Agent skill

AWS Cognito Admin

by Kilo-Org in Kilo-Org/kilo-marketplace

Cognito user pool administration — look up users, confirm accounts, reset passwords, update custom attributes, disable/enable accounts, and describe pool configuration.

MITAuto-check passed

Install AWS Cognito Admin

skills CLI
$ npx skills add Kilo-Org/kilo-marketplace --skill aws-cognito-admin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Kilo-Org/kilo-marketplace aws-cognito-admin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aws-cognito-admin .claude/skills/aws-cognito-admin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-cognito-admin
GitHub stars
190
Token cost
~1.7k tokens
SKILL.md length
476 words
Files
2
Skills in repo
85
Repo updated
First seen
Licence
MIT

At a glance

Cognito user pool administration — look up users, confirm accounts, reset passwords, update custom attributes, disable/enable accounts, and describe pool configuration.

  • Works in 10 steps: Discover user pools (skip if user… → Look up a user by email or username → List users matching a filter → …
  • Disable an account
  • SKILL.md covers Step 0 — Discover user pools…, Step 1 — Look up a user by…, Step 2 — List users matching a… and Step 3 — Force-confirm an…, plus 6 more sections
  • Calls aws and jq; needs FORCE_CHANGE_PASSWORD

What it does

AWS Cognito Admin is an agent skill from Kilo-Org/kilo-marketplace. Cognito user pool administration — look up users, confirm accounts, reset passwords, update custom attributes, disable/enable accounts, and describe pool configuration. Discovers user pools at runtime. Trigger on "look up a user", "Cognito", "reset password", "disable an account", "fix subscription", or /aws-cognito-admin.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It works with Amazon Web Services. The repository describes itself as: Kilo Marketplace - A curated collection of Skills, MCP Servers, and Modes for enhancing AI agent capabilities across the Kilo ecosystem—including Kilo Code (VS Code extension)… The licence is MIT.

When your agent uses it

  • Disable an account
  • Fix subscription
  • /aws-cognito-admin

Example prompts

  • “look up a user”
  • “Cognito”
  • “reset password”
  • “/aws-cognito-admin”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Discover user pools (skip if user already named a pool)
  2. Look up a user by email or username
  3. List users matching a filter
  4. Force-confirm an unconfirmed account
  5. Reset a user's password
  6. Disable or enable a user
  7. Update a custom attribute
  8. Delete a user
  9. Describe pool configuration
  10. List app clients

What it can do on your machine

Read from SKILL.md and the folder at commit ff51758. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FORCE_CHANGE_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Cognito Admin loads about 1.7k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 476 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Kilo-Org/kilo-marketplace at commit ff51758, republished under its MIT licence (© Kilo-Org). 476 words, ~1,674 tokens.

Download SKILL.mdSave it as .claude/skills/aws-cognito-admin/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
aws-cognito-admin
description
Cognito user pool administration — look up users, confirm accounts, reset passwords, update custom attributes, disable/enable accounts, and describe pool configuration. Discovers user pools at runtime. Trigger on "look up a user", "Cognito", "reset password", "disable an account", "fix subscription", or /aws-cognito-admin.
metadata.category
development

AWS Cognito Admin

Perform Cognito user pool administration without hardcoded pool IDs. All resources are discovered at runtime.


Step 0 — Discover user pools (skip if user already named a pool)

bash
aws cognito-idp list-user-pools --max-results 60 \
  --query 'UserPools[*].{Name:Name,Id:Id}' \
  --output table --no-cli-pager

Present the list and ask the user which pool to work with (or infer from context). If there is only one pool, proceed with it automatically. Store the pool ID as $POOL_ID for subsequent commands.


Step 1 — Look up a user by email or username

bash
aws cognito-idp admin-get-user \
  --user-pool-id "$POOL_ID" \
  --username "$EMAIL_OR_USERNAME" \
  --no-cli-pager

Display all attributes clearly. Key things to note:

  • UserStatus — expected: CONFIRMED. Flag UNCONFIRMED, FORCE_CHANGE_PASSWORD, DISABLED, or UNKNOWN.
  • Enabled — if false, the account is disabled.
  • All custom: attributes — these often carry subscription status, plan tier, external IDs (e.g. Stripe customer ID), and role flags. Explain what each likely means.
  • UserCreateDate and UserLastModifiedDate — note if the account is newly created or hasn't been modified in a long time.

Step 2 — List users matching a filter

Use prefix filters for email or other standard attributes:

bash
aws cognito-idp list-users \
  --user-pool-id "$POOL_ID" \
  --filter 'email ^= "user@example"' \
  --query 'Users[*].{Username:Username,Email:Attributes[?Name==`email`]|[0].Value,Status:UserStatus,Enabled:Enabled}' \
  --output table --no-cli-pager

Supported filter operators: =, ^= (starts-with), $= (ends-with), *= (contains), !=. Filterable attributes: username, email, phone_number, name, given_name, family_name, preferred_username, cognito:user_status, status, sub.


Step 3 — Force-confirm an unconfirmed account

Use this when a user did not receive or click their confirmation email but should be activated anyway:

bash
aws cognito-idp admin-confirm-sign-up \
  --user-pool-id "$POOL_ID" \
  --username "$USERNAME" \
  --no-cli-pager

After running, re-fetch the user (Step 1) and confirm UserStatus is now CONFIRMED.


Step 4 — Reset a user's password

Sends a temporary password reset code to the user's registered email or phone:

bash
aws cognito-idp admin-reset-user-password \
  --user-pool-id "$POOL_ID" \
  --username "$USERNAME" \
  --no-cli-pager

After running, the user will receive a reset code and their status will change to RESET_REQUIRED. Let the user know to check their inbox.


Step 5 — Disable or enable a user

Disable (blocks all sign-in immediately):

bash
aws cognito-idp admin-disable-user \
  --user-pool-id "$POOL_ID" \
  --username "$USERNAME" \
  --no-cli-pager

Enable (restores sign-in access):

bash
aws cognito-idp admin-enable-user \
  --user-pool-id "$POOL_ID" \
  --username "$USERNAME" \
  --no-cli-pager

Disabling does not delete the user or their attributes. Existing sessions may remain valid until they expire — Cognito does not invalidate tokens on disable.


Show full SKILL.md (181 more words)Show less

Step 6 — Update a custom attribute

Use this to manually fix subscription status, plan tier, role flags, or any other custom attribute:

bash
aws cognito-idp admin-update-user-attributes \
  --user-pool-id "$POOL_ID" \
  --username "$USERNAME" \
  --user-attributes Name="custom:subscription_status",Value="active" \
  --no-cli-pager

To update multiple attributes at once, repeat Name=...,Value=... entries:

bash
aws cognito-idp admin-update-user-attributes \
  --user-pool-id "$POOL_ID" \
  --username "$USERNAME" \
  --user-attributes \
    Name="custom:subscription_status",Value="active" \
    Name="custom:plan",Value="pro" \
  --no-cli-pager

After updating, re-fetch the user (Step 1) to confirm the change took effect.

Note: You cannot update email or phone_number directly with this command if auto-verification is enabled. Use admin-update-user-attributes with email_verified set to true in the same call, or use the console.


Step 7 — Delete a user

This is irreversible. Always confirm before proceeding.

Before deleting, show the user's full profile (Step 1) and explicitly list what will be lost:

  • The Cognito account and all its attributes
  • The ability to sign in with this username/email
  • Any downstream records keyed on the Cognito sub (UUID) will become orphaned

Then ask for explicit confirmation. Only proceed after the user confirms.

bash
aws cognito-idp admin-delete-user \
  --user-pool-id "$POOL_ID" \
  --username "$USERNAME" \
  --no-cli-pager

Step 8 — Describe pool configuration

bash
aws cognito-idp describe-user-pool \
  --user-pool-id "$POOL_ID" \
  --no-cli-pager \
  | jq '{
      Name: .UserPool.Name,
      MFA: .UserPool.MfaConfiguration,
      PasswordPolicy: .UserPool.Policies.PasswordPolicy,
      UsernameAttributes: .UserPool.UsernameAttributes,
      AutoVerifiedAttributes: .UserPool.AutoVerifiedAttributes,
      EstimatedNumberOfUsers: .UserPool.EstimatedNumberOfUsers,
      SchemaAttributes: [.UserPool.SchemaAttributes[]? | select(.Name | startswith("custom:"))]
    }'

This shows MFA settings, password policy, whether email/phone is used as the username, and all custom attributes defined in the schema.


Step 9 — List app clients

bash
aws cognito-idp list-user-pool-clients \
  --user-pool-id "$POOL_ID" \
  --query 'UserPoolClients[*].{Name:ClientName,Id:ClientId}' \
  --output table --no-cli-pager

To inspect a specific client's OAuth flows and callback URLs:

bash
aws cognito-idp describe-user-pool-client \
  --user-pool-id "$POOL_ID" \
  --client-id "$CLIENT_ID" \
  --no-cli-pager \
  | jq '{
      ClientName: .UserPoolClient.ClientName,
      AllowedOAuthFlows: .UserPoolClient.AllowedOAuthFlows,
      CallbackURLs: .UserPoolClient.CallbackURLs,
      LogoutURLs: .UserPoolClient.LogoutURLs,
      ExplicitAuthFlows: .UserPoolClient.ExplicitAuthFlows
    }'

© Kilo-Org, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/aws-cognito-admin of Kilo-Org/kilo-marketplace.

  • SKILL.md
  • LICENSE

Open the folder on GitHubat commit ff51758

Compare with similar skills

AWS Cognito Admin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Cognito Admin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Cognito Admin this skillKilo-Org/kilo-marketplace190—~1.7kAutomated safety check: PassMIT
SageMaker IAM Role Preflighthuggingface/skills11k1 repos~1.8kAutomated safety check: PassApache-2.0
SageMaker Serving Image Selectionhuggingface/skills11k1 repos~4.6kAutomated safety check: PassApache-2.0
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Agent Squad Python Guide2FastLabs/agent-squad7.8k—~4.7kAutomated safety check: PassApache-2.0
Paperclip Pagepaperclipai/paperclip99k—~1kAutomated safety check: PassMIT

Similar skills

  • Official

    Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create.

    11k GitHub starsUsed in 1 repo~1.8k tokens
    DevOps & CloudAuto-check passed
  • Official

    Chooses the right serving container and current image URI for deploying a Hugging Face model to a SageMaker endpoint, preferring Hugging Face images over generic ones.

    11k GitHub starsUsed in 1 repo~4.6k tokens
    AI & LLM EngineeringAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Agent Squad Python Guide

    2FastLabs/agent-squad

    Map of the agent-squad Python framework for async multi-agent orchestration: which agent, classifier, storage and tool provider to pick, and the pitfalls to avoid.

    7.8k GitHub stars~4.7k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Paperclip Page

    paperclipai/paperclip

    Publish static HTML pages and asset folders to the Paperclip S3/CloudFront page host.

    99k GitHub stars~1k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Review Docs

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…

    11k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed

More from Kilo-Org/kilo-marketplace

All 85 skills in this repo
  • AzureML Project Scaffolding

    Kilo-Org/kilo-marketplace

    Sets up and maintains AzureML-ready Python projects as uv workspaces with devcontainers, a Makefile and job YAML, so local runs match cloud jobs and experiments stay reproducible.

    190 GitHub stars~3.1k tokensUpdated 10 days ago
    Auto-check: notes
  • Jupyter Notebook Builder

    Kilo-Org/kilo-marketplace

    Creates, inspects, edits and runs Jupyter notebooks, scaffolding experiment or tutorial notebooks from templates and preferring a Jupyter MCP server over raw JSON edits.

    190 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check passed
  • Tableau Dashboard Creator

    Kilo-Org/kilo-marketplace

    Takes a plain-language dashboard request through brand setup, data exploration, planning, an interactive HTML mock and a Tableau implementation spec.

    190 GitHub stars~3.8k tokensUpdated 10 days ago
    Auto-check: notes
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 10 days ago
    Auto-check passed
  • Nifi Flow Layout

    Kilo-Org/kilo-marketplace

    A skill your agent uses when arranging Apache NiFi processors, process groups, ports, comments, numbering, crossing connections, dense fan-in/fan-out, or reusable readable canvas layouts.

    190 GitHub stars~1.5k tokensUpdated 10 days ago
    Auto-check passed
  • Splunk Ingest Processor Setup

    Kilo-Org/kilo-marketplace

    Render Cisco Data Fabric ingest-time routing workflows and Splunk Cloud Platform Ingest Processor setup plans with SPL2 pipelines, source types, destinations, lifecycle handoffs, queue and…

    190 GitHub stars~1.2k tokensUpdated 10 days ago
    Auto-check passed

Questions about AWS Cognito Admin

What does AWS Cognito Admin do?

Cognito user pool administration — look up users, confirm accounts, reset passwords, update custom attributes, disable/enable accounts, and describe pool configuration. AWS Cognito Admin is an agent skill from Kilo-Org/kilo-marketplace. Cognito user pool administration — look up users, confirm accounts, reset passwords, update custom attributes, disable/enable accounts, and describe pool configuration.

When should I use AWS Cognito Admin?

AWS Cognito Admin fits situations like: disable an account; fix subscription; /aws-cognito-admin.

How do I install AWS Cognito Admin in Claude Code?

Run `npx skills add Kilo-Org/kilo-marketplace --skill aws-cognito-admin -a claude-code`. Or copy the skill folder (skills/aws-cognito-admin in Kilo-Org/kilo-marketplace) into .claude/skills/aws-cognito-admin in your project. Claude Code loads it when a task matches its description.

How do I install AWS Cognito Admin in Codex?

Run `npx skills add Kilo-Org/kilo-marketplace --skill aws-cognito-admin -a codex`. Or copy the skill folder (skills/aws-cognito-admin in Kilo-Org/kilo-marketplace) into .agents/skills/aws-cognito-admin in your project. Codex loads it when a task matches its description.

Can I use AWS Cognito Admin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Kilo-Org/kilo-marketplace --skill aws-cognito-admin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-cognito-admin, .gemini/skills/aws-cognito-admin, .github/skills/aws-cognito-admin and .opencode/skills/aws-cognito-admin in your project.

What does AWS Cognito Admin need to run?

Going by SKILL.md and its folder, AWS Cognito Admin needs the command-line tools its instructions call (aws and jq) and credentials named FORCE_CHANGE_PASSWORD.

Does AWS Cognito Admin access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AWS Cognito Admin safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Cognito Admin use?

AWS Cognito Admin is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Cognito Admin use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AWS Cognito Admin?

Skills that share tags, products or a category with AWS Cognito Admin: SageMaker IAM Role Preflight (huggingface/skills, 11k stars), SageMaker Serving Image Selection (huggingface/skills, 11k stars), Cloud Cost Optimization (wshobson/agents, 40k stars) and Agent Squad Python Guide (2FastLabs/agent-squad, 7.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Cognito Admin?

Kilo-Org (a GitHub organization) maintains it in Kilo-Org/kilo-marketplace, which has 190 GitHub stars. The repository holds 85 skills in this directory. The repository was last updated on September 28, 2026.

Source: Kilo-Org/kilo-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.