Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/lyhcode/agent-skills/awsclinpx skills add lyhcode/agent-skills --skill awscligit clone --depth 1 https://github.com/lyhcode/agent-skillsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00088 | $0.02067 |
| Opus 5 | $0.00044 | $0.01033 |
| Sonnet 5 | $0.00018 | $0.00413 |
| Haiku 4.5 | $0.00009 | $0.00207 |
Grade C, and why
awscli scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reaches for credential fileshighPrivilege escalation
SSH keys, cloud credentials, git-credentials, .npmrc, /etc/shadow: reading these is how a config file becomes a credential leak.
- `~/.aws/credentials` — access keys (profile names without `profile` prefix) How it starts
The opening of the file, as written. The whole thing — 262 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AWS CLI Assistant
Help users manage AWS services using the aws CLI (v2).
Prerequisites
- AWS CLI v2 installed (
brew install awsclion macOS, or see reference/commands.md) - Credentials configured via
aws configure, environment variables, SSO, or IAM role - Verify setup:
aws sts get-caller-identity
Command Structure
aws <service> <command> [subcommand] [options]
Configuration
Files
~/.aws/credentials— access keys (profile names withoutprofileprefix)~/.aws/config— region, output, SSO settings (named profiles use[profile name])
# ~/.aws/credentials
[default]
aws_access_key_id=AKIAIOSFODNN7EXAMPLE
aws_secret_access_key=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
# ~/.aws/config
[default]
region=us-west-2
output=json
[profile staging]
region=us-east-1
output=table
Key Environment Variables
| Variable | Purpose |
|---|---|
AWS_ACCESS_KEY_ID |
Access key |
AWS_SECRET_ACCESS_KEY |
Secret key |
AWS_SESSION_TOKEN |
Temporary session token |
AWS_DEFAULT_REGION / AWS_REGION |
Default region |
AWS_PROFILE |
Named profile to use |
AWS_PAGER |
Pager program (set "" to disable) |
Profiles
aws s3 ls --profile staging # Use specific profile
export AWS_PROFILE=staging # Set for session
aws configure list-profiles # List all profiles
aws configure list # Show active config with sources
Credential Precedence
- CLI options → 2. Environment variables → 3. SSO → 4.
~/.aws/credentials→ 5.~/.aws/config→ 6. Container/EC2 instance role
SSO (Recommended for Human Users)
[profile dev]
sso_session = my-sso
sso_account_id = 111122223333
sso_role_name = SampleRole
region = us-west-2
[sso-session my-sso]
sso_region = us-east-1
sso_start_url = https://my-sso-portal.awsapps.com/start
sso_registration_scopes = sso:account:access
aws sso login --profile dev
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 262 lines · 88 tokens per session scan C c4ab007f3da1
awscli is a skill published in the GitHub repository lyhcode/agent-skills (2 stars, last pushed 4mo ago), licensed MIT. It adds 88 tokens to every session and 2,067 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it C with 1 finding (reaches for credential files). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…