AWS Agent Toolkit Main Components: Core Skills, Plugins, Rules, and Tools
The AWS agent toolkit comprises five modular components—core skills, specialized skills, plugins, rules, and validation tools—that enable autonomous agents to securely discover, compose, and execute AWS-specific actions.
The AWS agent toolkit (repository: aws/agent-toolkit-for-aws) provides a modular, skill-based architecture for building AWS automation agents. This open-source framework organizes functionality into discrete, reusable units that agent runtimes can dynamically load and execute according to declarative security policies.
Core Components of the AWS Agent Toolkit
The AWS agent toolkit implements a "skill-based" architecture where functionality is encapsulated in modular units. According to the source code, the toolkit consists of five primary component categories.
Core Skills
Core skills provide the fundamental building blocks that every agent requires for basic AWS operations. These skills handle authentication, session management, and foundational serverless patterns.
In skills/core-skills/signing-in-to-aws/SKILL.md, the toolkit defines the authentication interface that agents use to establish AWS sessions. These core capabilities ensure agents can securely sign in before executing any service-specific operations.
Specialized Skills
Specialized skills expose fine-grained, service-specific commands for individual AWS services. These skills extend agent capabilities into domains such as storage, analytics, networking, and web development.
For example, the storage skill located at skills/specialized-skills/storage-skills/storing-and-querying-vectors/SKILL.md provides S3 operations, while skills/specialized-skills/web-and-mobile-development/aws-amplify/SKILL.md defines Amplify deployment capabilities. Each specialized skill wraps AWS SDK calls into agent-friendly interfaces.
Plugins
Plugins bundle related core and specialized skills into loadable packages that the agent runtime can consume. Each plugin represents a first-class deployment unit that groups functionality by domain.
The repository includes several plugin packages:
aws-core- Foundational skills for basic AWS operationsaws-data-analytics- Specialized skills for data processing servicesaws-agents- General agent capabilitiesaws-agents-for-devsecops- Security and compliance automation
As implemented in plugins/aws-core/skills/aws-serverless/SKILL.md, plugins wrap skill definitions and expose them to the runtime through a standardized interface.
Rules
Rules are declarative policy files that govern agent permissions and ensure safe interaction with AWS resources. Located at rules/aws-agent-rules.md, these configuration files define what actions agents are authorized to perform, implementing a governance layer that restricts potentially dangerous operations.
The rules system evaluates execution requests against security policies before allowing skill invocation, preventing unauthorized access to sensitive resources.
Tools
Tools are utility scripts that maintain repository integrity and skill consistency. The tools/validate.py script runs during CI pipelines to validate skill metadata, check file references, and ensure rule syntax compliance.
These validation tools ensure that skill definitions remain syntactically correct and that all references to AWS resources and documentation resolve properly before deployment.
How the AWS Agent Toolkit Components Work Together
The AWS agent toolkit orchestrates components through a standardized execution flow:
-
Plugin Loading - The agent runtime loads one or more plugins (e.g.,
aws-core,aws-agents-for-devsecops) during initialization. -
Skill Registration - Each plugin registers its core and specialized skills with the runtime, making them available for invocation.
-
Request Routing - When a user requests a task, the runtime selects the appropriate skill based on the intent (e.g., S3 upload, Amplify deployment).
-
Policy Enforcement - Before execution, the runtime checks
rules/aws-agent-rules.mdto verify the action is permitted under current security policies. -
Execution - The skill executes, typically wrapping AWS SDK calls to perform the requested operation.
-
Validation - During development,
tools/validate.pyensures skill metadata and references remain consistent.
Practical Code Examples for the AWS Agent Toolkit
The AWS agent toolkit exposes skills through a CLI-style interface. While the actual agent runtime operates outside this repository, the following examples demonstrate the command syntax for invoking specific skills.
