OPS on-demand: This skill should be used when the user asks to "audit AWS", "unused AWS resources", or…

MITAuto-check: notesDevOps & Cloud

Install Ops AWS Audit

skills CLI
$ npx skills add Lifecycle-Innovations-Limited/claude-ops --skill ops-aws-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Lifecycle-Innovations-Limited/claude-ops ops-aws-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Lifecycle-Innovations-Limited/claude-ops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-ops/skills/ops-aws-audit .claude/skills/ops-aws-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ops-aws-audit
GitHub stars
542
Token cost
~1.1k tokens
SKILL.md length
327 words
Files
1
Skills in repo
67
Repo updated
First seen
Licence
MIT

At a glance

OPS on-demand: This skill should be used when the user asks to "audit AWS", "unused AWS resources", or…

  • Works in 4 steps: Show the user the specific finding(s)… → Get explicit per-batch approval (ok /… → For any deletion/rotation, snapshot… → …
  • Asks to audit AWS
  • SKILL.md covers What this does, Configuration (env, all…, How to run and Recurring schedule, plus 1 more section
  • Calls bash and claude

What it does

Ops AWS Audit is an agent skill from Lifecycle-Innovations-Limited/claude-ops. OPS on-demand: This skill should be used when the user asks to "audit AWS", "unused AWS resources", or…

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Amazon Web Services. The repository describes itself as: Business operating system for Claude Code — 57 skills, 21 agents, smart daemon. Unified inbox (WhatsApp/Email/Slack/Telegram), autonomous PR merge, full-AWS monitoring, revenue… The licence is MIT.

When your agent uses it

  • Asks to audit AWS
  • Unused AWS resources

Example prompts

  • “audit AWS”
  • “unused AWS resources”
  • “/ops-aws-audit”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, AskUserQuestion, WebSearch, WebFetch

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Show the user the specific finding(s) and the exact aws command(s).
  2. Get explicit per-batch approval (ok / yes / proceed).
  3. For any deletion/rotation, snapshot state first; log resource IDs after.
  4. Root access keys can only be removed from a root console login — flag it,

What it can do on your machine

Read from SKILL.md and the folder at commit ee9c784. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • AskUserQuestion
    • WebSearch
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ops AWS Audit loads about 1.1k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 327 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, AskUserQuestion, WebSearch, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Lifecycle-Innovations-Limited/claude-ops at commit ee9c784, republished under its MIT licence (© Lifecycle-Innovations-Limited). 327 words, ~1,081 tokens.

Download SKILL.mdSave it as .claude/skills/ops-aws-audit/SKILL.md (or your agent's skills folder).
name
ops-aws-audit
description
OPS on-demand: This skill should be used when the user asks to "audit AWS", "unused AWS resources", or…
allowed-tools
Bash, Read, Grep, Glob, AskUserQuestion, WebSearch, WebFetch
argument-hint
[--quiet] [--schedule] [region,region]
effort
medium
maxTurns
30

What this does

Runs scripts/ops-aws-audit.sh — a read-only sweep that never mutates AWS. It inventories and analyses, then writes a severity-ranked report.

Checks include (2026 baseline):

  • IAM / credentials — root access key + root MFA, access keys older than AUDIT_KEY_AGE_DAYS (default 90), console users without MFA, and whether an IAM Access Analyzer (UNUSED_ACCESS) is configured.
  • EC2 / EBS — unattached volumes, gp2→gp3 candidates, unencrypted volumes, unassociated Elastic IPs, security groups open to 0.0.0.0/0 on SSH/RDP.
  • RDS — unencrypted or publicly-accessible instances, and orphaned manual snapshots whose source DB no longer exists.
  • S3 — account-level Block Public Access, per-bucket default encryption and lifecycle policies.
  • CloudWatch Logs — log groups with no retention (billed forever).
  • Lambda — deprecated/old runtimes.
  • Security posture — GuardDuty, Security Hub standards, Cost Anomaly Detection monitors, Compute Optimizer enrollment.
  • Cost — per-service Usage spend (RECORD_TYPE=Usage UnblendedCost) over the last AUDIT_COST_DAYS with the Δ vs the prior window. Credits mask net CE totals to ≈ $0 — this audit never uses unfiltered Blended/Unblended nets as burn.

Configuration (env, all optional)

VarDefaultMeaning
AUDIT_PROFILE(unset)Named AWS profile. Unset ⇒ standard chain (env keys / instance role / SSO).
AUDIT_REGIONS$AWS_REGION or us-east-1Comma-separated regions.
AUDIT_OUTPUT_DIR~/.aws-audit-history/audit-<ts>Where reports land.
AUDIT_KEY_AGE_DAYS90Active access-key age threshold.
AUDIT_COST_DAYS7Cost comparison window.

