AWS S3 object storage for bucket management, object operations, and access control.

MITAuto-check passedBackend & APIs

Install S3

skills CLI
$ npx skills add itsmostafa/aws-agent-skills --skill s3 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install itsmostafa/aws-agent-skills s3 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/s3 .claude/skills/s3 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
s3
GitHub stars
1.2k
Token cost
~2.3k tokens
SKILL.md length
494 words
Files
2
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

AWS S3 object storage for bucket management, object operations, and access control.

  • Works in 5 steps: Bucket policy denies access → IAM policy missing permissions → Public access block preventing access → …
  • Creating buckets
  • SKILL.md covers Table of Contents, Core Concepts, Common Patterns and CLI Reference, plus 3 more sections
  • Calls aws

What it does

S3 is an agent skill from itsmostafa/aws-agent-skills. AWS S3 object storage for bucket management, object operations, and access control. Use when creating buckets, uploading files, configuring lifecycle policies, setting up static websites, managing permissions, or implementing cross-region replication.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `security.md`).

It sits in Backend & APIs, covering File uploads and storage and Authorization and RBAC. It works with Amazon S3 and Amazon Web Services. The repository describes itself as: AWS Skills for Agents. The licence is MIT.

When your agent uses it

  • Creating buckets
  • Uploading files
  • Configuring lifecycle policies
  • Setting up static websites

Example prompts

  • “/s3”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Bucket policy denies access
  2. IAM policy missing permissions
  3. Public access block preventing access
  4. Object owned by different account
  5. VPC endpoint policy blocking

What it can do on your machine

Read from SKILL.md and the folder at commit e786d25. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • boto3.amazonaws.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

S3 loads about 2.3k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 494 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from itsmostafa/aws-agent-skills at commit e786d25, republished under its MIT licence (© itsmostafa). 494 words, ~2,329 tokens.

Download SKILL.mdSave it as .claude/skills/s3/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
s3
description
AWS S3 object storage for bucket management, object operations, and access control. Use when creating buckets, uploading files, configuring lifecycle policies, setting up static websites, managing permissions, or implementing cross-region replication.
last_updated
2026-01-07
doc_source
https://docs.aws.amazon.com/AmazonS3/latest/userguide/

AWS S3

Amazon Simple Storage Service (S3) provides scalable object storage with industry-leading durability (99.999999999%). S3 is fundamental to AWS—used for data lakes, backups, static websites, and as storage for many other AWS services.

Table of Contents

Core Concepts

Buckets

Containers for objects. Bucket names are globally unique across all AWS accounts.

Objects

Files stored in S3, consisting of data, metadata, and a unique key (path). Maximum size: 5 TB.

Storage Classes
ClassUse CaseDurabilityAvailability
StandardFrequently accessed99.999999999%99.99%
Intelligent-TieringUnknown access patterns99.999999999%99.9%
Standard-IAInfrequent access99.999999999%99.9%
Glacier InstantArchive with instant retrieval99.999999999%99.9%
Glacier FlexibleArchive (minutes to hours)99.999999999%99.99%
Glacier Deep ArchiveLong-term archive99.999999999%99.99%
Versioning

Keeps multiple versions of an object. Essential for data protection and recovery.

Common Patterns

Create a Bucket with Best Practices

AWS CLI:

bash
# Create bucket (us-east-1 doesn't need LocationConstraint)
aws s3api create-bucket \
  --bucket my-secure-bucket-12345 \
  --region us-west-2 \
  --create-bucket-configuration LocationConstraint=us-west-2

# Enable versioning
aws s3api put-bucket-versioning \
  --bucket my-secure-bucket-12345 \
  --versioning-configuration Status=Enabled

# Block public access
aws s3api put-public-access-block \
  --bucket my-secure-bucket-12345 \
  --public-access-block-configuration \
    BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true

# Enable encryption
aws s3api put-bucket-encryption \
  --bucket my-secure-bucket-12345 \
  --server-side-encryption-configuration '{
    "Rules": [{"ApplyServerSideEncryptionByDefault": {"SSEAlgorithm": "AES256"}}]
  }'

boto3:

python
import boto3

s3 = boto3.client('s3', region_name='us-west-2')

# Create bucket
s3.create_bucket(
    Bucket='my-secure-bucket-12345',
    CreateBucketConfiguration={'LocationConstraint': 'us-west-2'}
)

# Enable versioning
s3.put_bucket_versioning(
    Bucket='my-secure-bucket-12345',
    VersioningConfiguration={'Status': 'Enabled'}
)

# Block public access
s3.put_public_access_block(
    Bucket='my-secure-bucket-12345',
    PublicAccessBlockConfiguration={
        'BlockPublicAcls': True,
        'IgnorePublicAcls': True,
        'BlockPublicPolicy': True,
        'RestrictPublicBuckets': True
    }
)
Upload and Download Objects
bash
# Upload a single file
aws s3 cp myfile.txt s3://my-bucket/path/myfile.txt

# Upload with metadata
aws s3 cp myfile.txt s3://my-bucket/path/myfile.txt \
  --metadata "environment=production,version=1.0"

