Agent skill

Hf Cloud AWS Context Discovery

by sickn33 in sickn33/agentic-awesome-skills

Discover the effective local AWS profile, region, account, and caller identity before any AWS task without exposing credentials.

Apache-2.0Auto-check: warningsDevOps & Cloud

Install Hf Cloud AWS Context Discovery

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hf-cloud-aws-context-discovery -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hf-cloud-aws-context-discovery --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hf-cloud-aws-context-discovery .claude/skills/hf-cloud-aws-context-discovery && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hf-cloud-aws-context-discovery
GitHub stars
47k
Used in
1 other repo
Token cost
~1.2k tokens
SKILL.md length
542 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
Apache-2.0

At a glance

Discover the effective local AWS profile, region, account, and caller identity before any AWS task without exposing credentials.

  • Works in 4 steps: Active profile → Region → Credentials, account ID, caller ARN → …
  • Tasks that involve Authentication
  • SKILL.md covers When to Use, What to discover, Commands to run and What to report back, plus 1 more section
  • Calls aws

What it does

Hf Cloud AWS Context Discovery is an agent skill from sickn33/agentic-awesome-skills. Discover the effective local AWS profile, region, account, and caller identity before any AWS task without exposing credentials.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Authentication. It works with Amazon Web Services. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Authentication

Example prompts

  • “/hf-cloud-aws-context-discovery”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Active profile
  2. Region
  3. Credentials, account ID, caller ARN
  4. Identify SSO / assumed-role principals

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hf Cloud AWS Context Discovery loads about 1.2k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 542 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:18
    already answers. Never open or print `~/.aws/credentials`, credential-process output, secret environment variables, acce

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its Apache-2.0 licence (© sickn33). 542 words, ~1,186 tokens.

Download SKILL.mdSave it as .claude/skills/hf-cloud-aws-context-discovery/SKILL.md (or your agent's skills folder).
name
hf-cloud-aws-context-discovery
description
Discover the effective local AWS profile, region, account, and caller identity before any AWS task without exposing credentials.
risk
safe
source
https://github.com/huggingface/skills/tree/main/skills/hf-cloud-aws-context-discovery
source_repo
huggingface/skills
source_type
official
date_added
2026-07-21
author
Hugging Face
license
Apache-2.0
license_source
https://github.com/huggingface/skills/blob/main/LICENSE
tags
hugging-face, aws, credentials, discovery, cloud
tools
claude, codex, cursor

AWS Context Discovery

Before doing any AWS work, inspect only masked AWS CLI metadata. Don't guess the region, and don't ask the user for things the CLI already answers. Never open or print ~/.aws/credentials, credential-process output, secret environment variables, access keys, session tokens, or SSO token caches.

When to Use

  • Establish the effective AWS profile, region, account, and caller before AWS work.
  • Diagnose expired SSO sessions, missing profiles, or configuration overrides.
  • Provide verified context to later SageMaker planning and deployment skills.

What to discover

Run these at the start of the AWS work and remember the results for the rest of the session.

1. Active profile

Use a profile the user explicitly named, otherwise use the profile identified by masked AWS CLI metadata. If the named profile is absent from aws configure list-profiles, surface that clearly.

2. Region

Resolution order — stop at the first one that produces a value:

  1. Region the user explicitly named in this conversation
  2. Region reported by aws configure list --profile "$profile"
  3. Region reported by aws configure get region --profile "$profile"
  4. Ask the user — but only after the first four have failed

Do not fall back to us-east-1 or any other hardcoded default.

3. Credentials, account ID, caller ARN
bash
aws sts get-caller-identity --profile "$profile" --region "$region"

Three purposes in one call: confirms credentials are valid (stop if not), returns the Account ID (needed for ARN construction), returns the Arn of the caller.

4. Identify SSO / assumed-role principals

The Arn field tells you what kind of principal this is. The pattern matters because it determines what IAM operations the caller can do.

ARN patternTypeIAM write capability
arn:aws:iam::<acct>:user/<name>IAM userDepends on attached policies
arn:aws:sts::<acct>:assumed-role/AWSReservedSSO_<...>/<email>SSO assumed-roleTypically none — can't create/modify IAM roles
arn:aws:sts::<acct>:assumed-role/<role>/<session>Regular assumed-roleDepends on the role

If the caller is SSO, surface this immediately before later skills hit iam:CreateRole and fail:

Heads up: you're authenticated via SSO (AWSReservedSSO_<PermissionSet>_...). SSO principals usually can't create IAM roles directly. If we need a SageMaker execution role, I'll look for an existing one first — if none exists, you'll need to ask whoever manages your AWS access to create one.

This is the highest-leverage thing this skill does. Surfacing it now turns a confusing mid-deployment error into a five-second conversation.

