Official agent skill

Hf Cloud AWS Context Discovery

by huggingface in huggingface/skills

Discover the user's local AWS context (active profile, region, account ID, caller identity) at the start of any AWS task.

OfficialApache-2.0Auto-check: warningsDevOps & Cloud

Install Hf Cloud AWS Context Discovery

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add huggingface/skills --skill hf-cloud-aws-context-discovery -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install huggingface/skills hf-cloud-aws-context-discovery --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/huggingface/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hf-cloud-aws-context-discovery .claude/skills/hf-cloud-aws-context-discovery && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hf-cloud-aws-context-discovery
GitHub stars
11k
Used in
2 other repos
Token cost
~989 tokens
SKILL.md length
431 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
Apache-2.0

At a glance

Discover the user's local AWS context (active profile, region, account ID, caller identity) at the start of any AWS task.

  • Works in 4 steps: Active profile → Region → Credentials, account ID, caller ARN → …
  • Has not specified a region
  • SKILL.md covers What to discover, Commands to run and What to report back
  • Calls aws

What it does

Hf Cloud AWS Context Discovery is an agent skill from huggingface/skills, published by the product's own GitHub organization. Discover the user's local AWS context (active profile, region, account ID, caller identity) at the start of any AWS task. Use this skill before any other AWS work — deploying to SageMaker, creating resources, calling AWS APIs, or anything that touches an AWS account. Use it especially when the user has not specified a region or profile explicitly, when they say things like "use my AWS account", "deploy to AWS", "use my profile", or when about to make any AWS CLI or SDK call. Never guess the region or account ID —…

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Authentication. It works with Amazon Web Services and Amazon SageMaker. The repository describes itself as: Give your agents the power of the Hugging Face ecosystem. The licence is Apache-2.0.

When your agent uses it

  • Has not specified a region
  • Profile explicitly
  • They say things like use my AWS account
  • About to make any AWS CLI

Example prompts

  • “use my AWS account”
  • “deploy to AWS”
  • “use my profile”
  • “/hf-cloud-aws-context-discovery”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Active profile
  2. Region
  3. Credentials, account ID, caller ARN
  4. Identify SSO / assumed-role principals

What it can do on your machine

Read from SKILL.md and the folder at commit ca0325b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hf Cloud AWS Context Discovery loads about 989 tokens when it runs. Until then it costs about 155 tokens; SKILL.md has 431 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~989

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:64
    list profiles), `~/.aws/config` and `~/.aws/credentials` are plain INI files — read-only.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from huggingface/skills at commit ca0325b, republished under its Apache-2.0 licence (© huggingface). 431 words, ~989 tokens.

Download SKILL.mdSave it as .claude/skills/hf-cloud-aws-context-discovery/SKILL.md (or your agent's skills folder).
name
hf-cloud-aws-context-discovery
description
Discover the user's local AWS context (active profile, region, account ID, caller identity) at the start of any AWS task. Use this skill before any other AWS work — deploying to SageMaker, creating resources, calling AWS APIs, or anything that touches an AWS account. Use it especially when the user has not specified a region or profile explicitly, when they say things like "use my AWS account", "deploy to AWS", "use my profile", or when about to make any AWS CLI or SDK call. Never guess the region or account ID — always use this skill to read it from the local configuration first.

AWS Context Discovery

Before doing any AWS work, read the user's local AWS config. Don't guess the region, and don't ask the user for things their config already answers.

What to discover

Run these at the start of the AWS work and remember the results for the rest of the session.

1. Active profile

AWS_PROFILE env var, else default. If the user mentioned a profile in their prompt, that overrides. If the named profile doesn't exist in ~/.aws/config, surface that clearly.

2. Region

Resolution order — stop at the first one that produces a value:

  1. Region the user explicitly named in this conversation
  2. AWS_REGION env var
  3. AWS_DEFAULT_REGION env var
  4. region field on the active profile in ~/.aws/config
  5. Ask the user — but only after the first four have failed

Do not fall back to us-east-1 or any other hardcoded default.

3. Credentials, account ID, caller ARN
bash
aws sts get-caller-identity --profile <profile> --region <region>

Three purposes in one call: confirms credentials are valid (stop if not), returns the Account ID (needed for ARN construction), returns the Arn of the caller.