# Download a file
aws s3 cp s3://my-bucket/path/myfile.txt ./myfile.txt

# Sync a directory
aws s3 sync ./local-folder s3://my-bucket/prefix/ --delete

# Copy between buckets
aws s3 cp s3://source-bucket/file.txt s3://dest-bucket/file.txt
Generate Presigned URL
python
import boto3
from botocore.config import Config

s3 = boto3.client('s3', config=Config(signature_version='s3v4'))

# Generate presigned URL for download (GET)
url = s3.generate_presigned_url(
    'get_object',
    Params={'Bucket': 'my-bucket', 'Key': 'path/to/file.txt'},
    ExpiresIn=3600  # URL valid for 1 hour
)

# Generate presigned URL for upload (PUT)
upload_url = s3.generate_presigned_url(
    'put_object',
    Params={
        'Bucket': 'my-bucket',
        'Key': 'uploads/newfile.txt',
        'ContentType': 'text/plain'
    },
    ExpiresIn=3600
)
Configure Lifecycle Policy
bash
cat > lifecycle.json << 'EOF'
{
  "Rules": [
    {
      "ID": "MoveToGlacierAfter90Days",
      "Status": "Enabled",
      "Filter": {"Prefix": "logs/"},
      "Transitions": [
        {"Days": 90, "StorageClass": "GLACIER"}
      ],
      "Expiration": {"Days": 365}
    },
    {
      "ID": "DeleteOldVersions",
      "Status": "Enabled",
      "Filter": {},
      "NoncurrentVersionExpiration": {"NoncurrentDays": 30}
    }
  ]
}
EOF

aws s3api put-bucket-lifecycle-configuration \
  --bucket my-bucket \
  --lifecycle-configuration file://lifecycle.json
Event Notifications to Lambda
bash
aws s3api put-bucket-notification-configuration \
  --bucket my-bucket \
  --notification-configuration '{
    "LambdaFunctionConfigurations": [
      {
        "LambdaFunctionArn": "arn:aws:lambda:us-east-1:123456789012:function:ProcessS3Upload",
        "Events": ["s3:ObjectCreated:*"],
        "Filter": {
          "Key": {
            "FilterRules": [
              {"Name": "prefix", "Value": "uploads/"},
              {"Name": "suffix", "Value": ".jpg"}
            ]
          }
        }
      }
    ]
  }'

CLI Reference

High-Level Commands (aws s3)
CommandDescription
aws s3 lsList buckets or objects
aws s3 cpCopy files
aws s3 mvMove files
aws s3 rmDelete files
aws s3 syncSync directories
aws s3 mbMake bucket
aws s3 rbRemove bucket
Low-Level Commands (aws s3api)
CommandDescription
aws s3api create-bucketCreate bucket with options
aws s3api put-objectUpload with full control
aws s3api get-objectDownload with options
aws s3api delete-objectDelete single object
aws s3api put-bucket-policySet bucket policy
aws s3api put-bucket-versioningEnable versioning
aws s3api list-object-versionsList all versions
Useful Flags
  • --recursive: Process all objects in prefix
  • --exclude/--include: Filter objects
  • --dryrun: Preview changes
  • --storage-class: Set storage class
  • --acl: Set access control (prefer policies instead)

Best Practices

Show full SKILL.md (219 more words)Show less
Security
  • Block public access at account and bucket level
  • Enable versioning for data protection
  • Use bucket policies over ACLs
  • Enable encryption (SSE-S3 or SSE-KMS)
  • Enable access logging for audit
  • Use VPC endpoints for private access
  • Enable MFA Delete for critical buckets
Performance
  • Use Transfer Acceleration for distant uploads
  • Use multipart upload for files > 100 MB
  • Randomize key prefixes for high-throughput (less relevant with 2024 improvements)
  • Use byte-range fetches for large file downloads
Cost Optimization
  • Use lifecycle policies to transition to cheaper storage
  • Enable Intelligent-Tiering for unpredictable access
  • Delete incomplete multipart uploads:
    json
    {
      "Rules": [{
        "ID": "AbortIncompleteMultipartUpload",
        "Status": "Enabled",
        "Filter": {},
        "AbortIncompleteMultipartUpload": {"DaysAfterInitiation": 7}
      }]
    }
  • Use S3 Storage Lens to analyze storage patterns

Troubleshooting

Access Denied Errors

Causes:

  1. Bucket policy denies access
  2. IAM policy missing permissions
  3. Public access block preventing access
  4. Object owned by different account
  5. VPC endpoint policy blocking

Debug steps:

bash
# Check your identity
aws sts get-caller-identity

# Check bucket policy
aws s3api get-bucket-policy --bucket my-bucket

# Check public access block
aws s3api get-public-access-block --bucket my-bucket

# Check object ownership
aws s3api get-object-attributes \
  --bucket my-bucket \
  --key myfile.txt \
  --object-attributes ObjectOwner
CORS Errors

Symptom: Browser blocks cross-origin request

Fix:

bash
aws s3api put-bucket-cors --bucket my-bucket --cors-configuration '{
  "CORSRules": [{
    "AllowedOrigins": ["https://myapp.com"],
    "AllowedMethods": ["GET", "PUT", "POST"],
    "AllowedHeaders": ["*"],
    "ExposeHeaders": ["ETag"],
    "MaxAgeSeconds": 3600
  }]
}'
Slow Uploads

Solutions:

  • Use multipart upload for large files
  • Enable Transfer Acceleration
  • Use aws s3 cp with --expected-size for large files
  • Check network throughput to the region
403 on Presigned URL

Causes:

  • URL expired
  • Signer lacks permissions
  • Bucket policy blocks access
  • Region mismatch (v4 signatures are region-specific)

Fix: Ensure signer has permissions and use correct region.

