this skillHack23/cia239—~1.9kAutomated safety check: PassApache-2.0
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Review Docshashicorp/terraform-provider-aws11k—~1.3kAutomated safety check: PassMPL-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only

Similar skills

  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Review Docs

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…

    11k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Business continuity and disaster recovery: 30-day retention, quarterly restore tests, RTO/RPO targets per ISO 27001 A.17

    239 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about AWS Cloudwatch Monitoring

What does AWS Cloudwatch Monitoring do?

AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform. AWS Cloudwatch Monitoring is an agent skill from Hack23/cia.

When should I use AWS Cloudwatch Monitoring?

AWS Cloudwatch Monitoring fits situations like: devOps & Cloud work in your project.

How do I install AWS Cloudwatch Monitoring in Claude Code?

Run `npx skills add Hack23/cia --skill aws-cloudwatch-monitoring -a claude-code`. Or copy the skill folder (.github/skills/aws-cloudwatch-monitoring in Hack23/cia) into .claude/skills/aws-cloudwatch-monitoring in your project. Claude Code loads it when a task matches its description.

How do I install AWS Cloudwatch Monitoring in Codex?

Run `npx skills add Hack23/cia --skill aws-cloudwatch-monitoring -a codex`. Or copy the skill folder (.github/skills/aws-cloudwatch-monitoring in Hack23/cia) into .agents/skills/aws-cloudwatch-monitoring in your project. Codex loads it when a task matches its description.

Can I use AWS Cloudwatch Monitoring in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill aws-cloudwatch-monitoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-cloudwatch-monitoring, .gemini/skills/aws-cloudwatch-monitoring, .github/skills/aws-cloudwatch-monitoring and .opencode/skills/aws-cloudwatch-monitoring in your project.

What does AWS Cloudwatch Monitoring need to run?

SKILL.md names no scripts, command-line tools or credentials: AWS Cloudwatch Monitoring is instructions for the agent only.

Does AWS Cloudwatch Monitoring access the network?

SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and github.com. This is read from the text; nothing was executed.

Is AWS Cloudwatch Monitoring safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Cloudwatch Monitoring use?

AWS Cloudwatch Monitoring is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Cloudwatch Monitoring use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AWS Cloudwatch Monitoring?

Skills that share tags, products or a category with AWS Cloudwatch Monitoring: Cloud Cost Optimization (wshobson/agents, 40k stars), Review Docs (hashicorp/terraform-provider-aws, 11k stars), AWS Cdk Development (zxkane/aws-skills, 367 stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Cloudwatch Monitoring?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 10, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.