Authenticating with AWS (Core Skill)
Invoke the core authentication skill defined in skills/core-skills/signing-in-to-aws/SKILL.md:
aws-agent-toolkit sign-in \
--profile my-aws-profile \
--region us-east-1
Uploading Files to S3 (Specialized Storage Skill)
Execute the storage skill implemented in skills/specialized-skills/storage-skills/storing-and-querying-vectors/SKILL.md:
aws-agent-toolkit s3 upload \
--bucket my-bucket \
--key path/to/object.txt \
--source ./local-file.txt
Deploying Amplify Applications (Specialized Web Skill)
Deploy using the Amplify skill from skills/specialized-skills/web-and-mobile-development/aws-amplify/SKILL.md:
aws-agent-toolkit amplify deploy \
--app-id d1abcd2efgh3 \
--branch main \
--framework react
Running Security Compliance Checks (DevSecOps Plugin)
Execute the security skill from plugins/aws-agents-for-devsecops/skills/setup-security-agent/SKILL.md:
aws-agent-toolkit security check \
--target my-ec2-instance \
--profile devsecops-profile
Key Files and Directory Structure
Understanding the AWS agent toolkit requires familiarity with its repository layout:
skills/core-skills/- Contains fundamental capabilities like authentication and basic serverless operationsskills/specialized-skills/- Houses service-specific implementations for Amplify, RDS, S3, Analytics, and Networkingplugins/- Contains loadable plugin packages includingaws-core,aws-data-analytics, andaws-agents-for-devsecopsrules/aws-agent-rules.md- Central policy definition file for agent permissionstools/validate.py- CI validation script for skill metadata and syntax checkingREADME.md- High-level overview and quick-start documentation
Summary
The AWS agent toolkit provides a flexible, extensible foundation for building AWS automation agents through these key components:
- Core skills deliver essential authentication and session management capabilities required by all agents
- Specialized skills expose service-specific commands for individual AWS services like S3, Amplify, and RDS
- Plugins bundle related skills into loadable units such as
aws-coreandaws-agents-for-devsecops - Rules enforce security policies through declarative configuration files that restrict agent actions
- Tools maintain code quality through validation scripts like
tools/validate.pythat check skill metadata and references
This modular architecture enables developers to compose agents capable of automating virtually any AWS service while maintaining strict governance through rule-based security controls.
Frequently Asked Questions
What is the difference between core skills and specialized skills in the AWS agent toolkit?
Core skills provide fundamental capabilities required by all agents, such as authentication and basic serverless operations, as defined in skills/core-skills/signing-in-to-aws/SKILL.md. Specialized skills extend functionality into specific AWS service domains like S3, Amplify, or RDS, allowing agents to perform targeted operations like file uploads or application deployments. While core skills handle universal prerequisites, specialized skills implement domain-specific business logic.
How do plugins work in the AWS agent toolkit architecture?
Plugins package related skills into deployable units that the agent runtime loads dynamically. According to the source code in plugins/aws-core/skills/aws-serverless/SKILL.md, plugins expose both core and specialized skills through standardized interfaces, allowing the runtime to discover and invoke capabilities without hardcoding service dependencies. This plugin system enables modular deployment where you can load only the AWS service capabilities your agent requires.
What is the purpose of the rules component in the AWS agent toolkit?
The rules component, located at rules/aws-agent-rules.md, implements declarative security policies that restrict what actions agents can perform on AWS resources. Before executing any skill, the agent runtime checks these rules to ensure the requested operation is permitted, preventing unauthorized access or accidental infrastructure modifications. This governance layer ensures that even autonomous agents operate within defined security boundaries.
How does the validation tool ensure skill consistency in the AWS agent toolkit?
The tools/validate.py script executes during CI pipelines to verify that skill definitions contain valid metadata, proper file references, and correct syntax. This validation tool checks that all skills referenced in plugins actually exist and that their documentation links resolve correctly, preventing broken dependencies in production. By automating these checks, the toolkit maintains high code quality across hundreds of service-specific skill definitions.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →