Iam Audit
briiirussell/cybersecurity-skills
Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
$ npx skills add itsmostafa/aws-agent-skills --skill cognito -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install itsmostafa/aws-agent-skills cognito --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cognito .claude/skills/cognito && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cognito" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/cognito into .claude/skills/cognito/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognito", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/cognitoType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add itsmostafa/aws-agent-skills --skill cognito -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install itsmostafa/aws-agent-skills cognito --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cognito .agents/skills/cognito && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cognito" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/cognito into .agents/skills/cognito/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognito", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add itsmostafa/aws-agent-skills --skill cognito -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install itsmostafa/aws-agent-skills cognito --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cognito .cursor/skills/cognito && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cognito" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/cognito into .cursor/skills/cognito/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognito", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/itsmostafa/aws-agent-skills.git --path skills/cognito--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add itsmostafa/aws-agent-skills --skill cognito -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install itsmostafa/aws-agent-skills cognito --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cognito .gemini/skills/cognito && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cognito" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/cognito into .gemini/skills/cognito/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognito", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install itsmostafa/aws-agent-skills cognitoInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add itsmostafa/aws-agent-skills --skill cognito -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cognito .github/skills/cognito && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cognito" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/cognito into .github/skills/cognito/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognito", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add itsmostafa/aws-agent-skills --skill cognito -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install itsmostafa/aws-agent-skills cognito --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cognito .opencode/skills/cognito && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cognito" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/cognito into .opencode/skills/cognito/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognito", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cognitoAWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
Cognito is an agent skill from itsmostafa/aws-agent-skills. AWS Cognito user authentication and authorization service. Use when setting up user pools, configuring identity pools, implementing OAuth flows, managing user attributes, or integrating with social identity providers.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `auth-flows.md`).
It sits in Backend & APIs, covering OAuth and OpenID Connect, Authentication and Authorization and RBAC. It works with Amazon Web Services. The repository describes itself as: AWS Skills for Agents. The licence is MIT.
Read from SKILL.md and the folder at commit e786d25. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awsFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
cognito-idp.us-east-1.amazonaws.comAlso links to:
docs.aws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
REFRESH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cognito loads about 2.3k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 397 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from itsmostafa/aws-agent-skills at commit e786d25, republished under its MIT licence (© itsmostafa). 397 words, ~2,306 tokens.
.claude/skills/cognito/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Amazon Cognito provides authentication, authorization, and user management for web and mobile applications. Users can sign in directly or through federated identity providers.
User directory for sign-up and sign-in. Provides:
Provide temporary AWS credentials to access AWS services. Users can be:
| Token | Purpose | Lifetime |
|---|---|---|
| ID Token | User identity claims | 1 hour |
| Access Token | API authorization | 1 hour |
| Refresh Token | Get new ID/Access tokens | 30 days (configurable) |
AWS CLI:
aws cognito-idp create-user-pool \
--pool-name my-app-users \
--policies '{
"PasswordPolicy": {
"MinimumLength": 12,
