Agent skill

Hf Cloud Sagemaker Iam Preflight

by waybarrios in waybarrios/opencode-power-pack

Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.

Apache-2.0Auto-check passedSecurity

Install Hf Cloud Sagemaker Iam Preflight

skills CLI
$ npx skills add waybarrios/opencode-power-pack --skill hf-cloud-sagemaker-iam-preflight -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install waybarrios/opencode-power-pack hf-cloud-sagemaker-iam-preflight --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hf-cloud-sagemaker-iam-preflight .claude/skills/hf-cloud-sagemaker-iam-preflight && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hf-cloud-sagemaker-iam-preflight
GitHub stars
534
Token cost
~1.6k tokens
SKILL.md length
739 words
Files
5 (incl. scripts, references)
Skills in repo
32
Repo updated
First seen
Licence
Apache-2.0

At a glance

Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.

  • Works in 3 steps: Did the user provide a role? → Discover existing roles → Create, only if discovery found nothing
  • A role ARN is missing
  • SKILL.md covers Running the helpers…, Order of operations, What "validated" means and Minimum permissions, plus 1 more section
  • Runs Python scripts from its folder; calls aws, python3 and python

What it does

Hf Cloud Sagemaker Iam Preflight is an agent skill from waybarrios/opencode-power-pack. Verify or select a SageMaker execution role before creating models, endpoints, or training jobs. Use when a role ARN is missing or IAM access fails; inspect existing roles before proposing role creation.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/minimum-permissions.json`, `references/trust-policy.json` and `scripts/check_role.py`).

It sits in Security. It works with Amazon SageMaker, Amazon Web Services, Bash and PowerShell. The repository describes itself as: 54 rigorous skills for Codex, OpenCode, and Pi: code review, security audit, feature development, frontend design, MCP tools, Hugging Face ML/training, and more. The licence is Apache-2.0.

When your agent uses it

  • A role ARN is missing
  • IAM access fails
  • Inspect existing roles before proposing role creation

Example prompts

  • “/hf-cloud-sagemaker-iam-preflight”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Did the user provide a role?
  2. Discover existing roles
  3. Create, only if discovery found nothing

What it can do on your machine

Read from SKILL.md and the folder at commit 9dccb6d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • python3
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hf Cloud Sagemaker Iam Preflight loads about 1.6k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 739 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from waybarrios/opencode-power-pack at commit 9dccb6d, republished under its Apache-2.0 licence (© waybarrios). 739 words, ~1,604 tokens.

Download SKILL.mdSave it as .claude/skills/hf-cloud-sagemaker-iam-preflight/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hf-cloud-sagemaker-iam-preflight
description
Verify or select a SageMaker execution role before creating models, endpoints, or training jobs. Use when a role ARN is missing or IAM access fails; inspect existing roles before proposing role creation.
license
Apache-2.0 (modified; see UPSTREAMS.json)

SageMaker IAM Preflight

Every SageMaker resource needs an execution role — the IAM role SageMaker assumes to read model artifacts from S3, pull serving containers from ECR, and write logs. Most deployments fail here because the script tried to create a new role without checking if a usable one already existed, then blew up because the caller is an SSO principal.

This skill encodes the right order: discover, validate, only create if necessary.

Running the helpers (cross-platform)

The helpers are Python so they run identically on Windows, macOS, and Linux:

bash
python3 scripts/check_role.py        # macOS / Linux
python  scripts/check_role.py        # Windows (PowerShell / cmd)

Run them from the shell where the AWS CLI already works — i.e. wherever aws sts get-caller-identity succeeds. The script shells out to that same aws binary and inherits the shell's profile, region, SSO session, proxy, and credential chain.

Windows / WSL / Git Bash caveat. Do not invoke these through a Bash shim (WSL, Git Bash, MSYS) on Windows. Those Bash environments frequently do not share the Windows AWS config, credentials, SSO sessions, environment variables, or proxy settings — so aws sts get-caller-identity fails inside Bash even when it works natively in PowerShell. (This is exactly why the old .sh helpers failed on Windows and were replaced with Python.) If you're in PowerShell, run python ...\check_role.py directly in PowerShell. If the helper still can't see your identity, run the same discovery natively (see "Native AWS CLI equivalent" below) in the shell where aws sts get-caller-identity returns your ARN.

Order of operations

Step 1 — Did the user provide a role?

Validate that one specifically:

bash
python3 scripts/check_role.py "<role-name-or-arn>"

On success it prints the ARN to stdout (exit 0). On failure it logs why on stderr. Don't try to silently fix a broken role — surface the problem.

Step 2 — Discover existing roles
bash
python3 scripts/check_role.py

Lists roles matching common SageMaker patterns (AmazonSageMaker-ExecutionRole-*, SageMakerExecutionRole*, etc.), ranks by last-used date (most recent first), validates trust policy in that order, returns the first usable ARN. Most accounts that have used SageMaker before already have one.

Why rank by last-used: in accounts with multiple roles (auto-generated 2021 role + manual project role + etc.), the alphabetically-first one is rarely the actively-maintained one. The most-recently-used role is more likely to have current policies — including cross-account ECR pull. The script prints the ranking so you can see which got picked.

IAM frequently reports no RoleLastUsed at all (tracking only covers recent activity). When every candidate ties at "never used", the script falls back to newest creation date — a newer role is more likely to have current policies than a 2021 leftover.

Show full SKILL.md (329 more words)Show less
Step 3 — Create, only if discovery found nothing

If the user can create (has IAM permissions):

bash
python3 scripts/create_role.py "<role-name>" "<model-bucket>"

Second arg scopes S3 access to a specific bucket. Omit if unknown; script warns and the user can update the policy later.

If the user cannot create (SSO principal — hf-cloud-aws-context-discovery will have flagged this):

Stop and surface this clearly. Don't retry alternative IAM operations hoping one works:

I can't find an existing SageMaker execution role, and you're authenticated via SSO so you can't create one directly. Please either:

  • Ask your AWS admin for a SageMaker execution role ARN, or
  • Have them grant your SSO permission set iam:CreateRole, iam:AttachRolePolicy, iam:PutRolePolicy

Specific instructions get unblocked fast; vague "permission denied" messages don't.

What "validated" means

A role is usable when (1) it exists, (2) its trust policy allows sagemaker.amazonaws.com to sts:AssumeRole — see references/trust-policy.json for the canonical form.

check_role.py verifies these two. It does not deep-check permissions because comprehensive analysis is expensive (iam:SimulatePrincipalPolicy per action) and most existing SageMaker roles are over-permissioned via AmazonSageMakerFullAccess. If you suspect a permissions issue at deploy time, the deployment error will tell you which action was denied — fix it then, not preemptively.

Minimum permissions

references/minimum-permissions.json covers what SageMaker actually needs:

  • s3:GetObject + s3:ListBucket on the model artifact bucket
  • ECR pull permissions
  • CloudWatch logs and metrics

Layered on top of AmazonSageMakerFullAccess (attached by create_role.py). Replace REPLACE_WITH_MODEL_BUCKET in the template with the actual bucket name — create_role.py does this automatically when given a bucket as its second argument.

Native AWS CLI equivalent (fallback)

If the Python helper can't run or can't see your identity (rare — usually a broken PATH or running under a Bash shim that lacks AWS context), do the same preflight by hand in the shell where aws sts get-caller-identity works. The logic is just AWS CLI calls; the helper exists only to bundle and rank them.