References

© itsmostafa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/s3 of itsmostafa/aws-agent-skills.

  • SKILL.md
  • security.md

Open the folder on GitHubat commit e786d25

Compare with similar skills

S3 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

S3 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
S3 this skillitsmostafa/aws-agent-skills1.2k—~2.3kAutomated safety check: PassMIT
Creating Data Lake Tableaws/agent-toolkit-for-aws2.8k1 repos~2.1kAutomated safety check: PassApache-2.0
AWS Essentialsericrisco/rsc-harness167—~2.9kAutomated safety check: NotesMIT
Processing S3 Uploads With Step Functionsaws/agent-toolkit-for-aws2.8k—~4kAutomated safety check: PassApache-2.0
Django Storages for S3Jeffallan/claude-skills12k—~1.9kAutomated safety check: PassMIT
Neon Object Storageneondatabase/agent-skills100—~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Creating Data Lake Table

    aws/agent-toolkit-for-aws

    Official

    Create managed Iceberg tables using Amazon S3 Tables (s3tables API namespace) with automatic compaction and snapshot management.

    2.8k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed
  • AWS Essentials

    ericrisco/rsc-harness

    A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or…

    167 GitHub stars~2.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Django Storages for S3

    Jeffallan/claude-skills

    Sets up Django 4.2+ to keep static and media files on AWS S3 through django-storages, with public and private backends, presigned URLs and CloudFront.

    12k GitHub stars~1.9k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Neon Object Storage

    neondatabase/agent-skills

    Official

    S3-compatible object storage that branches with your Neon project, so files and the database stay in sync across every branch.

    100 GitHub stars~3.5k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • AWS S3

    majiayu000/claude-skill-registry

    Configure S3 buckets, policies, and lifecycle rules. An agent skill from majiayu000/claude-skill-registry.

    666 GitHub starsUsed in 3 repos~3.1k tokens
    Backend & APIsAuto-check passed

More from itsmostafa/aws-agent-skills

All 17 skills in this repo
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Bedrock

    itsmostafa/aws-agent-skills

    AWS Bedrock foundation models for generative AI. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Ecs

    itsmostafa/aws-agent-skills

    AWS ECS container orchestration for running Docker containers.

    1.2k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed
  • Cloudformation

    itsmostafa/aws-agent-skills

    AWS CloudFormation infrastructure as code for stack management.

    1.2k GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Cloudwatch

    itsmostafa/aws-agent-skills

    AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards.

    1.2k GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about S3

What does S3 do?

AWS S3 object storage for bucket management, object operations, and access control. S3 is an agent skill from itsmostafa/aws-agent-skills. AWS S3 object storage for bucket management, object operations, and access control.

When should I use S3?

S3 fits situations like: creating buckets; uploading files; configuring lifecycle policies; setting up static websites.

How do I install S3 in Claude Code?

Run `npx skills add itsmostafa/aws-agent-skills --skill s3 -a claude-code`. Or copy the skill folder (skills/s3 in itsmostafa/aws-agent-skills) into .claude/skills/s3 in your project. Claude Code loads it when a task matches its description.

How do I install S3 in Codex?

Run `npx skills add itsmostafa/aws-agent-skills --skill s3 -a codex`. Or copy the skill folder (skills/s3 in itsmostafa/aws-agent-skills) into .agents/skills/s3 in your project. Codex loads it when a task matches its description.

Can I use S3 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add itsmostafa/aws-agent-skills --skill s3 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/s3, .gemini/skills/s3, .github/skills/s3 and .opencode/skills/s3 in your project.

What does S3 need to run?

Going by SKILL.md and its folder, S3 needs the command-line tools its instructions call (aws). Our summary lists: Python 3.

Does S3 access the network?

SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and boto3.amazonaws.com. This is read from the text; nothing was executed.

Is S3 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does S3 use?

S3 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does S3 use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to S3?

Skills that share tags, products or a category with S3: Creating Data Lake Table (aws/agent-toolkit-for-aws, 2.8k stars), AWS Essentials (ericrisco/rsc-harness, 167 stars), Processing S3 Uploads With Step Functions (aws/agent-toolkit-for-aws, 2.8k stars) and Django Storages for S3 (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains S3?

itsmostafa (a GitHub user) maintains it in itsmostafa/aws-agent-skills, which has 1,161 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.

Source: itsmostafa/aws-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.