aws-infra_skill

This skill helps you query and audit AWS resources using the AWS CLI with read-only defaults and explicit write confirmations.
  • Python

2.6k

GitHub Stars

2

Bundled Files

2 months ago

Catalog Refreshed

4 months ago

First Indexed

Readme & install

Copy the install command, review bundled files from the catalogue, and read any extended description pulled from the listing source.

Installation

Preview and clipboard use veilstrat where the catalogue uses aiagentskills.

npx veilstrat add skill openclaw/skills --skill aws-infra

  • _meta.json271 B
  • SKILL.md1.9 KB

Overview

This skill provides chat-based AWS infrastructure assistance using the local AWS CLI and console context. It defaults to read-only queries for inventory, monitoring, auditing, and cost checks. Any write or destructive action is proposed explicitly with the exact CLI command and requires user confirmation before execution.

How this skill works

The skill inspects AWS resources by running AWS CLI describe/list/get commands and querying CloudWatch and Cost Explorer for metrics and billing data. It detects profile and region from environment variables or ~/.aws/config and reports which context was used. For change requests it generates the precise CLI command, recommends --dry-run when available, and waits for explicit user confirmation before running anything that modifies resources.

When to use it

  • Inventory and discovery of resources across EC2, S3, IAM, Lambda, ECS/EKS, RDS, and more
  • Auditing security posture: IAM permissions, S3 public access, security groups, and KMS usage
  • Troubleshooting and health checks using CloudWatch metrics and logs
  • Billing and cost analysis using Cost Explorer read-only queries
  • Preparing safe infrastructure changes with an exact CLI plan and confirmation

Best practices

  • Treat all interactions as read-only by default; explicitly confirm any write or destructive actions
  • Specify AWS_PROFILE and AWS_REGION when working across multiple accounts or regions
  • Prefer --dry-run where supported and show the planned command before execution
  • Never expose or log secrets such as access keys or session tokens
  • When reporting results, always state the region and profile used for the queries

Example use cases

  • List all EC2 instances in a region and highlight instances with missing tags
  • Check S3 buckets for public access and provide exact aws s3api commands to remediate
  • Fetch CloudWatch metrics and recent logs for a Lambda function to diagnose errors
  • Generate a cost summary for the last 30 days and identify top spenders by service
  • Draft an IAM policy change command and require confirmation before applying it

FAQ

It honors an explicit profile/region you provide, otherwise uses AWS_PROFILE and AWS_REGION, then falls back to ~/.aws/config. The skill states the context used with each result.

Will it ever run destructive commands without asking?

No. All commands that modify, delete, or could affect billing require you to request the change and then explicitly confirm the exact command before it runs.

Built by
VeilStrat
AI signals for GTM teams
© 2026 VeilStrat. All rights reserved.All systems operational
aws-infra skill by openclaw/skills | VeilStrat