AWS Infra
Chat-based AWS infrastructure assistance using AWS CLI and console context. Use for querying, auditing, and monitoring AWS resources (EC2, S3, IAM, Lambda, ECS/EKS, RDS, CloudWatch…
bmdhodl
@bmdhodl
What This Skill Does
Chat-based AWS infrastructure assistant that uses the AWS CLI to query, audit, and monitor resources like EC2, S3, IAM, Lambda, ECS/EKS, RDS, CloudWatch, and billing. It defaults to read-only operations and requires explicit user confirmation before executing any write or destructive actions.
Replaces manually running AWS CLI commands or navigating the AWS console for common infrastructure queries and audits.
When to Use It
- List all EC2 instances in a specific region and their states
- Check S3 bucket public access settings and encryption status
- Audit IAM users and their attached policies for security review
- Retrieve CloudWatch metrics or logs to diagnose a service error
- Query AWS Cost Explorer for spending by service over the last month
- Propose a safe change to an RDS instance (e.g., modify instance class) and confirm before executing
Install
$ openclaw skills install @bmdhodl/aws-infraAWS Infra
Overview
Use the local AWS CLI to answer questions about AWS resources. Default to read‑only queries. Only propose or run write/destructive actions after explicit user confirmation.
Quick Start
- Determine profile/region from environment or
~/.aws/config. - Start with identity:
aws sts get-caller-identity
- Use read‑only service commands to answer the question.
- If the user asks for changes, outline the exact command and ask for confirmation before running.
Safety Rules (must follow)
- Treat all actions as read‑only unless the user explicitly requests a change and confirms it.
- For any potentially destructive change (delete/terminate/destroy/modify/scale/billing/IAM credentials), require a confirmation step.
- Prefer
--dry-runwhen available and show the plan before execution. - Never reveal or log secrets (access keys, session tokens).
Task Guide (common requests)
- Inventory / list: use
list/describe/getcommands. - Health / errors: use CloudWatch metrics/logs queries.
- Security checks: IAM, S3 public access, SG exposure, KMS key usage.
- Costs: Cost Explorer / billing queries (read‑only).
- Changes: show exact CLI command and require confirmation.
Region & Profile Handling
- If the user specifies a region/profile, honor it.
- Otherwise use
AWS_PROFILE/AWS_REGIONif set, then fall back to~/.aws/config. - When results are region‑scoped, state the region used.
References
See references/aws-cli-queries.md for common command patterns.
Assets
assets/icon.svg— custom icon (dark cloud + terminal prompt)
Top skills in this category
API Gateway
@byungkyuCall third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, run a query through a connected
Marketing Mode
@thesethroseMarketing Mode combines 23 comprehensive marketing skills covering strategy, psychology, content, SEO, conversion optimization, and paid growth. Use when users need marketing strategy, copywriting, SEO help, conversion optimization, paid advertising, or any marketing tactic.
Blogwatcher
@steipeteMonitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.
Marketing Skills
@jchopard69Access 23 marketing modules offering checklists, frameworks, and ready-to-use deliverables for CRO, SEO, copywriting, analytics, launches, ads, and social me...
diagram-generator
@matthewyinGenerate and edit diagrams with the mcp-diagram-generator MCP server. Use this skill for new diagrams, existing .drawio/.mmd/.excalidraw edits, network topology, architecture, flowchart, swimlane, sequence, class, ER, and Excalidraw whiteboard work. Always use this skill when the user asks to draw,