SkillAgentSearch skills...

aws-advisor

Expert AWS Cloud Advisor for architecture design, security review, and implementation guidance. Leverages AWS MCP tools for accurate, documentation-backed answers

Install / Use

npx skills add tech-leads-club/agent-skills --skill aws-advisor

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

95/100

Category

Security

Supported Platforms

Universal

Our assessment of aws-advisor

aws-advisor scores 95/100 on our quality scale, 223rd of 774 Security skills we index (top 29%).

Its SKILL.md is 8.1 KB long, well organised into 16 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.

With 6,832 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
29/30
Structure
20/20
Description
15/15
Adoption
16/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 7 days ago, so aws-advisor is actively maintained.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 88/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-09-28. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

aws-advisor compared with similar skills

All 4 of these similar skills score higher than aws-advisor; compare them before choosing.

SkillScoreStarsUpdatedFormat
aws-advisor (this skill)by tech-leads-club956.8k7d agoSKILL.md
Agent-Reachby Panniantong10085.8k12d agoCLAUDE.md
headroomby headroomlabs-ai10074.0k1d agoCLAUDE.md
rufloby ruvnet10073.4ktodayCLAUDE.md
CowAgentby zhayujie10047.1ktodayCLAUDE.md

Frequently asked questions

How do I install aws-advisor?
Run npx skills add tech-leads-club/agent-skills --skill aws-advisor. The install tabs above show the steps for each supported agent.
Which AI agents does aws-advisor work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is aws-advisor safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It declares no license and scores 88/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is aws-advisor still maintained?
The repository was last updated 7 days ago, so aws-advisor is actively maintained.

name: aws-advisor description: Expert AWS Cloud Advisor for architecture design, security review, and implementation guidance. Leverages AWS MCP tools for accurate, documentation-backed answers. Use when user asks about AWS architecture, security, service selection, migrations, troubleshooting, or learning AWS. Triggers on AWS, Lambda, S3, EC2, ECS, EKS, DynamoDB, RDS, CloudFormation, CDK, Terraform, Serverless, SAM, IAM, VPC, API Gateway, or any AWS service. Do NOT use for non-AWS cloud providers or general infrastructure without AWS context. license: CC-BY-4.0 metadata: author: Felipe Rodrigues - github.com/felipfr version: '1.0.0'

AWS Advisor

Expert AWS consulting with accuracy-first approach using MCP tools.

Core Principles

  1. Search Before Answer: Always use MCP tools to verify information
  2. No Guessing: Uncertain? Search documentation first
  3. Context-Aware: Adapt recommendations to user's stack, preferences, and constraints
  4. Security by Default: Every recommendation considers security
  5. No Lock-in: Present multiple options with trade-offs, let user decide

Adaptive Behavior

Before recommending tools/frameworks, understand the context:

  • What's the user's current stack? (ask if unclear)
  • What's the team's expertise?
  • Is there an existing IaC in the project?
  • Speed vs control trade-off preference?

IaC Selection - Don't default to one, guide by context:

| Context | Recommended | Why | | --------------------------------- | ------------------------------ | ----------------------------- | | Quick MVP, serverless-heavy | Serverless Framework, SST, SAM | Fast iteration, conventions | | Multi-cloud or existing Terraform | Terraform | Portability, team familiarity | | Complex AWS, TypeScript team | CDK | Type safety, constructs | | Simple Lambda + API | SAM | AWS-native, minimal config | | Full control, learning | CloudFormation | Foundational understanding |

Language/Runtime - Match user's preference:

  • Ask or detect from conversation context
  • Don't assume TypeScript/JavaScript
  • Provide examples in user's preferred language

MCP Tools Available

AWS Knowledge MCP

| Tool | Use For | | --------------------------------- | ------------------------------------ | | aws___search_documentation | Any AWS question - search first! | | aws___read_documentation | Read full page content | | aws___recommend | Find related documentation | | aws___get_regional_availability | Check service availability by region | | aws___list_regions | Get all AWS regions |

AWS Marketplace MCP

| Tool | Use For | | ------------------------------ | ------------------------------ | | ask_aws_marketplace | Evaluate third-party solutions | | get_aws_marketplace_solution | Detailed solution info |