PowerShell:

powershell
# 1. List candidate SageMaker roles
aws iam list-roles --query "Roles[?contains(RoleName,'SageMaker') || contains(RoleName,'sagemaker')]" --output json

# 2. For each candidate, confirm the trust policy allows sagemaker.amazonaws.com
aws iam get-role --role-name <role-name> --query "Role.AssumeRolePolicyDocument" --output json

# 3. Prefer the most-recently-used role with SageMaker-execution naming
#    (LastUsedDate is often None for every role — then prefer newest CreateDate)
aws iam get-role --role-name <role-name> --query "Role.[RoleLastUsed.LastUsedDate, CreateDate]" --output text

Pick the most-recently-used role whose trust policy contains sagemaker.amazonaws.com. Use the resulting ARN exactly as if check_role.py had returned it. Bash/macOS/Linux use the same commands.

© waybarrios, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/hf-cloud-sagemaker-iam-preflight of waybarrios/opencode-power-pack.

  • SKILL.md
  • references/minimum-permissions.json
  • references/trust-policy.json
  • scripts/check_role.py
  • scripts/create_role.py

Open the folder on GitHubat commit 9dccb6d

Compare with similar skills

Hf Cloud Sagemaker Iam Preflight next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hf Cloud Sagemaker Iam Preflight compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hf Cloud Sagemaker Iam Preflight this skillwaybarrios/opencode-power-pack534—~1.6kAutomated safety check: PassApache-2.0
SageMaker IAM Role Preflighthuggingface/skills11k1 repos~1.8kAutomated safety check: PassApache-2.0
Python Environment Setup for SageMakerhuggingface/skills11k2 repos~1.7kAutomated safety check: PassApache-2.0
Hyperpod Version Checkerawslabs/agent-plugins916—~910Automated safety check: PassApache-2.0
SDK Getting Startedawslabs/agent-plugins916—~248Automated safety check: PassApache-2.0
Jeecg Onlformjeecgboot/skills239—~7.7kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create.

    11k GitHub starsUsed in 1 repo~1.8k tokens
    DevOps & CloudAuto-check passed
  • Official

    Sets up an isolated Python environment with a supported interpreter and current boto3 before any SageMaker deployment, training or AWS automation code runs.

    11k GitHub starsUsed in 2 repos~1.7k tokens
    AI & LLM EngineeringAuto-check passed
  • Hyperpod Version Checker

    awslabs/agent-plugins

    Official

    Check and compare software component versions on SageMaker HyperPod cluster nodes - NVIDIA drivers, CUDA toolkit, cuDNN, NCCL, EFA, AWS OFI NCCL, GDRCopy, MPI, Neuron SDK (Trainium/Inferentia)…

    916 GitHub stars~910 tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • SDK Getting Started

    awslabs/agent-plugins

    Official

    Validates the user's environment for SageMaker AI operations — checks SDK version, AWS region, and execution role.

    916 GitHub stars~248 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Jeecg Onlform

    jeecgboot/skills

    JeecgBoot Online表单(cgform)全生命周期管理——通过API自动创建/编辑数据库表和表单配置, 支持单表、主子表、树表,26种控件类型,以及JS/Java/SQL增强、权限配置、数据CRUD、积木报表集成。

    239 GitHub stars~7.7k tokensUpdated 23 days ago
    DatabasesAuto-check passed
  • Oss Bounty Finder

    tinyfish-io/tinyfish-cookbook

    Find paid open-source work, OSS bounties, open source grants, or ways to get paid contributing to open source.

    2.2k GitHub stars~4.6k tokensUpdated 2 days ago
    Data & AnalyticsAuto-check passed

More from waybarrios/opencode-power-pack

All 32 skills in this repo
  • Huggingface LLM Trainer

    waybarrios/opencode-power-pack

    Train or fine-tune language models with TRL or Unsloth on Hugging Face Jobs, including SFT, DPO, GRPO, reward models, and GGUF conversion.

    534 GitHub stars~3k tokensUpdated 5 days ago
    Auto-check passed
  • Huggingface Vision Trainer

    waybarrios/opencode-power-pack

    Train object-detection, image-classification, or SAM segmentation models on Hugging Face Jobs.

