Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计通过

aws-profile-managementAWS profile management 搜索

Agent Skill

用于辅助云资源、部署、容器、基础设施和运维自动化任务。它适合让 Agent 检查配置、整理部署步骤、分析资源状态、生成排障思路或辅助云服务接入。使用时需要明确目标环境、账号权限、区域和资源组,区分本地测试与生产操作;涉及删除资源、重启服务、修改网络或权限配置时,应先确认影响范围。

总安装

188

周安装

8

GitHub Stars

7

下载量

66
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:aws-profile-management(AWS profile management 搜索)
来源仓库:https://github.com/lgbarn/devops-skills
仓库路径:skills/aws-profile-management
安装命令:
npx skills add https://github.com/lgbarn/devops-skills --skill aws-profile-management
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/lgbarn/devops-skills --skill aws-profile-management

简介

用于确保在执行 AWS 操作前激活正确的身份凭证与环境配置。

  • 它适合让 Agent 自动校验当前 IAM 用户/角色权限,并与预期环境(dev/staging/prod)进行匹配。
  • 使用时需提供目标账户 ID 与角色命名规范,系统将比对 sts get-caller-identity 返回结果。
  • 安装需通过 npx skills add 命令从 lgbarn/devops-skills 仓库添加 aws-profile-management 技能。
  • 可有效预防因凭证错位导致的误操作事故,建议在关键部署流程中强制启用此技能。

SKILL.md

AWS Profile Management

Overview

Credential mistakes are one of the most common causes of infrastructure accidents. This skill ensures the correct AWS profile is active before any operation.

Announce at start: "I'm using the aws-profile-management skill to verify credentials."

Pre-Operation Verification

Step 1: Check Current Identity

# Get current identity
aws sts get-caller-identity

Expected output includes:

  • Account: AWS account ID
  • Arn: IAM user/role ARN
  • UserId: User or assumed role ID

Step 2: Match to Environment

EnvironmentExpected AccountExpected Role Pattern
dev123456789012*-dev-*, *-developer-*
staging234567890123*-staging-*, *-deploy-*
prod345678901234*-prod-*, *-admin-*

STOP if account doesn't match expected environment.

Step 3: Check Credential Expiry

For assumed roles:

# Check remaining session time
aws sts get-caller-identity 2>&1 | grep -i expir || echo "Credentials valid"

For SSO:

# Check SSO session
aws sso list-accounts 2>&1 || echo "Check SSO login status"

Profile Switching

Using Named Profiles

# List available profiles
aws configure list-profiles

# Set profile for session
export AWS_PROFILE=production

# Or use inline
AWS_PROFILE=production terraform plan

Using AWS SSO

# Login to SSO
aws sso login --profile production

# Verify login
aws sts get-caller-identity --profile production

Using Assume Role

# Assume role and export credentials
eval $(aws sts assume-role \
  --role-arn arn:aws:iam::ACCOUNT:role/ROLE_NAME \
  --role-session-name terraform-session \
  --query 'Credentials.[AccessKeyId,SecretAccessKey,SessionToken]' \
  --output text | \
  awk '{print "export AWS_ACCESS_KEY_ID="$1"\nexport AWS_SECRET_ACCESS_KEY="$2"\nexport AWS_SESSION_TOKEN="$3}')

# Verify
aws sts get-caller-identity

Environment Detection

From Directory Structure

environments/
├── dev/
├── staging/
└── prod/
# Detect environment from path
ENV=$(basename "$(pwd)")
echo "Detected environment: $ENV"

From Terraform Backend

# Check backend configuration
grep -A 10 'backend' *.tf | grep -E 'bucket|key|workspace'

From Workspace

# Check Terraform workspace
terraform workspace show

Safety Checks

Pre-Operation Checklist

Before any Terraform or AWS operation:

  1. Identity Verified

- Account ID matches environment - Role/user is appropriate - Credentials not expired

  1. Environment Confirmed

- Directory matches expected environment - Backend configuration is correct - No conflicting env vars set

  1. Permission Verified

- Role has required permissions - No unexpected permission errors expected

Red Flags - STOP Immediately

ConditionAction
Account ID doesn't match environmentSTOP - wrong account!
Role seems too permissive for taskVerify with user
Credentials expiredRe-authenticate
Multiple AWS_* env vars setClear and use profile
Unknown account IDVerify before proceeding

Common Issues

Wrong Account Active

Symptoms:

  • Terraform can't find expected resources
  • Plan shows creating resources that exist
  • Permission denied for expected resources

Solution:

# Clear any env vars
unset AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN

# Set correct profile
export AWS_PROFILE=correct_profile

# Verify
aws sts get-caller-identity

Expired Credentials

Symptoms:

  • "ExpiredToken" errors
  • "credentials have expired" messages

Solution:

# For SSO
aws sso login --profile your_profile

# For assumed role
# Re-run assume-role command

Conflicting Configurations

Symptoms:

  • Unexpected account appearing
  • Operations in wrong region

Solution:

# Check all credential sources
echo "Profile: $AWS_PROFILE"
echo "Access Key set: ${AWS_ACCESS_KEY_ID:+yes}"
echo "Default region: $AWS_DEFAULT_REGION"
aws configure list

Integration with Other Skills

This skill should be invoked before:

  • terraform-plan-review
  • terraform-drift-detection
  • terraform-state-operations
  • Any AWS CLI operations

The profile verification output should be included in analysis reports to confirm correct environment.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.98%
按下载量换算22

Claude

27.36%
按下载量换算18

Cursor

20.64%
按下载量换算14

Gemini CLI

8.82%
按下载量换算6

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills