S3
itsmostafa/aws-agent-skills
AWS S3 object storage for bucket management, object operations, and access control.
Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations.
$ npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws/agent-toolkit-for-aws securing-s3-buckets --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/storage-skills/securing-s3-buckets .claude/skills/securing-s3-buckets && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "securing-s3-buckets" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/storage-skills/securing-s3-buckets into .claude/skills/securing-s3-buckets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securing-s3-buckets", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/storage-skills/securing-s3-bucketsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws/agent-toolkit-for-aws securing-s3-buckets --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/specialized-skills/storage-skills/securing-s3-buckets .agents/skills/securing-s3-buckets && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "securing-s3-buckets" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/storage-skills/securing-s3-buckets into .agents/skills/securing-s3-buckets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securing-s3-buckets", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws/agent-toolkit-for-aws securing-s3-buckets --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/specialized-skills/storage-skills/securing-s3-buckets .cursor/skills/securing-s3-buckets && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "securing-s3-buckets" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/storage-skills/securing-s3-buckets into .cursor/skills/securing-s3-buckets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securing-s3-buckets", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws/agent-toolkit-for-aws.git --path skills/specialized-skills/storage-skills/securing-s3-buckets--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws/agent-toolkit-for-aws securing-s3-buckets --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/specialized-skills/storage-skills/securing-s3-buckets .gemini/skills/securing-s3-buckets && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "securing-s3-buckets" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/storage-skills/securing-s3-buckets into .gemini/skills/securing-s3-buckets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securing-s3-buckets", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws/agent-toolkit-for-aws securing-s3-bucketsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/specialized-skills/storage-skills/securing-s3-buckets .github/skills/securing-s3-buckets && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "securing-s3-buckets" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/storage-skills/securing-s3-buckets into .github/skills/securing-s3-buckets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securing-s3-buckets", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws/agent-toolkit-for-aws securing-s3-buckets --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/specialized-skills/storage-skills/securing-s3-buckets .opencode/skills/securing-s3-buckets && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "securing-s3-buckets" agent skill from https://github.com/aws/agent-toolkit-for-aws/tree/main/skills/specialized-skills/storage-skills/securing-s3-buckets into .opencode/skills/securing-s3-buckets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "securing-s3-buckets", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
securing-s3-bucketsCreate and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations.
Securing S3 Buckets is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an existing bucket, fix a security finding, configure encryption, or enable logging and monitoring. Do NOT use for general S3 data operations, S3 Tables setup, or discovering existing data assets.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/audit-checklist.md`, `references/encryption.md` and `references/iam-permissions.md`).
It sits in Backend & APIs, covering File uploads and storage and Authorization and RBAC. It works with Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awspython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Securing S3 Buckets loads about 2k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 817 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 817 words, ~1,951 tokens.
.claude/skills/securing-s3-buckets/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Implements layered S3 security controls across five workflows: securing new buckets, auditing existing configurations, remediating findings, configuring encryption, and enabling monitoring. Follows AWS Well-Architected security best practices.
Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to AWS CLI or shell otherwise.
Check for required tools before starting.
Constraints:
aws sts get-caller-identitySee references/iam-permissions.md for IAM permissions by workflow.
| User intent | Workflow |
|---|---|
| Secure a new bucket | A: Secure New Bucket |
| Audit / review existing bucket | B: Audit Existing Bucket |
| Fix a specific finding | C: Remediate Issue |
| Configure encryption | D: Configure Encryption |
| Enable logging / monitoring | E: Enable Monitoring |
Constraints:
aws iam simulate-principal-policy to validate permissions before write operationsThese rules apply to ALL workflows that call put-bucket-policy:
aws s3api get-bucket-policy) — put-bucket-policy replaces the entire policyaws s3api get-bucket-policy --bucket <name> --output text > backup-policy-$(date +%s).jsonNoSuchBucketPolicy is returned, proceed with a new policy — no backup is neededecho '<policy>' | python3 -m json.tool)put-bucket-policy command and wait for confirmationSee references/workflows.md for full CLI steps.
