Agent skill

AWS Sst Development

by zxkane in zxkane/aws-skills

SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

MITAuto-check: warningsDevOps & Cloud

Install AWS Sst Development

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add zxkane/aws-skills --skill aws-sst-development -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zxkane/aws-skills aws-sst-development --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zxkane/aws-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aws-iac/skills/aws-sst-development .claude/skills/aws-sst-development && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-sst-development
GitHub stars
367
Token cost
~2.7k tokens
SKILL.md length
1,220 words
Files
4 (incl. references)
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

  • Works in 4 steps: sst.config.ts — the app name, home,… → infra/ — one file per domain (storage,… → infra/tests/ — source-level Vitest… → …
  • Editing sst.config.ts
  • SKILL.md covers When you're invoked, Orientation: read the repo…, The conventions, and which are… and Working rhythm, plus 1 more section
  • Calls npx, pulumi and tsc

What it does

AWS Sst Development is an agent skill from zxkane/aws-skills. SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework. Use when writing or editing sst.config.ts, building infra/ modules (sst.aws.Function/Bucket/Dynamo/Cron/Service/Router, sst.Secret, sst.Linkable, raw aws. Pulumi resources), wiring resource links, scoping IAM, or running sst deploy/dev/diff/remove. Essential when the user mentions SST, sst.config.ts, $config, $transform, $interpolate, sst.aws., sst.Secret, Pulumi/Ion, "sst deploy", a failed SST deploy (ConflictException on a…

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/authoring.md`, `references/deploy-and-troubleshoot.md` and `references/testing.md`).

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Amazon Web Services, Pulumi, AWS CloudFormation and Terraform. The repository describes itself as: Claude Code plugins and agent skills for AWS development — IaC(CDK/SST), serverless, cost ops, and Bedrock AgentCore. The licence is MIT.

When your agent uses it

  • Editing sst.config.ts
  • Building infra/ modules (sst.aws.Function/Bucket/Dynamo/Cron/Service/Router
  • A failed SST deploy (ConflictException on a resource-type change
  • Identifier filename has already been declared

Example prompts

  • “sst deploy”
  • “Identifier”
  • “has already been declared”
  • “/aws-sst-development”

Requirements

  • Python 3
  • Node.js
  • Pre-approved tools (allowed-tools): mcp__awsdocs__*, mcp__aws-mcp__*, Read, Write, Edit, Glob, Grep, Bash(npx sst *), Bash(npm *), Bash(pnpm *), Bash(npx vitest *), Bash(aws sts get-caller-identity), Bash(aws ssm get-parameter*), Bash(aws ssm get-parameters-by-path*), Bash(aws lambda get-function*), Bash(aws lambda list-versions-by-function*)

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. sst.config.ts — the app name, home, providers/region, defaultTags,
  2. infra/ — one file per domain (storage, functions, api, observability…).
  3. infra/tests/ — source-level Vitest assertions that pin resource
  4. package.json / .nvmrc — package manager (npm vs pnpm), Node version,

What it can do on your machine

Read from SKILL.md and the folder at commit 68530c6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • mcp__awsdocs__*
    • mcp__aws-mcp__*
    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Bash(npx sst *)
    • Bash(npm *)
    • Bash(pnpm *)

    …and 6 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • pulumi
    • tsc
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx and aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Sst Development loads about 2.7k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 258 tokens; SKILL.md has 1,220 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~258
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningContains zero-width charactersSKILL.md:108
    v` runs fine). The fix is `$interpolate`⟨U+200B⟩`` `${bucket.arn}/*` ``. This

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zxkane/aws-skills at commit 68530c6, republished under its MIT licence (© zxkane). 1,220 words, ~2,674 tokens.

Download SKILL.mdSave it as .claude/skills/aws-sst-development/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
aws-sst-development
description
SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework. Use when writing or editing sst.config.ts, building infra/ modules (sst.aws.Function/Bucket/Dynamo/Cron/Service/Router, sst.Secret, sst.Linkable, raw aws.* Pulumi resources), wiring resource links, scoping IAM, or running sst deploy/dev/diff/remove. Essential when the user mentions SST, sst.config.ts, $config, $transform, $interpolate, sst.aws.*, sst.Secret, Pulumi/Ion, "sst deploy", a failed SST deploy (ConflictException on a resource-type change, "Identifier '__filename' has already been declared", MalformedPolicyDocument on an Output<T>), or wants to scaffold/troubleshoot AWS infrastructure with SST. Also use when a request to "deploy my AWS stack" or "add a Lambda/bucket/table" is made in a repo that already contains an sst.config.ts (using $config) or an sst dependency. Do NOT use when the task is primarily AWS CDK, Terraform, raw CloudFormation, or SAM with no SST present — those have their own tooling.
allowed-tools
mcp__awsdocs__*, mcp__aws-mcp__*, Read, Write, Edit, Glob, Grep, Bash(npx sst *), Bash(npm *), Bash(pnpm *), Bash(npx vitest *), Bash(aws sts get-caller-identity), Bash(aws ssm get-parameter*), Bash(aws ssm get-parameters-by-path*), Bash(aws lambda get-function*), Bash(aws lambda list-versions-by-function*)
context
fork
skills
aws-mcp-setup

SST v4 for AWS

SST v4 (the "Ion" engine) is a Pulumi-backed IaC framework: you describe AWS resources in TypeScript and SST/Pulumi reconciles them into your account. It gives you high-level sst.aws.* components (Function, Bucket, Dynamo, Cron, Service, …) that expand into many underlying resources, plus an escape hatch to any raw Pulumi aws.* resource for the long tail. This skill encodes a production-proven way to author, link, test, deploy, and troubleshoot SST stacks on AWS — distilled from real multi-stack projects that have paid for each lesson with a prod incident.

SST and Pulumi are third-party — verify current syntax with Context7 (resolve-library-id → query-docs for sst or pulumi-aws) when you're unsure about a component's options. Verify AWS-side facts (service limits, model IDs, IAM action names, region availability) with the AWS docs MCP, never from memory. The patterns here are the how; the docs are the what.

When you're invoked

Figure out which mode you're in and jump to the right reference:

SituationGo to
New project, or adding a resource/module to an existing SST appAuthor → references/authoring.md
Wiring one module's output into another (links, SSM, IAM scope)Author → references/authoring.md § Sharing
Writing tests for infra so changes don't silently breakTest → references/testing.md
Running a deploy, or a deploy just failedDeploy/Operate → references/deploy-and-troubleshoot.md
Migrating a resource between Pulumi types, renaming a physical nameDeploy/Operate → references/deploy-and-troubleshoot.md § Migrations

Always read the relevant reference before editing — they carry the why behind each rule, which matters more than the rule itself.

Orientation: read the repo before you touch it

SST projects are conventional but not identical. Before editing, build a quick map so your change matches the house style instead of fighting it:

  1. sst.config.ts — the app name, home, providers/region, defaultTags, any global $transform (Node runtime pin, bundle fixups), and the order in which run() imports infra/ modules. The import order is the dependency order; respect it.
  2. infra/ — one file per domain (storage, functions, api, observability…). This is where resources are declared. Check for an infra/CLAUDE.md — these projects keep IaC-specific rules there, and it's the single most valuable file to read first.
  3. infra/tests/ — source-level Vitest assertions that pin resource invariants. If they exist, your change must keep them green and probably needs a new assertion.
  4. package.json / .nvmrc — package manager (npm vs pnpm), Node version, and the sst/pulumi versions actually installed.

Run npx sst version to confirm you're on v4/Ion (the $config + .sst/platform/ signature). v2/v3 ("SST Classic", CDK-based) is a different framework — these patterns don't apply there.

The conventions, and which are universal vs tunable

The projects this skill is built from share a deliberate house style. Some of it is universal (true for any SST v4 + AWS project — apply it everywhere); some is project-specific (a sensible default these projects chose — adopt it for consistency, but recognize a project may differ).

