plugins/aws-agentic-ai/skills/aws-agentic-ai/SKILL.md
AWS Bedrock AgentCore comprehensive expert for deploying and managing AI agents at scale. Use when working with any AgentCore service including Gateway, Runtime, Memory, Identity, Code Interpreter, Browser, Observability, Agent Registry, or Evaluations. Covers agent deployment, MCP tool integration, credential management, agent discovery, governance workflows, and automated quality assessment. Essential when user mentions AgentCore, agent runtime, agent registry, agent evaluation, MCP gateway, deploy agent, register MCP server, discover agents, evaluate agent quality, agent credentials, or wants to build, deploy, catalog, or monitor AI agents on AWS.
npx skillsauth add zxkane/aws-skills aws-agentic-aiInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
This skill has been flagged as suspicious. Review the scan results before using.
2 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
AWS Bedrock AgentCore provides a complete platform for deploying and scaling AI agents with nine core services. This skill covers service selection, deployment patterns, and integration workflows using AWS CLI.
How to use this skill: Identify the service(s) the user needs from the table below, then read the corresponding service README before responding. For cross-service patterns (credentials, security, registry integration), check the Cross-Service Resources section. Verify AWS-specific details using the MCP documentation tools.
Always verify AWS facts using MCP tools before answering. Two documentation sources are available:
mcp__acdocs__*) — bundled with this plugin, provides search_agentcore_docs and fetch_agentcore_doc for AgentCore documentationmcp__aws-mcp__* or mcp__*awsdocs*__*) — loaded via the aws-mcp-setup dependency for broader AWS documentationPrefer the AgentCore docs MCP for AgentCore-specific questions. If MCP tools are unavailable, guide the user through the aws-mcp-setup skill's setup flow.
| Service | Use For | Documentation |
|---------|---------|---------------|
| Gateway | Converting REST APIs to MCP tools | services/gateway/README.md |
| Runtime | Deploying and scaling agents | services/runtime/README.md |
| Memory | Managing conversation state | services/memory/README.md |
| Identity | Credential and access management | services/identity/README.md |
| Code Interpreter | Secure code execution in sandboxes | services/code-interpreter/README.md |
| Browser | Web automation and scraping | services/browser/README.md |
| Observability | Tracing and monitoring | services/observability/README.md |
| Agent Registry | Catalog, discover, and govern agents/tools (Preview) | services/registry/README.md |
| Evaluations | Automated agent quality assessment (LLM-as-a-Judge) | services/evaluations/README.md |
Read services/gateway/README.md before implementing — Gateway setup involves deployment strategies, IAM, and auth choices that vary significantly by use case.
Credential provider is only needed for API key authentication. Lambda targets use IAM roles, and MCP servers use OAuth.
Read cross-service/credential-management.md first — credential patterns differ across services and getting them wrong causes hard-to-debug auth failures.
Read services/registry/README.md first — the registry has governance workflows, MCP endpoint options, and sync modes that affect how records become discoverable.
Agent Registry is in Preview. Available in us-east-1, us-west-2, eu-west-1, ap-northeast-1, ap-southeast-2.
Read services/evaluations/README.md first — evaluators, scoring modes, and IAM setup vary between online monitoring and on-demand testing.
Builtin.Helpfulness or create custom)Read services/observability/README.md for the full monitoring setup — observability configuration depends on your Runtime protocol and framework choice.
Each service README (linked in the table above) contains sub-links to getting-started guides, troubleshooting, and advanced topics. Start with the service README and follow pointers from there.
Deep-dive reference documentation for Runtime internals, deployment, OAuth integration, and communication protocols. Read these when building production Runtime deployments or configuring OAuth authentication:
references/agentcore-oauth-integration.md - Three-layer OAuth architecture (Inbound JWT, Outbound Credential Provider, Gateway OAuth), Cognito configuration, supported IdPs, end-to-end CDK examplesreferences/agentcore-runtime-core.md - Container contract, MicroVM Session model, Agent lifecycle (per-request vs per-session), tool integration (MCP/HTTP), startup flowreferences/agentcore-runtime-deploy.md - CDK deployment (L1/L2 constructs), multi-Runtime architecture, security model, observability (OTel/CloudWatch), BedrockAgentCoreApp vs FastAPI comparisonreferences/agentcore-runtime-protocols.md - HTTP, MCP, A2A, AG-UI protocol specifications with container contracts, endpoint specs, and selection guideProduction-ready templates in scripts/ for common deployment patterns:
| Script | Protocol | Description |
|--------|----------|-------------|
| Dockerfile.runtime-template | — | ARM64 multi-stage Docker build for AgentCore Runtime |
| runtime-fastapi-template.py | HTTP | FastAPI Runtime with SSE streaming and MCPClient |
| mcp-server-template.py | MCP | MCP Server with Streamable HTTP transport |
| a2a-server-template.py | A2A | A2A Server with Agent Card discovery |
| agui-server-template.py | AG-UI | AG-UI Server with standard AG-UI event stream |
| gateway-custom-resource-lambda.py | — | CDK Custom Resource Lambda for Gateway lifecycle |
For patterns and best practices that span multiple AgentCore services:
cross-service/credential-management.md - Unified credential patterns, security practices, rotation procedurescross-service/registry-integration.md - Cross-service patterns with Gateway, Identity, Runtimecross-service/security-resource-policies.md - Resource-based policies, cross-account access, VPC/IP restrictionscross-service/agent-persistence-patterns.md - Deploy Strands Agents, OpenClaw, Claude Agent SDK on AgentCore with S3 Files and Session Storagedevelopment
AWS serverless and event-driven architecture expert based on Well-Architected Framework. Use when building serverless APIs, Lambda functions, REST APIs, microservices, or async workflows. Covers Lambda with TypeScript/Python, API Gateway (REST/HTTP), DynamoDB, Step Functions, EventBridge, SQS, SNS, and serverless patterns. Essential when user mentions serverless, Lambda, API Gateway, event-driven, async processing, queues, pub/sub, or wants to build scalable serverless applications with AWS best practices.
testing
AWS cost optimization, monitoring, and operational excellence expert. Use when analyzing AWS bills, estimating costs, setting up CloudWatch alarms, querying logs, auditing CloudTrail activity, or assessing security posture. Essential when user mentions AWS costs, spending, billing, budget, pricing, CloudWatch, observability, monitoring, alerting, CloudTrail, audit, or wants to optimize AWS infrastructure costs and operational efficiency.
tools
Configure AWS MCP servers for documentation search and API access. Use when setting up AWS MCP, configuring AWS documentation tools, troubleshooting MCP connectivity, or when user mentions aws-mcp, awsdocs, uvx setup, or MCP server configuration. Covers both Full AWS MCP Server (with uvx + credentials) and lightweight Documentation MCP (no auth required).
development
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python. Use when creating CDK stacks, defining CDK constructs, implementing infrastructure as code, or when the user mentions CDK, CloudFormation, IaC, cdk synth, cdk deploy, or wants to define AWS infrastructure programmatically. Covers CDK app structure, construct patterns, stack composition, and deployment workflows.