4. Identify SSO / assumed-role principals

The Arn field tells you what kind of principal this is. The pattern matters because it determines what IAM operations the caller can do.

ARN patternTypeIAM write capability
arn:aws:iam::<acct>:user/<name>IAM userDepends on attached policies
arn:aws:sts::<acct>:assumed-role/AWSReservedSSO_<...>/<email>SSO assumed-roleTypically none — can't create/modify IAM roles
arn:aws:sts::<acct>:assumed-role/<role>/<session>Regular assumed-roleDepends on the role

If the caller is SSO, surface this immediately before later skills hit iam:CreateRole and fail:

Heads up: you're authenticated via SSO (AWSReservedSSO_<PermissionSet>_...). SSO principals usually can't create IAM roles directly. If we need a SageMaker execution role, I'll look for an existing one first — if none exists, you'll need to ask whoever manages your AWS access to create one.

This is the highest-leverage thing this skill does. Surfacing it now turns a confusing mid-deployment error into a five-second conversation.

Show full SKILL.md (119 more words)Show less

Commands to run

bash
# Effective profile and region (faster than parsing config files)
aws configure list

# Validate credentials and get identity
aws sts get-caller-identity
aws sts get-caller-identity --profile <profile-name>  # if a profile was named

aws configure list handles env-var overrides and shows the resolved effective values. Prefer it over parsing ~/.aws/config yourself. If you need to read raw config (e.g. to list profiles), ~/.aws/config and ~/.aws/credentials are plain INI files — read-only.

What to report back

One or two lines, not a wall of text:

Working with profile my-profile in eu-west-1, account 123456789012. You're authenticated via SSO, so we'll need to use an existing IAM role rather than create one.

Don't ask the user to confirm the region you just read from their config — they configured it; that is the confirmation.

If something is wrong (credentials expired, profile doesn't exist, no region anywhere), stop and surface the specific error before continuing.

© huggingface, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hf-cloud-aws-context-discovery of huggingface/skills.

Open the folder on GitHubat commit ca0325b

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in huggingface/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hf Cloud AWS Context Discovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hf Cloud AWS Context Discovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hf Cloud AWS Context Discovery this skillhuggingface/skills11k2 repos~989Automated safety check: WarnApache-2.0
Hyperpod Issue Reportawslabs/agent-plugins9151 repos~890Automated safety check: PassApache-2.0
Sagemaker AI Ops Reviewaws/tools-for-devops-agent1001 repos~3.9kAutomated safety check: PassApache-2.0
SDK Getting Startedawslabs/agent-plugins9151 repos~248Automated safety check: PassApache-2.0
Scanning For Hardcoded Secretsjeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT
Troubleshootaws-samples/sample-autonomous-cloud-coding-agents157—~2.7kAutomated safety check: PassMIT-0

Similar skills

  • Hyperpod Issue Report

    awslabs/agent-plugins

    Official

    Generate comprehensive issue reports from HyperPod clusters (EKS and Slurm) by collecting diagnostic logs and configurations for troubleshooting and AWS Support cases.

    915 GitHub starsUsed in 1 repo~890 tokens
    DevOps & CloudAuto-check passed
  • Sagemaker AI Ops Review

    aws/tools-for-devops-agent

    Official

    Amazon SageMaker AI Operational Review. An agent skill from aws/tools-for-devops-agent.

    100 GitHub starsUsed in 1 repo~3.9k tokens
    DevOps & CloudAuto-check passed
  • SDK Getting Started

    awslabs/agent-plugins

    Official

    Validates the user's environment for SageMaker AI operations — checks SDK version, AWS region, and execution role.

    915 GitHub starsUsed in 1 repo~248 tokens
    DevOps & CloudAuto-check passed
  • Scanning For Hardcoded Secrets

    jeremylongshore/tons-of-skills-marketplace

    Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing secrets, generic…

    2.8k GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Troubleshoot

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Diagnose and fix common ABCA issues: deployment failures, preflight errors, authentication problems, agent failures, and build issues.

