Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add G1Joshi/Agent-Skills --skill awscligit clone --depth 1 https://github.com/G1Joshi/Agent-SkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/g1joshi/agent-skills/awscli)<a href="https://agentmods.dev/skills/g1joshi/agent-skills/awscli"><img src="https://agentmods.dev/badge/skills/g1joshi/agent-skills/awscli/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/g1joshi/agent-skills/awscli"><img src="https://agentmods.dev/badge/skills/g1joshi/agent-skills/awscli.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00014 | $0.00513 |
| Opus 5 | $0.00007 | $0.00257 |
| Sonnet 5 | $0.00003 | $0.00103 |
| Haiku 4.5 | $0.00001 | $0.00051 |
Grade B, and why
awscli scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks for rootmediumPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
sudo installer -pkg AWSCLIV2.pkg -target / Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl "https://awscli.amazonaws.com/AWSCLIV2.pkg" -o "AWSCLIV2.pkg" What it actually says
AWS CLI
The AWS CLI allows you to control AWS services from the command line. In 2025, usage is centered around AWS IAM Identity Center (formerly SSO) for secure, short-lived credentials.
When to Use
- Scripting: Automate S3 uploads (
aws s3 sync). - DevOps: Debugging permissions or inspecting resources without the Console UI.
- CI/CD: Deploying CloudFormation/CDK stacks (though specialized tools are often better).
Quick Start
# Install v2
curl "https://awscli.amazonaws.com/AWSCLIV2.pkg" -o "AWSCLIV2.pkg"
sudo installer -pkg AWSCLIV2.pkg -target /
# Configure with SSO (Recommended 2025)
aws configure sso
# SSO session name: my-session
# SSO start URL: https://my-org.awsapps.com/start
# SSO region: us-east-1
# Registration scopes: sso:account:access
# Login daily
aws sso login --profile my-profile
Core Concepts
Profiles
Managed in ~/.aws/config. Allow switching between Prod, Staging, and Dev accounts easily.
export AWS_PROFILE=prod
Query (--query)
Built-in JMESPath filtering. Use it instead of piping to jq for simple lookups.
aws ec2 describe-instances --query "Reservations[*].Instances[*].PublicIpAddress"
S3 Web Viewer
aws s3 presign s3://my-bucket/file.txt generates a temporary public URL.
Best Practices (2025)
Do:
- Use AWS SSO: Stop using long-lived
aws_access_key_idCSVs. They are the #1 cause of hacks. - Use
aws-vault: If you must use keys, wrap them inaws-vaultto store them in the OS keychain. - Update v2: Ensure you are on v2.x. v1 is deprecated.
Don't:
- Don't parse text output: Always use
--output jsonand a parser (jqor--query). Text output format changes.
References
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 67 lines · 14 tokens per session scan B b40d520593f8
awscli is a skill published in the GitHub repository G1Joshi/Agent-Skills (12 stars, last pushed 7mo ago), licensed MIT. It adds 14 tokens to every session and 513 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 2 findings (asks for root, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
shipping-and-launch
Prepares production launches. Use when preparing to deploy to production, or when asking what needs to be in place before shipping. Use when you need a pre-launch checklist, when setting up monitoring, when planning a staged rollout, or when you need a rollback strategy.
opa-policies
Write OPA/Gatekeeper and Kyverno admission policies for Kubernetes security guardrails.
cost-optimization
Identify and reduce cloud infrastructure costs — right-sizing, reserved capacity, waste detection, tagging for cost attribution.
drift-detection
Detect, classify, and automate Terraform drift detection in CI — scheduled plans, drift metrics, cloud-native audit log correlation.
dns-management
DNS management for Kubernetes — CoreDNS tuning, external-dns automation, split-horizon DNS, and bare-metal DNS design.
tls-termination
Configure TLS termination with cert-manager — Let's Encrypt, internal CA via Vault PKI, wildcard certs, mTLS between services.