    534 GitHub stars~2.7k tokensUpdated 5 days ago
    Auto-check passed
  • Codeql

    waybarrios/opencode-power-pack

    Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

    534 GitHub starsUsed in 2 repos~3.7k tokens
    Auto-check passed
  • Semgrep

    waybarrios/opencode-power-pack

    Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

    534 GitHub stars~2.4k tokensUpdated 5 days ago
    Auto-check passed
  • Insecure Defaults

    waybarrios/opencode-power-pack

    Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production.

    534 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Train Sentence Transformers

    waybarrios/opencode-power-pack

    Train or fine-tune SentenceTransformer bi-encoders, CrossEncoder rerankers, or SparseEncoder models, including losses, negatives, evaluation, distillation, LoRA, and Matryoshka.

    534 GitHub stars~2.2k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about Hf Cloud Sagemaker Iam Preflight

What does Hf Cloud Sagemaker Iam Preflight do?

Verify or select a SageMaker execution role before creating models, endpoints, or training jobs. Hf Cloud Sagemaker Iam Preflight is an agent skill from waybarrios/opencode-power-pack. Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.

When should I use Hf Cloud Sagemaker Iam Preflight?

Hf Cloud Sagemaker Iam Preflight fits situations like: A role ARN is missing; IAM access fails; inspect existing roles before proposing role creation.

How do I install Hf Cloud Sagemaker Iam Preflight in Claude Code?

Run `npx skills add waybarrios/opencode-power-pack --skill hf-cloud-sagemaker-iam-preflight -a claude-code`. Or copy the skill folder (skills/hf-cloud-sagemaker-iam-preflight in waybarrios/opencode-power-pack) into .claude/skills/hf-cloud-sagemaker-iam-preflight in your project. Claude Code loads it when a task matches its description.

How do I install Hf Cloud Sagemaker Iam Preflight in Codex?

Run `npx skills add waybarrios/opencode-power-pack --skill hf-cloud-sagemaker-iam-preflight -a codex`. Or copy the skill folder (skills/hf-cloud-sagemaker-iam-preflight in waybarrios/opencode-power-pack) into .agents/skills/hf-cloud-sagemaker-iam-preflight in your project. Codex loads it when a task matches its description.

Can I use Hf Cloud Sagemaker Iam Preflight in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waybarrios/opencode-power-pack --skill hf-cloud-sagemaker-iam-preflight -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hf-cloud-sagemaker-iam-preflight, .gemini/skills/hf-cloud-sagemaker-iam-preflight, .github/skills/hf-cloud-sagemaker-iam-preflight and .opencode/skills/hf-cloud-sagemaker-iam-preflight in your project.

What does Hf Cloud Sagemaker Iam Preflight need to run?

Going by SKILL.md and its folder, Hf Cloud Sagemaker Iam Preflight needs Python for the scripts in its folder and the command-line tools its instructions call (aws, python3 and python). Our summary lists: Python 3.

Does Hf Cloud Sagemaker Iam Preflight access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hf Cloud Sagemaker Iam Preflight safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hf Cloud Sagemaker Iam Preflight use?

Hf Cloud Sagemaker Iam Preflight is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hf Cloud Sagemaker Iam Preflight use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 310 tokens, read only when the agent opens those files.

What are the alternatives to Hf Cloud Sagemaker Iam Preflight?

Skills that share tags, products or a category with Hf Cloud Sagemaker Iam Preflight: SageMaker IAM Role Preflight (huggingface/skills, 11k stars), Python Environment Setup for SageMaker (huggingface/skills, 11k stars), Hyperpod Version Checker (awslabs/agent-plugins, 916 stars) and SDK Getting Started (awslabs/agent-plugins, 916 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hf Cloud Sagemaker Iam Preflight?

waybarrios (a GitHub user) maintains it in waybarrios/opencode-power-pack, which has 534 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 6, 2026.

Source: waybarrios/opencode-power-pack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.