    157 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Hf Cloud AWS Context Discovery

    sickn33/agentic-awesome-skills

    Discover the effective local AWS profile, region, account, and caller identity before any AWS task without exposing credentials.

    47k GitHub starsUsed in 1 repo~1.2k tokens
    DevOps & CloudAuto-check: warnings

More from huggingface/skills

All 25 skills in this repo
  • Official

    Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create.

    11k GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Official

    Chooses the right serving container and current image URI for deploying a Hugging Face model to a SageMaker endpoint, preferring Hugging Face images over generic ones.

    11k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Hugging Face LLM Trainer

    huggingface/skills

    Official

    Trains or fine-tunes language and vision models with TRL or Unsloth on Hugging Face Jobs cloud GPUs, then converts the results to GGUF.

    11k GitHub starsUsed in 3 repos~7.2k tokens
    Auto-check passed
  • Official

    Routes a sentence-transformers training task to the right model type and required reference docs and example scripts, covering bi-encoders, rerankers, sparse and multi-vector models.

    11k GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Official

    Sets up an isolated Python environment with a supported interpreter and current boto3 before any SageMaker deployment, training or AWS automation code runs.

    11k GitHub starsUsed in 2 repos~1.7k tokens
    Auto-check passed
  • Official

    Runs evaluations of Hugging Face Hub models on local hardware with inspect-ai or lighteval, and helps choose between vLLM, Transformers and accelerate backends.

    11k GitHub starsUsed in 2 repos~1.6k tokens
    Auto-check passed

Categories

Questions about Hf Cloud AWS Context Discovery

What does Hf Cloud AWS Context Discovery do?

Discover the user's local AWS context (active profile, region, account ID, caller identity) at the start of any AWS task. Hf Cloud AWS Context Discovery is an agent skill from huggingface/skills, published by the product's own GitHub organization. Discover the user's local AWS context (active profile, region, account ID, caller identity) at the start of any AWS task.

When should I use Hf Cloud AWS Context Discovery?

Hf Cloud AWS Context Discovery fits situations like: has not specified a region; profile explicitly; they say things like use my AWS account; about to make any AWS CLI.

How do I install Hf Cloud AWS Context Discovery in Claude Code?

Run `npx skills add huggingface/skills --skill hf-cloud-aws-context-discovery -a claude-code`. Or copy the skill folder (skills/hf-cloud-aws-context-discovery in huggingface/skills) into .claude/skills/hf-cloud-aws-context-discovery in your project. Claude Code loads it when a task matches its description.

How do I install Hf Cloud AWS Context Discovery in Codex?

Run `npx skills add huggingface/skills --skill hf-cloud-aws-context-discovery -a codex`. Or copy the skill folder (skills/hf-cloud-aws-context-discovery in huggingface/skills) into .agents/skills/hf-cloud-aws-context-discovery in your project. Codex loads it when a task matches its description.

Can I use Hf Cloud AWS Context Discovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add huggingface/skills --skill hf-cloud-aws-context-discovery -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hf-cloud-aws-context-discovery, .gemini/skills/hf-cloud-aws-context-discovery, .github/skills/hf-cloud-aws-context-discovery and .opencode/skills/hf-cloud-aws-context-discovery in your project.

What does Hf Cloud AWS Context Discovery need to run?

Going by SKILL.md and its folder, Hf Cloud AWS Context Discovery needs the command-line tools its instructions call (aws).

Does Hf Cloud AWS Context Discovery access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hf Cloud AWS Context Discovery safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Hf Cloud AWS Context Discovery use?

Hf Cloud AWS Context Discovery is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hf Cloud AWS Context Discovery use?

About 989 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hf Cloud AWS Context Discovery?

Skills that share tags, products or a category with Hf Cloud AWS Context Discovery: Hyperpod Issue Report (awslabs/agent-plugins, 915 stars), Sagemaker AI Ops Review (aws/tools-for-devops-agent, 100 stars), SDK Getting Started (awslabs/agent-plugins, 915 stars) and Scanning For Hardcoded Secrets (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hf Cloud AWS Context Discovery?

huggingface (a GitHub organization, an official publisher) maintains it in huggingface/skills, which has 11,148 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 1, 2026.

Source: huggingface/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.