agent-bom discover aws
Discover AI agent assets on AWS and generate inventory
Install & Use
Copy this prompt and send it to your AI assistant (Claude / Cursor / TRAE / Codex / WorkBuddy etc.) to auto-install:
Help me install this AI Skill: agent-bom discover aws. It is used for: Discover AI agent assets on AWS and generate inventory Full Skill content: https://321skill.com/skills/agent-bom-discover-aws-x-11/raw/index.md Read that page and install it.
The prompt includes a link to the full Skill content. You can also view the full content.
This Skill addresses the lack of a unified tool and high security risks when inventorying AI agent and MCP-related assets in AWS cloud environments. In actual operations, teams need to quickly understand AI-related resources in services like Bedrock, ECS, SageMaker, Lambda, and EKS. However, traditional methods either rely on manual effort or require long-term, valid cloud credentials, posing security risks.
Usage is straightforward: simply run the agent-bom discover-aws command in an environment with configured AWS credentials (recommended: AWS SSO, WebIdentity, or STS short-term credentials). It automatically invokes the AWS SDK for read-only scanning, generates a JSON inventory file compliant with the agent-bom specification, and outputs it to the specified path. You can then optionally pass this inventory to agent-bom for further analysis.
It is well-suited for operations engineers and AI agent developers managing AWS AI infrastructure. Teams already using agent-bom for asset inventory management can integrate it seamlessly. It is also highly useful for scenarios requiring regular auditing of AWS AI assets to ensure compliance.
We recommend prioritizing this tool for unified AWS AI asset management and always using short-term credentials and read-only IAM policies. Note that it currently only supports the AWS cloud platform and requires a Python 3.11+ environment. The generated JSON inventory can be used independently or as input to agent-bom for deep scanning.
Key Features
Unlike AWS Config or AWS Resource Explorer, it specifically discovers AI agent and MCP assets (such as Bedrock Agent, SageMaker endpoints, etc.), outputs standardized agent-bom format, and avoids exposing long-term credentials to agent-bom.
Limitations
Requires Python 3.11+ environment, depends on the agent-bom package, and only supports the AWS cloud platform; other cloud providers are not supported.
FAQ
What AWS permissions are required?
A read-only IAM policy is recommended. Specific permissions can be viewed via the `agent-bom trust` command. Prefer using AWS SSO or STS short-term credentials.
Which AWS services are supported?
Supports services related to AI agents and MCP, such as Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, and more.
Installation guide for AI assistants
If your AI coding assistant (Claude Code, Cursor, TRAE etc.) can see this page, send it this message to auto-install:
Visit https://321skill.com/skills/agent-bom-discover-aws-x-11/raw/index.md to read the original Skill definition (Markdown format) for agent-bom discover aws, and install it according to the instructions.
Raw Markdown URL for AI: /skills/agent-bom-discover-aws-x-11/raw/index.md