Required steps (execute in order, do not skip):
--bucket-namespace account-regionalDenyInsecureTransport bucket policyConstraints:
You MUST pass --bucket-namespace account-regional on create-bucket call — this is REQUIRED, not optional. Example:
aws s3api create-bucket --bucket <name> --bucket-namespace account-regional --region <region>You MUST NOT change Block Public Access — S3 enables it by default on new buckets
You MUST NOT change ACL ownership controls — S3 disables ACLs (BucketOwnerEnforced) by default
You MUST apply a bucket policy with a DenyInsecureTransport statement that denies s3:* when aws:SecureTransport is false — this is REQUIRED, not optional. Example:
aws s3api put-bucket-policy --bucket <name> --policy '{"Version":"2012-10-17","Statement":[{"Sid":"DenyInsecureTransport","Effect":"Deny","Principal":"*","Action":"s3:*","Resource":["arn:aws:s3:::<name>/*","arn:aws:s3:::<name>"],"Condition":{"Bool":{"aws:SecureTransport":"false"}}}]}'You MUST ask the user which logging option they want before step 4
You MUST follow the put-bucket-policy safety rules for steps 4 and 5
You SHOULD confirm each step succeeded before proceeding
See references/audit-checklist.md for the full checklist.
Constraints:
See references/remediation.md for fix commands by issue type.
Constraints:
See references/encryption.md for encryption options and commands.
Constraints:
aws/s3 keyBucketKeyEnabled: true and BlockedEncryptionTypes: [SSE-C] in all configurationsaws/s3 and aliases without error — agent-enforced constraints. Verify with get-bucket-encryption after applying.See references/workflows.md for full CLI steps.
Constraints:
ObjectLockConfigurationNotFoundError — Object Lock is not enabled. Treat as NOT CONFIGURED, not a failure.
AccessDenied on audit commands — Check IAM policy, bucket policy, Block Public Access, VPC endpoint policy, and SCPs/RCPs. Use aws iam simulate-principal-policy to diagnose.
put-bucket-policy silently removes existing statements — See put-bucket-policy safety rules.
GuardDuty BadRequestException: detector already exists — Run aws guardduty list-detectors first; only call create-detector if empty.
CloudTrail changes not taking effect — Verify you are using --region <trail-home-region>, not the bucket's region. Find it with aws cloudtrail describe-trails --query 'trailList[*].[Name,HomeRegion]'.
© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in skills/specialized-skills/storage-skills/securing-s3-buckets of aws/agent-toolkit-for-aws.
Open the folder on GitHubat commit 188af2f
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aws/agent-toolkit-for-aws, which our catalogue first saw on October 7, 2026.
Securing S3 Buckets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Securing S3 Buckets this skillaws/agent-toolkit-for-aws | 2.8k | 1 repos | ~2k | Automated safety check: Pass | Apache-2.0 | |
| S3itsmostafa/aws-agent-skills | 1.2k | — | ~2.3k | Automated safety check: Pass | MIT | |
| AWS Essentialsericrisco/rsc-harness | 167 | — | ~2.9k | Automated safety check: Notes | MIT | |
| FoundatioFoundatioFx/Foundatio | 2.1k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Cognitoitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| PhidownESA-PhiLab/phidown | 105 | — | ~1k | Automated safety check: Pass | Apache-2.0 |
itsmostafa/aws-agent-skills
AWS S3 object storage for bucket management, object operations, and access control.
ericrisco/rsc-harness
A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or…
FoundatioFx/Foundatio
A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
ESA-PhiLab/phidown
Search, filter, download, and analyze Copernicus Data Space products with the phidown project.
borisachen/fftiers
Operate the borischen.co fftiers pipeline — season rollover, run main.R, S3 deploy from Workbench or EC2.
aws/agent-toolkit-for-aws
Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.
aws/agent-toolkit-for-aws
A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.
aws/agent-toolkit-for-aws
Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.
aws/agent-toolkit-for-aws
Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.
aws/agent-toolkit-for-aws
Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…
aws/agent-toolkit-for-aws
A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.
Works with
Categories
Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Securing S3 Buckets is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations.
Securing S3 Buckets fits situations like: the user wants to secure a new bucket; audit an existing bucket; fix a security finding; configure encryption.
Run `npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a claude-code`. Or copy the skill folder (skills/specialized-skills/storage-skills/securing-s3-buckets in aws/agent-toolkit-for-aws) into .claude/skills/securing-s3-buckets in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a codex`. Or copy the skill folder (skills/specialized-skills/storage-skills/securing-s3-buckets in aws/agent-toolkit-for-aws) into .agents/skills/securing-s3-buckets in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securing-s3-buckets, .gemini/skills/securing-s3-buckets, .github/skills/securing-s3-buckets and .opencode/skills/securing-s3-buckets in your project.
Going by SKILL.md and its folder, Securing S3 Buckets needs the command-line tools its instructions call (aws and python3). Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Securing S3 Buckets is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Securing S3 Buckets: S3 (itsmostafa/aws-agent-skills, 1.2k stars), AWS Essentials (ericrisco/rsc-harness, 167 stars), Foundatio (FoundatioFx/Foundatio, 2.1k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.
Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.