"RequireUppercase": true,
"RequireLowercase": true,
"RequireNumbers": true,
"RequireSymbols": true
}
}' \
--auto-verified-attributes email \
--username-attributes email \
--mfa-configuration OPTIONAL \
--user-attribute-update-settings '{
"AttributesRequireVerificationBeforeUpdate": ["email"]
}'aws cognito-idp create-user-pool-client \
--user-pool-id us-east-1_abc123 \
--client-name my-web-app \
--generate-secret \
--explicit-auth-flows ALLOW_USER_SRP_AUTH ALLOW_REFRESH_TOKEN_AUTH \
--supported-identity-providers COGNITO \
--callback-urls https://myapp.com/callback \
--logout-urls https://myapp.com/logout \
--allowed-o-auth-flows code \
--allowed-o-auth-scopes openid email profile \
--allowed-o-auth-flows-user-pool-client \
--access-token-validity 60 \
--id-token-validity 60 \
--refresh-token-validity 30 \
--token-validity-units '{
"AccessToken": "minutes",
"IdToken": "minutes",
"RefreshToken": "days"
}'import boto3
import hmac
import hashlib
import base64
cognito = boto3.client('cognito-idp')
def get_secret_hash(username, client_id, client_secret):
message = username + client_id
dig = hmac.new(
client_secret.encode('utf-8'),
message.encode('utf-8'),
digestmod=hashlib.sha256
).digest()
return base64.b64encode(dig).decode()
response = cognito.sign_up(
ClientId='client-id',
SecretHash=get_secret_hash('user@example.com', 'client-id', 'client-secret'),
Username='user@example.com',
Password='SecurePassword123!',
UserAttributes=[
{'Name': 'email', 'Value': 'user@example.com'},
{'Name': 'name', 'Value': 'John Doe'}
]
)cognito.confirm_sign_up(
ClientId='client-id',
SecretHash=get_secret_hash('user@example.com', 'client-id', 'client-secret'),
Username='user@example.com',
ConfirmationCode='123456'
)response = cognito.initiate_auth(
ClientId='client-id',
AuthFlow='USER_SRP_AUTH',
AuthParameters={
'USERNAME': 'user@example.com',
'SECRET_HASH': get_secret_hash('user@example.com', 'client-id', 'client-secret'),
'SRP_A': srp_a # From SRP library
}
)
# For simple password auth (not recommended for production)
response = cognito.admin_initiate_auth(
UserPoolId='us-east-1_abc123',
ClientId='client-id',
AuthFlow='ADMIN_USER_PASSWORD_AUTH',
AuthParameters={
'USERNAME': 'user@example.com',
'PASSWORD': 'password',
'SECRET_HASH': get_secret_hash('user@example.com', 'client-id', 'client-secret')
}
)
tokens = response['AuthenticationResult']
id_token = tokens['IdToken']
access_token = tokens['AccessToken']
refresh_token = tokens['RefreshToken']response = cognito.initiate_auth(
ClientId='client-id',
AuthFlow='REFRESH_TOKEN_AUTH',
AuthParameters={
'REFRESH_TOKEN': refresh_token,
'SECRET_HASH': get_secret_hash('user@example.com', 'client-id', 'client-secret')
}
)aws cognito-identity create-identity-pool \
--identity-pool-name my-app-identities \
--allow-unauthenticated-identities \
--cognito-identity-providers \
ProviderName=cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123,\
ClientId=client-id,\
ServerSideTokenCheck=trueimport boto3
cognito_identity = boto3.client('cognito-identity')
# Get identity ID
response = cognito_identity.get_id(
IdentityPoolId='us-east-1:12345678-1234-1234-1234-123456789012',
Logins={
'cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123': id_token
}
)
identity_id = response['IdentityId']
# Get credentials
response = cognito_identity.get_credentials_for_identity(
IdentityId=identity_id,
Logins={
'cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123': id_token
}
)
credentials = response['Credentials']
# Use credentials['AccessKeyId'], credentials['SecretKey'], credentials['SessionToken']| Command | Description |
|---|---|
aws cognito-idp create-user-pool | Create user pool |
aws cognito-idp describe-user-pool | Get pool details |
aws cognito-idp update-user-pool | Update pool settings |
aws cognito-idp delete-user-pool | Delete pool |
aws cognito-idp list-user-pools | List pools |
| Command | Description |
|---|---|
aws cognito-idp admin-create-user | Create user (admin) |
aws cognito-idp admin-delete-user | Delete user |
aws cognito-idp admin-get-user | Get user details |
aws cognito-idp list-users | List users |
aws cognito-idp admin-set-user-password | Set password |
aws cognito-idp admin-disable-user | Disable user |
| Command | Description |
|---|---|
aws cognito-idp initiate-auth | Start authentication |
aws cognito-idp respond-to-auth-challenge | Respond to MFA |
aws cognito-idp admin-initiate-auth | Admin authentication |
Causes:
Debug:
aws cognito-idp admin-get-user \
--user-pool-id us-east-1_abc123 \
--username user@example.comCauses:
Validate JWT:
import jwt
import requests
# Get JWKS
jwks_url = f'https://cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123/.well-known/jwks.json'
jwks = requests.get(jwks_url).json()
# Decode and verify (use python-jose or similar)
from jose import jwt
claims = jwt.decode(
token,
jwks,
algorithms=['RS256'],
audience='client-id',
issuer='https://cognito-idp.us-east-1.amazonaws.com/us-east-1_abc123'
)Check:
# Check domain
aws cognito-idp describe-user-pool \
--user-pool-id us-east-1_abc123 \
--query 'UserPool.Domain'Symptom: TooManyRequestsException
Solutions:
© itsmostafa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/cognito of itsmostafa/aws-agent-skills.
