Generating Infrastructure As Code
jeremylongshore/tons-of-skills-marketplace
Execute use when generating infrastructure as code configurations.
SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add zxkane/aws-skills --skill aws-sst-development -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zxkane/aws-skills aws-sst-development --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zxkane/aws-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aws-iac/skills/aws-sst-development .claude/skills/aws-sst-development && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aws-sst-development" agent skill from https://github.com/zxkane/aws-skills/tree/main/plugins/aws-iac/skills/aws-sst-development into .claude/skills/aws-sst-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-sst-development", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zxkane/aws-skills/tree/main/plugins/aws-iac/skills/aws-sst-developmentType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zxkane/aws-skills --skill aws-sst-development -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zxkane/aws-skills aws-sst-development --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zxkane/aws-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/aws-iac/skills/aws-sst-development .agents/skills/aws-sst-development && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aws-sst-development" agent skill from https://github.com/zxkane/aws-skills/tree/main/plugins/aws-iac/skills/aws-sst-development into .agents/skills/aws-sst-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-sst-development", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zxkane/aws-skills --skill aws-sst-development -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zxkane/aws-skills aws-sst-development --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zxkane/aws-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/aws-iac/skills/aws-sst-development .cursor/skills/aws-sst-development && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aws-sst-development" agent skill from https://github.com/zxkane/aws-skills/tree/main/plugins/aws-iac/skills/aws-sst-development into .cursor/skills/aws-sst-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-sst-development", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zxkane/aws-skills.git --path plugins/aws-iac/skills/aws-sst-development--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zxkane/aws-skills --skill aws-sst-development -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zxkane/aws-skills aws-sst-development --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zxkane/aws-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/aws-iac/skills/aws-sst-development .gemini/skills/aws-sst-development && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aws-sst-development" agent skill from https://github.com/zxkane/aws-skills/tree/main/plugins/aws-iac/skills/aws-sst-development into .gemini/skills/aws-sst-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-sst-development", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zxkane/aws-skills aws-sst-developmentInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zxkane/aws-skills --skill aws-sst-development -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zxkane/aws-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/aws-iac/skills/aws-sst-development .github/skills/aws-sst-development && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aws-sst-development" agent skill from https://github.com/zxkane/aws-skills/tree/main/plugins/aws-iac/skills/aws-sst-development into .github/skills/aws-sst-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-sst-development", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zxkane/aws-skills --skill aws-sst-development -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zxkane/aws-skills aws-sst-development --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zxkane/aws-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/aws-iac/skills/aws-sst-development .opencode/skills/aws-sst-development && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aws-sst-development" agent skill from https://github.com/zxkane/aws-skills/tree/main/plugins/aws-iac/skills/aws-sst-development into .opencode/skills/aws-sst-development/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aws-sst-development", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aws-sst-developmentSST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.
AWS Sst Development is an agent skill from zxkane/aws-skills. SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework. Use when writing or editing sst.config.ts, building infra/ modules (sst.aws.Function/Bucket/Dynamo/Cron/Service/Router, sst.Secret, sst.Linkable, raw aws. Pulumi resources), wiring resource links, scoping IAM, or running sst deploy/dev/diff/remove. Essential when the user mentions SST, sst.config.ts, $config, $transform, $interpolate, sst.aws., sst.Secret, Pulumi/Ion, "sst deploy", a failed SST deploy (ConflictException on a…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/authoring.md`, `references/deploy-and-troubleshoot.md` and `references/testing.md`).
It sits in DevOps & Cloud, covering Infrastructure as code. It works with Amazon Web Services, Pulumi, AWS CloudFormation and Terraform. The repository describes itself as: Claude Code plugins and agent skills for AWS development — IaC(CDK/SST), serverless, cost ops, and Bedrock AgentCore. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 68530c6. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
mcp__awsdocs__*mcp__aws-mcp__*ReadWriteEditGlobGrepBash(npx sst *)Bash(npm *)Bash(pnpm *)…and 6 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxpulumitscawsFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx and aws, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AWS Sst Development loads about 2.7k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 258 tokens; SKILL.md has 1,220 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
v` runs fine). The fix is `$interpolate`⟨U+200B⟩`` `${bucket.arn}/*` ``. ThisAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zxkane/aws-skills at commit 68530c6, republished under its MIT licence (© zxkane). 1,220 words, ~2,674 tokens.