Universal — these principles hold for any SST v4 + AWS project:

  • Control the Node runtime deliberately, in one place. Don't leave it to whatever the installed SST happens to default to. The idiom is a single global $transform(sst.aws.Function, (args) => { args.runtime ??= "nodejs24.x" }) in run() — ??= is correct here (the transform runs before the component applies its own default, so it fills in only when the user didn't set one). Recent SST already defaults to a current Node runtime, so check the installed default first (Context7); the transform is then version-independence insurance so a future SST downgrade can't silently move your fleet. See references/authoring.md.
  • Never interpolate a Pulumi Output<T> into a plain JS template literal. Use $interpolate (or pulumi.interpolate). A bare top-level `${bucket.arn}/*` stringifies the Output to a [Output<T>] placeholder and produces a broken ARN that only fails at deploy time (it type-checks and sst dev runs fine). The fix is $interpolate``` ${bucket.arn}/*``. This has caused prod deploy outages. Seereferences/authoring.md` § Outputs.
  • Migrating a resource between Pulumi types should default to two PRs — Pulumi creates-before-destroys, so for a uniqueness-constrained AWS name (bucket, IAM role, gateway) the old resource still owns it and the create fails with ConflictException. Two sequential deploys (teardown, then recreate) is the conservative default; aliases: / pulumi import / state surgery can bridge identity in some cases but only with a reviewed plan. See references/deploy-and-troubleshoot.md § Migrations.
  • Prefer typed sst.aws.* / aws.* resources over the aws.cloudcontrol.Resource escape hatch. CloudControl outputs are stringly-typed and oneOf fields don't patch cleanly. Use it only when no typed resource exists yet, and migrate off it when one ships.

Project-specific defaults — adopt for consistency, but confirm per repo:

Show full SKILL.md (487 more words)Show less
  • Region ap-northeast-1, home: "aws", and defaultTags carrying Project / Stage / ManagedBy: "sst".
  • Stage-gated lifecycle: removal: stage === "prod" ? "retain" : "remove" and protect: stage === "prod" so prod resources survive a stack tear-down and non-prod previews clean up.
  • SSM Parameter Store as the out-of-graph contract under a /{app}/{stage}/{domain}/... prefix — for consumers that aren't in the Pulumi graph (CI scripts, sibling apps, operators). For same-app Lambdas, prefer SST link: (it wires a real dependency edge and grants IAM); don't route same-app sharing through SSM. See references/authoring.md § Sharing.
  • Lazy await import("./infra/<module>") inside run() so sst dev hot-reload stays light. (For testing, a module export still runs its top-level new sst.aws.* unless it's wrapped in a factory function — see references/testing.md for how to test infra.)
  • Source-level Vitest tests on every infra module — a lightweight, house-style regression net asserting on the source text (resource names, index shapes, IAM scopes). It's a deliberate choice, not an SST limit: Pulumi does support runtime mocks (@pulumi/pulumi/runtime) for behavioral graph tests when a module has real logic. Source assertions don't replace a preview-deploy + smoke test. See references/testing.md.
  • An observability gate: every new Lambda/queue/schedule gets an alarm and structured logging before merge. Whether you enforce this depends on the project, but it's cheap insurance. See references/deploy-and-troubleshoot.md § Observability.

When you introduce a convention, say which bucket it's in ("this is universal" vs "matching this repo's house style") so the user can override the project-specific ones deliberately.

Working rhythm

  1. Orient (above) — map config, modules, tests, tooling.
  2. Verify syntax with Context7 / AWS docs MCP if anything is non-obvious. Don't guess at a component's option name.
  3. Author the resource/module following references/authoring.md. Match the surrounding file's commenting density and naming — these projects comment the why heavily, and a terse one-liner in a heavily-annotated file reads as a regression.
  4. Test — add or update source-level assertions (references/testing.md) and run npx vitest (or the repo's test script). Run npx sst diff and/or tsc --noEmit to catch type and plan errors before deploying.
  5. Deploy/operate per references/deploy-and-troubleshoot.md. Confirm the target account with aws sts get-caller-identity before any sst deploy.
  6. Clean up any exported state files — they contain account IDs and ARNs and must not linger in /tmp or chat history.

What good looks like

  • The change is the smallest diff that satisfies the requirement, in the right infra/ module, wired into run() in dependency order.
  • Every Lambda gets the right runtime via the global transform (you didn't hand-set runtime unless intentionally diverging — e.g. a Python function).
  • Cross-resource references use link: (in-graph) and/or $interpolate-scoped IAM; outputs other tools consume are published to SSM under the stage prefix.
  • New infra has a matching source-level test, and the existing suite stays green.
  • You confirmed AWS-side facts via the docs MCP and SST/Pulumi syntax via Context7 rather than relying on recall.
  • Anything irreversible (deploy, sst remove, a resource-type migration) was flagged to the user with the account it targets, and migrations were planned as two PRs, not one.