Open the folder on GitHubat commit e786d25
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in itsmostafa/aws-agent-skills, which our catalogue first saw on October 7, 2026.
Cognito next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cognito this skillitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Iam Auditbriiirussell/cybersecurity-skills | 413 | — | ~3.1k | Automated safety check: Notes | MIT | |
| Auth Implementation Patternsynulihao/AgentSkillOS | 617 | 10 repos | ~4.4k | Automated safety check: Pass | None | |
| Supercheck Security Authsupercheck-io/supercheck | 215 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | |
| Authenticationcodewithmukesh/dotnet-claude-kit | 755 | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Spring Boot Security JWTgiuseppe-trisciuoglio/developer-kit | 356 | — | ~3.9k | Automated safety check: Notes | MIT |
briiirussell/cybersecurity-skills
Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…
ynulihao/AgentSkillOS
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.
supercheck-io/supercheck
Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…
codewithmukesh/dotnet-claude-kit
Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.
giuseppe-trisciuoglio/developer-kit
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…
rohitg00/awesome-claude-code-toolkit
Authentication and authorization patterns including OAuth2, JWT, RBAC, session management, and PKCE flows
itsmostafa/aws-agent-skills
AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.
itsmostafa/aws-agent-skills
AWS Bedrock foundation models for generative AI. An agent skill from itsmostafa/aws-agent-skills.
itsmostafa/aws-agent-skills
AWS CloudFormation infrastructure as code for stack management.
itsmostafa/aws-agent-skills
AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards.
itsmostafa/aws-agent-skills
AWS DynamoDB NoSQL database for scalable data storage. An agent skill from itsmostafa/aws-agent-skills.
itsmostafa/aws-agent-skills
AWS ECS container orchestration for running Docker containers.
Works with
Categories
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills. Cognito is an agent skill from itsmostafa/aws-agent-skills. AWS Cognito user authentication and authorization service.
Cognito fits situations like: setting up user pools; configuring identity pools; implementing OAuth flows; managing user attributes.
Run `npx skills add itsmostafa/aws-agent-skills --skill cognito -a claude-code`. Or copy the skill folder (skills/cognito in itsmostafa/aws-agent-skills) into .claude/skills/cognito in your project. Claude Code loads it when a task matches its description.
Run `npx skills add itsmostafa/aws-agent-skills --skill cognito -a codex`. Or copy the skill folder (skills/cognito in itsmostafa/aws-agent-skills) into .agents/skills/cognito in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add itsmostafa/aws-agent-skills --skill cognito -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cognito, .gemini/skills/cognito, .github/skills/cognito and .opencode/skills/cognito in your project.
Going by SKILL.md and its folder, Cognito needs the command-line tools its instructions call (aws) and credentials named REFRESH_TOKEN. Our summary lists: Python 3; A credential in REFRESH_TOKEN.
SKILL.md names 2 domains. In commands or code: cognito-idp.us-east-1.amazonaws.com; the agent is likely to contact it when it follows the instructions. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cognito is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cognito: Iam Audit (briiirussell/cybersecurity-skills, 413 stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars) and Authentication (codewithmukesh/dotnet-claude-kit, 755 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
itsmostafa (a GitHub user) maintains it in itsmostafa/aws-agent-skills, which has 1,162 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.
Source: itsmostafa/aws-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.