.claude/skills/aws-sst-development/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.SST v4 (the "Ion" engine) is a Pulumi-backed IaC framework: you describe AWS
resources in TypeScript and SST/Pulumi reconciles them into your account. It
gives you high-level sst.aws.* components (Function, Bucket, Dynamo, Cron,
Service, …) that expand into many underlying resources, plus an escape hatch to
any raw Pulumi aws.* resource for the long tail. This skill encodes a
production-proven way to author, link, test, deploy, and troubleshoot SST
stacks on AWS — distilled from real multi-stack projects that have paid for
each lesson with a prod incident.
SST and Pulumi are third-party — verify current syntax with Context7
(resolve-library-id → query-docs for sst or pulumi-aws) when you're
unsure about a component's options. Verify AWS-side facts (service limits,
model IDs, IAM action names, region availability) with the AWS docs MCP, never
from memory. The patterns here are the how; the docs are the what.
Figure out which mode you're in and jump to the right reference:
| Situation | Go to |
|---|---|
| New project, or adding a resource/module to an existing SST app | Author → references/authoring.md |
| Wiring one module's output into another (links, SSM, IAM scope) | Author → references/authoring.md § Sharing |
| Writing tests for infra so changes don't silently break | Test → references/testing.md |
| Running a deploy, or a deploy just failed | Deploy/Operate → references/deploy-and-troubleshoot.md |
| Migrating a resource between Pulumi types, renaming a physical name | Deploy/Operate → references/deploy-and-troubleshoot.md § Migrations |
Always read the relevant reference before editing — they carry the why behind each rule, which matters more than the rule itself.
SST projects are conventional but not identical. Before editing, build a quick map so your change matches the house style instead of fighting it:
sst.config.ts — the app name, home, providers/region, defaultTags,
any global $transform (Node runtime pin, bundle fixups), and the order in
which run() imports infra/ modules. The import order is the dependency
order; respect it.infra/ — one file per domain (storage, functions, api, observability…).
This is where resources are declared. Check for an infra/CLAUDE.md — these
projects keep IaC-specific rules there, and it's the single most valuable
file to read first.infra/tests/ — source-level Vitest assertions that pin resource
invariants. If they exist, your change must keep them green and probably
needs a new assertion.package.json / .nvmrc — package manager (npm vs pnpm), Node version,
and the sst/pulumi versions actually installed.Run npx sst version to confirm you're on v4/Ion (the $config + .sst/platform/
signature). v2/v3 ("SST Classic", CDK-based) is a different framework — these
patterns don't apply there.
The projects this skill is built from share a deliberate house style. Some of it is universal (true for any SST v4 + AWS project — apply it everywhere); some is project-specific (a sensible default these projects chose — adopt it for consistency, but recognize a project may differ).
Universal — these principles hold for any SST v4 + AWS project:
$transform(sst.aws.Function, (args) => { args.runtime ??= "nodejs24.x" }) in
run() — ??= is correct here (the transform runs before the component
applies its own default, so it fills in only when the user didn't set one).
Recent SST already defaults to a current Node runtime, so check the installed
default first (Context7); the transform is then version-independence insurance
so a future SST downgrade can't silently move your fleet. See
references/authoring.md.Output<T> into a plain JS template literal.
Use $interpolate (or pulumi.interpolate). A bare top-level
`${bucket.arn}/*` stringifies the Output to a [Output<T>] placeholder
and produces a broken ARN that only fails at deploy time (it type-checks and
sst dev runs fine). The fix is $interpolate``` ${bucket.arn}/*``. This has caused prod deploy outages. Seereferences/authoring.md` § Outputs.ConflictException. Two sequential deploys (teardown, then
recreate) is the conservative default; aliases: / pulumi import / state
surgery can bridge identity in some cases but only with a reviewed plan. See
references/deploy-and-troubleshoot.md § Migrations.sst.aws.* / aws.* resources over the
aws.cloudcontrol.Resource escape hatch. CloudControl outputs are
stringly-typed and oneOf fields don't patch cleanly. Use it only when no
typed resource exists yet, and migrate off it when one ships.Project-specific defaults — adopt for consistency, but confirm per repo:
ap-northeast-1, home: "aws", and defaultTags carrying
Project / Stage / ManagedBy: "sst".removal: stage === "prod" ? "retain" : "remove"
and protect: stage === "prod" so prod resources survive a stack tear-down
and non-prod previews clean up./{app}/{stage}/{domain}/... prefix — for consumers that aren't in the
Pulumi graph (CI scripts, sibling apps, operators). For same-app Lambdas,
prefer SST link: (it wires a real dependency edge and grants IAM); don't
route same-app sharing through SSM. See references/authoring.md § Sharing.await import("./infra/<module>") inside run() so sst dev
hot-reload stays light. (For testing, a module export still runs its top-level
new sst.aws.* unless it's wrapped in a factory function — see
references/testing.md for how to test infra.)@pulumi/pulumi/runtime) for behavioral graph
tests when a module has real logic. Source assertions don't replace a
preview-deploy + smoke test. See references/testing.md.references/deploy-and-troubleshoot.md
§ Observability.When you introduce a convention, say which bucket it's in ("this is universal" vs "matching this repo's house style") so the user can override the project-specific ones deliberately.