© zxkane, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. 1 hidden character (zero-width or bidirectional) removed. Raw file

Files

SKILL.md and 3 other files (references) in plugins/aws-iac/skills/aws-sst-development of zxkane/aws-skills.

  • SKILL.md
  • references/authoring.md
  • references/deploy-and-troubleshoot.md
  • references/testing.md

Open the folder on GitHubat commit 68530c6

Compare with similar skills

AWS Sst Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Sst Development compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Sst Development this skillzxkane/aws-skills367—~2.7kAutomated safety check: WarnMIT
Generating Infrastructure As Codejeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT
Infrastructure As Codeseb1n/awesome-ai-agent-skills206—~3.3kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0
Infra Syncagentic-community/mcp-gateway-registry967—~2.7kAutomated safety check: PassApache-2.0

Similar skills

  • Generating Infrastructure As Code

    jeremylongshore/tons-of-skills-marketplace

    Execute use when generating infrastructure as code configurations.

    2.8k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Infrastructure As Code

    seb1n/awesome-ai-agent-skills

    Define, deploy, and manage cloud infrastructure as code using tools like Terraform, Pulumi, CloudFormation, and CDK, ensuring consistency, repeatability, and version control.

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Infra Sync

    agentic-community/mcp-gateway-registry

    Keep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry.

    967 GitHub stars~2.7k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    115 GitHub stars~5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from zxkane/aws-skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    Auto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Auto-check passed
  • AWS Agentic AI

    zxkane/aws-skills

    AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.

    367 GitHub stars~2.5k tokensUpdated 3 mo ago
    Auto-check passed
  • AWS Cost Operations

    zxkane/aws-skills

    AWS cost optimization, monitoring, and operational excellence expert.

    367 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • AWS MCP Setup

    zxkane/aws-skills

    Configure AWS MCP servers for documentation search and API access.

    367 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about AWS Sst Development

What does AWS Sst Development do?

SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework. AWS Sst Development is an agent skill from zxkane/aws-skills. SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

When should I use AWS Sst Development?

AWS Sst Development fits situations like: editing sst.config.ts; building infra/ modules (sst.aws.Function/Bucket/Dynamo/Cron/Service/Router; A failed SST deploy (ConflictException on a resource-type change; identifier filename has already been declared.

How do I install AWS Sst Development in Claude Code?

Run `npx skills add zxkane/aws-skills --skill aws-sst-development -a claude-code`. Or copy the skill folder (plugins/aws-iac/skills/aws-sst-development in zxkane/aws-skills) into .claude/skills/aws-sst-development in your project. Claude Code loads it when a task matches its description.

How do I install AWS Sst Development in Codex?

Run `npx skills add zxkane/aws-skills --skill aws-sst-development -a codex`. Or copy the skill folder (plugins/aws-iac/skills/aws-sst-development in zxkane/aws-skills) into .agents/skills/aws-sst-development in your project. Codex loads it when a task matches its description.

Can I use AWS Sst Development in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zxkane/aws-skills --skill aws-sst-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-sst-development, .gemini/skills/aws-sst-development, .github/skills/aws-sst-development and .opencode/skills/aws-sst-development in your project.

What does AWS Sst Development need to run?

Going by SKILL.md and its folder, AWS Sst Development needs the command-line tools its instructions call (npx, pulumi, tsc and aws). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: mcp__awsdocs__*, mcp__aws-mcp__*, Read, Write, Edit, Glob, Grep, Bash(npx sst *), Bash(npm *), Bash(pnpm *), Bash(npx vitest *), Bash(aws sts get-caller-identity), Bash(aws ssm get-parameter*), Bash(aws ssm get-parameters-by-path*), Bash(aws lambda get-function*), Bash(aws lambda list-versions-by-function*).

Does AWS Sst Development access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is AWS Sst Development safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): contains zero-width characters. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does AWS Sst Development use?

AWS Sst Development is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Sst Development use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.4k tokens, read only when the agent opens those files.

What are the alternatives to AWS Sst Development?

Skills that share tags, products or a category with AWS Sst Development: Generating Infrastructure As Code (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Infrastructure As Code (seb1n/awesome-ai-agent-skills, 206 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars) and AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Sst Development?

zxkane (a GitHub user) maintains it in zxkane/aws-skills, which has 367 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on June 15, 2026.

Source: zxkane/aws-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.