How to run

bash
# one region, current account

Load `ops-rules` before acting. Public repo (no personal data). Outbound: one draft → one approval → one send. If `AskUserQuestion` / `Workflow` are missing, follow Rule 10 in `ops-rules` (Hermes: numbered options / two-turn Telegram card; `delegate_task`).
bash "${CLAUDE_PLUGIN_ROOT}/scripts/ops-aws-audit.sh"

# multi-region + named profile
AUDIT_PROFILE=prod AUDIT_REGIONS=us-east-1,eu-central-1 \
  bash "${CLAUDE_PLUGIN_ROOT}/scripts/ops-aws-audit.sh"

Outputs in AUDIT_OUTPUT_DIR: report.md (human), findings.json (machine), raw/ (per-service snapshots + cost-delta.tsv), audit.log.

After the run, read findings.json and summarise CRITICAL/HIGH first.

Recurring schedule

--schedule installs a daily systemd --user timer via scripts/install-aws-audit-cron.sh (Linux; this box uses systemd, not launchd):

bash
bash "${CLAUDE_PLUGIN_ROOT}/scripts/install-aws-audit-cron.sh"
systemctl --user list-timers ops-aws-audit.timer

Dispatch to the background fleet instead:

bash
claude --bg --name aws-audit -- bash "${CLAUDE_PLUGIN_ROOT}/scripts/ops-aws-audit.sh" --quiet

Cleanup is human-gated (never automatic)

This skill only audits. To act on a finding:

  1. Show the user the specific finding(s) and the exact aws command(s).
  2. Get explicit per-batch approval (ok / yes / proceed).
  3. For any deletion/rotation, snapshot state first; log resource IDs after.
  4. Root access keys can only be removed from a root console login — flag it, do not attempt to "rotate root" from an IAM-user CLI session (that only rotates the IAM user's own key, not the root key).

© Lifecycle-Innovations-Limited, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-ops/skills/ops-aws-audit of Lifecycle-Innovations-Limited/claude-ops.

Open the folder on GitHubat commit ee9c784

Compare with similar skills

Ops AWS Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ops AWS Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ops AWS Audit this skillLifecycle-Innovations-Limited/claude-ops542—~1.1kAutomated safety check: NotesMIT
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Review Docshashicorp/terraform-provider-aws11k—~1.3kAutomated safety check: PassMPL-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only

Similar skills

  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Review Docs

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…

    11k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from Lifecycle-Innovations-Limited/claude-ops

All 67 skills in this repo
  • Ops Dash

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "ops dashboard", "pixel HQ", or…

    542 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check: notes
  • Ops Gtm

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "go to market", "GTM plan", or…

    542 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Ops Marketing

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "klaviyo", "ads spend", or…

    542 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check: notes
  • Ops Socials

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "tweet", "post to linkedin", or…

    542 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check: notes
  • Ops Yolo

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "yolo mode", "run the business today"…

    542 GitHub stars~4k tokensUpdated yesterday
    Auto-check: notes
  • Ops Monitor

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "datadog", "APM alerts", or…

    542 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check: notes

Categories

Questions about Ops AWS Audit

What does Ops AWS Audit do?

OPS on-demand: This skill should be used when the user asks to "audit AWS", "unused AWS resources", or…. Ops AWS Audit is an agent skill from Lifecycle-Innovations-Limited/claude-ops.

When should I use Ops AWS Audit?

Ops AWS Audit fits situations like: asks to audit AWS; unused AWS resources.

How do I install Ops AWS Audit in Claude Code?

Run `npx skills add Lifecycle-Innovations-Limited/claude-ops --skill ops-aws-audit -a claude-code`. Or copy the skill folder (claude-ops/skills/ops-aws-audit in Lifecycle-Innovations-Limited/claude-ops) into .claude/skills/ops-aws-audit in your project. Claude Code loads it when a task matches its description.

How do I install Ops AWS Audit in Codex?

Run `npx skills add Lifecycle-Innovations-Limited/claude-ops --skill ops-aws-audit -a codex`. Or copy the skill folder (claude-ops/skills/ops-aws-audit in Lifecycle-Innovations-Limited/claude-ops) into .agents/skills/ops-aws-audit in your project. Codex loads it when a task matches its description.

Can I use Ops AWS Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Lifecycle-Innovations-Limited/claude-ops --skill ops-aws-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ops-aws-audit, .gemini/skills/ops-aws-audit, .github/skills/ops-aws-audit and .opencode/skills/ops-aws-audit in your project.

What does Ops AWS Audit need to run?

Going by SKILL.md and its folder, Ops AWS Audit needs the command-line tools its instructions call (bash and claude). Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, AskUserQuestion, WebSearch, WebFetch.

Does Ops AWS Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ops AWS Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ops AWS Audit use?

Ops AWS Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ops AWS Audit use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ops AWS Audit?

Skills that share tags, products or a category with Ops AWS Audit: Cloud Cost Optimization (wshobson/agents, 40k stars), Review Docs (hashicorp/terraform-provider-aws, 11k stars), AWS Cdk Development (zxkane/aws-skills, 367 stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ops AWS Audit?

Lifecycle-Innovations-Limited (a GitHub organization) maintains it in Lifecycle-Innovations-Limited/claude-ops, which has 542 GitHub stars. The repository holds 67 skills in this directory. The repository was last updated on October 10, 2026.

Source: Lifecycle-Innovations-Limited/claude-ops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.