references/authoring.md. Match the
surrounding file's commenting density and naming — these projects comment the
why heavily, and a terse one-liner in a heavily-annotated file reads as a
regression.references/testing.md) and
run npx vitest (or the repo's test script). Run npx sst diff and/or
tsc --noEmit to catch type and plan errors before deploying.references/deploy-and-troubleshoot.md. Confirm the
target account with aws sts get-caller-identity before any sst deploy./tmp or chat history.infra/ module, wired into run() in dependency order.runtime unless intentionally diverging — e.g. a Python function).link: (in-graph) and/or $interpolate-scoped
IAM; outputs other tools consume are published to SSM under the stage prefix.sst remove, a resource-type migration) was
flagged to the user with the account it targets, and migrations were planned
as two PRs, not one.© zxkane, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. 1 hidden character (zero-width or bidirectional) removed. Raw file
SKILL.md and 3 other files (references) in plugins/aws-iac/skills/aws-sst-development of zxkane/aws-skills.
Open the folder on GitHubat commit 68530c6
AWS Sst Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AWS Sst Development this skillzxkane/aws-skills | 367 | — | ~2.7k | Automated safety check: Warn | MIT | |
| Generating Infrastructure As Codejeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Infrastructure As Codeseb1n/awesome-ai-agent-skills | 206 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| AWS Cloud Advisortech-leads-club/agent-skills | 7k | — | ~2.1k | Automated safety check: Pass | CC-BY-4.0 | |
| Infra Syncagentic-community/mcp-gateway-registry | 967 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 |
jeremylongshore/tons-of-skills-marketplace
Execute use when generating infrastructure as code configurations.
seb1n/awesome-ai-agent-skills
Define, deploy, and manage cloud infrastructure as code using tools like Terraform, Pulumi, CloudFormation, and CDK, ensuring consistency, repeatability, and version control.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
tech-leads-club/agent-skills
Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.
agentic-community/mcp-gateway-registry
Keep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry.
aws-samples/appmod-blueprints
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
zxkane/aws-skills
AWS serverless and event-driven architecture expert based on Well-Architected Framework.
zxkane/aws-skills
AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale.
zxkane/aws-skills
AWS cost optimization, monitoring, and operational excellence expert.
zxkane/aws-skills
Configure AWS MCP servers for documentation search and API access.
Categories
SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework. AWS Sst Development is an agent skill from zxkane/aws-skills. SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.
AWS Sst Development fits situations like: editing sst.config.ts; building infra/ modules (sst.aws.Function/Bucket/Dynamo/Cron/Service/Router; A failed SST deploy (ConflictException on a resource-type change; identifier filename has already been declared.
Run `npx skills add zxkane/aws-skills --skill aws-sst-development -a claude-code`. Or copy the skill folder (plugins/aws-iac/skills/aws-sst-development in zxkane/aws-skills) into .claude/skills/aws-sst-development in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zxkane/aws-skills --skill aws-sst-development -a codex`. Or copy the skill folder (plugins/aws-iac/skills/aws-sst-development in zxkane/aws-skills) into .agents/skills/aws-sst-development in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zxkane/aws-skills --skill aws-sst-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-sst-development, .gemini/skills/aws-sst-development, .github/skills/aws-sst-development and .opencode/skills/aws-sst-development in your project.
Going by SKILL.md and its folder, AWS Sst Development needs the command-line tools its instructions call (npx, pulumi, tsc and aws). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: mcp__awsdocs__*, mcp__aws-mcp__*, Read, Write, Edit, Glob, Grep, Bash(npx sst *), Bash(npm *), Bash(pnpm *), Bash(npx vitest *), Bash(aws sts get-caller-identity), Bash(aws ssm get-parameter*), Bash(aws ssm get-parameters-by-path*), Bash(aws lambda get-function*), Bash(aws lambda list-versions-by-function*).
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): contains zero-width characters. Read the flagged lines before installing; the check is not a guarantee either way.
AWS Sst Development is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AWS Sst Development: Generating Infrastructure As Code (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Infrastructure As Code (seb1n/awesome-ai-agent-skills, 206 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars) and AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zxkane (a GitHub user) maintains it in zxkane/aws-skills, which has 367 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on June 15, 2026.
Source: zxkane/aws-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.