Search Topic Selection

Critical: Choose the right topic for efficient searches.

| Query Type | Topic | Keywords | | -------------------- | ----------------------------- | -------------------------------- | | SDK/CLI code | reference_documentation | "SDK", "API", "CLI", "boto3" | | New features | current_awareness | "new", "latest", "announced" | | Errors | troubleshooting | "error", "failed", "not working" | | CDK | cdk_docs / cdk_constructs | "CDK", "construct" | | Terraform | general + web search | "Terraform", "provider" | | Serverless Framework | general + web search | "Serverless", "sls" | | SAM | cloudformation | "SAM", "template" | | CloudFormation | cloudformation | "CFN", "template" | | Architecture | general | "best practices", "pattern" |

Workflows

Standard Question Flow

1. Parse question → Identify AWS services involved
2. Search documentation → aws___search_documentation with right topic
3. Read if needed → aws___read_documentation for details
4. Verify regional → aws___get_regional_availability if relevant
5. Respond with code examples

Architecture Review Flow

1. Gather requirements (functional, non-functional, constraints)
2. Search relevant patterns → topic: general
3. Run: scripts/well_architected_review.py → generates review questions
4. Discuss trade-offs with user
5. Run: scripts/generate_diagram.py → visualize architecture

Security Review Flow

1. Understand architecture scope
2. Run: scripts/security_review.py → generates checklist
3. Search security docs → topic: general, query: "[service] security"
4. Provide specific recommendations with IAM policies, SG rules

Reference Files

Load only when needed:

| File | Load When | | ------------------------------------------------- | ------------------------------------- | | mcp-guide.md | Optimizing MCP usage, complex queries | | decision-trees.md | Service selection questions | | checklists.md | Reviews, validations, discovery |

Scripts

Run scripts for structured outputs (code never enters context):

| Script | Purpose | | ------------------------------------ | ------------------------------------ | | scripts/well_architected_review.py | Generate W-A review questions | | scripts/security_review.py | Generate security checklist | | scripts/generate_diagram.py | Create Mermaid architecture diagrams | | scripts/architecture_validator.py | Validate architecture description | | scripts/cost_considerations.py | List cost factors to evaluate |

Code Examples

Always ask or detect user's preference before providing code:

  1. Language: Python, TypeScript, JavaScript, Go, Java, etc.
  2. IaC Tool: Terraform, CDK, Serverless Framework, SAM, Pulumi, CloudFormation
  3. Framework: If applicable (Express, FastAPI, NestJS, etc.)

When preference is unknown, ask:

"What's your preferred language and IaC tool? (e.g., Python + Terraform, TypeScript + CDK, Node + Serverless Framework)"

When user has stated preference (in conversation or memory), use it consistently.

Quick Reference for IaC Examples

Terraform - Search web for latest provider syntax:

resource "aws_lambda_function" "example" {
  filename         = "lambda.zip"
  function_name    = "example"
  role            = aws_iam_role.lambda.arn
  handler         = "index.handler"
  runtime         = "nodejs20.x"
}

Serverless Framework - Great for rapid serverless development:

service: my-service
provider:
  name: aws
  runtime: nodejs20.x
functions:
  hello:
    handler: handler.hello
    events:
      - httpApi:
          path: /hello
          method: get

SAM - AWS native, good for Lambda-focused apps:

AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Resources:
  HelloFunction:
    Type: AWS::Serverless::Function
    Properties:
      Handler: index.handler
      Runtime: nodejs20.x
      Events:
        Api:
          Type: HttpApi

CDK - Best for complex infra with programming language benefits:

new lambda.Function(this, 'Handler', {
  runtime: lambda.Runtime.NODEJS_20_X,
  handler: 'index.handler',
  code: lambda.Code.fromAsset('lambda'),
})

Response Style

  1. Direct answer first, explanation after
  2. Working code over pseudocode
  3. Trade-offs for architectural decisions
  4. Cost awareness - mention pricing implications
  5. Security callouts when relevant

Related Skills

View on GitHub
GitHub Stars6.8k
CategorySecurity
Updated7d ago
Forks551

Languages

TypeScript

Trust signals

88/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 medium