Show full SKILL.md (173 more words)Show less

Commands to run

bash
# Profiles and masked effective metadata; never read credential files directly
aws configure list-profiles
aws configure list --profile "$profile"
aws configure get region --profile "$profile"

# Validate credentials and get identity
aws sts get-caller-identity --profile "$profile" --region "$region"

aws configure list masks credential values and identifies their source. Use these metadata commands instead of parsing AWS files or inspecting secret-bearing environment variables. If the CLI cannot resolve a profile or region without exposing credentials, stop and ask the user for the non-secret profile or region value.

What to report back

One or two lines, not a wall of text:

Working with profile my-profile in eu-west-1, account 123456789012. You're authenticated via SSO, so we'll need to use an existing IAM role rather than create one.

Don't ask the user to confirm the region you just read from their config — they configured it; that is the confirmation.

If something is wrong (credentials expired, profile doesn't exist, no region anywhere), stop and surface the specific error before continuing.

Limitations

  • Discovery may reveal account IDs, role ARNs, or profile names; report only what the task needs and never expose secrets or session tokens.
  • STS identity checks require network access and valid credentials.
  • A valid identity does not imply permission to change resources.

© sickn33, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hf-cloud-aws-context-discovery of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hf Cloud AWS Context Discovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hf Cloud AWS Context Discovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hf Cloud AWS Context Discovery this skillsickn33/agentic-awesome-skills47k1 repos~1.2kAutomated safety check: WarnApache-2.0
Troubleshootaws-samples/sample-autonomous-cloud-coding-agents158—~2.7kAutomated safety check: PassMIT-0
Hf Cloud AWS Context Discoveryhuggingface/skills11k2 repos~989Automated safety check: WarnApache-2.0
Scanning For Hardcoded Secretsjeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT
AWS Account Managementhoodini/ai-agents-skills282—~3.5kAutomated safety check: PassNone
Atmos Authcloudposse/atmos1.4k—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Troubleshoot

    aws-samples/sample-autonomous-cloud-coding-agents

    Official

    Diagnose and fix common ABCA issues: deployment failures, preflight errors, authentication problems, agent failures, and build issues.

    158 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Discover the user's local AWS context (active profile, region, account ID, caller identity) at the start of any AWS task.

    11k GitHub starsUsed in 2 repos~989 tokens
    DevOps & CloudAuto-check: warnings
  • Scanning For Hardcoded Secrets

    jeremylongshore/tons-of-skills-marketplace

    Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing secrets, generic…

    2.8k GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • AWS Account Management

    hoodini/ai-agents-skills

    Manage AWS accounts, organizations, IAM, and billing. An agent skill from hoodini/ai-agents-skills.

    282 GitHub stars~3.5k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Atmos Auth

    cloudposse/atmos

    Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

    1.4k GitHub stars~4.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Managing Cloud Identity With Okta

    mukul975/Anthropic-Cybersecurity-Skills

    Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Hf Cloud AWS Context Discovery

What does Hf Cloud AWS Context Discovery do?

Discover the effective local AWS profile, region, account, and caller identity before any AWS task without exposing credentials. Hf Cloud AWS Context Discovery is an agent skill from sickn33/agentic-awesome-skills. Discover the effective local AWS profile, region, account, and caller identity before any AWS task without exposing credentials.

When should I use Hf Cloud AWS Context Discovery?

Hf Cloud AWS Context Discovery fits situations like: tasks that involve Authentication.

How do I install Hf Cloud AWS Context Discovery in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hf-cloud-aws-context-discovery -a claude-code`. Or copy the skill folder (skills/hf-cloud-aws-context-discovery in sickn33/agentic-awesome-skills) into .claude/skills/hf-cloud-aws-context-discovery in your project. Claude Code loads it when a task matches its description.

How do I install Hf Cloud AWS Context Discovery in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hf-cloud-aws-context-discovery -a codex`. Or copy the skill folder (skills/hf-cloud-aws-context-discovery in sickn33/agentic-awesome-skills) into .agents/skills/hf-cloud-aws-context-discovery in your project. Codex loads it when a task matches its description.

Can I use Hf Cloud AWS Context Discovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hf-cloud-aws-context-discovery -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hf-cloud-aws-context-discovery, .gemini/skills/hf-cloud-aws-context-discovery, .github/skills/hf-cloud-aws-context-discovery and .opencode/skills/hf-cloud-aws-context-discovery in your project.

What does Hf Cloud AWS Context Discovery need to run?

Going by SKILL.md and its folder, Hf Cloud AWS Context Discovery needs the command-line tools its instructions call (aws).

Does Hf Cloud AWS Context Discovery access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hf Cloud AWS Context Discovery safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Hf Cloud AWS Context Discovery use?

Hf Cloud AWS Context Discovery is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hf Cloud AWS Context Discovery use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hf Cloud AWS Context Discovery?

Skills that share tags, products or a category with Hf Cloud AWS Context Discovery: Troubleshoot (aws-samples/sample-autonomous-cloud-coding-agents, 158 stars), Hf Cloud AWS Context Discovery (huggingface/skills, 11k stars), Scanning For Hardcoded Secrets (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and AWS Account Management (hoodini/ai-agents-skills, 282 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hf Cloud AWS Context Discovery?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.