agent-bom discover aws
One-click discovery of AWS AI agent assets, outputting a standardized inventory.
Install & Use
Copy this prompt and send it to your AI assistant (Claude / Cursor / TRAE / Codex / WorkBuddy etc.) to auto-install:
Help me install this AI Skill: agent-bom discover aws. It is used for: One-click discovery of AWS AI agent assets, outputting a standardized inventory. Full Skill content: https://321skill.com/skills/agent-bom-discover-aws-x-5/raw/index.md Read that page and install it.
The prompt includes a link to the full Skill content. You can also view the full content.
Problem it solves: When you need to quickly inventory all AI Agent and MCP-related resources (such as Bedrock, ECS, SageMaker, Lambda, EKS, Step Functions, EC2, etc.) in your AWS cloud environment, manually navigating through various service consoles is time-consuming, labor-intensive, and prone to omissions. This Skill automatically scans the specified account and outputs a standardized inventory JSON compliant with the agent-bom specification, helping you gain a complete overview of your AI infrastructure.
How to use: Run this Skill directly in a terminal or integrated environment. It does not require long-term cloud credentials (only temporary STS tokens or an IAM role). It automatically calls AWS APIs to discover all eligible assets and generates a normalized bill of materials file. You can choose to pass the results to the main agent-bom tool for further security scanning or use them directly for asset inventory.
Target audience: Operations engineers, agent developers, security auditors, and teams that need to manage AI Agent infrastructure on AWS. Particularly suitable for scenarios requiring regular inventory, compliance audits, or migration planning.
Usage recommendations: It is recommended to first assign an IAM role with minimal permissions (e.g., ReadOnlyAccess + specific service permissions) to the tool to avoid excessive privileges. Scan results can be used in conjunction with agent-bom's vulnerability scanning feature to identify exposure surfaces or configuration risks. Note that this tool only discovers assets and does not modify any resources, making it safe to use in production environments.
Key Features
Compared to native AWS resource discovery tools (like Resource Explorer, Config), this Skill is specifically designed for AI Agent and MCP-related assets. Its output format is directly compatible with the agent-bom ecosystem, and it can run without long-term credentials, reducing security risks.
Limitations
Only covers AI Agent and MCP-related services on AWS (such as Bedrock, ECS, SageMaker, etc.). It is not suitable for general-purpose cloud resource inventory and requires at least read-only permissions for the corresponding services in the target account.
FAQ
Does running this tool require long-term AWS access keys?
No. It only requires temporary STS credentials or an IAM role. The tool automatically obtains temporary credentials at runtime, avoiding the risk of long-term credential leakage.
What is the output JSON format? Can it be used directly for agent-bom scanning?
The output is a standardized inventory JSON compliant with the agent-bom specification. It can be directly passed to the main agent-bom tool for subsequent security scanning, vulnerability analysis, and other operations.
Installation guide for AI assistants
If your AI coding assistant (Claude Code, Cursor, TRAE etc.) can see this page, send it this message to auto-install:
Visit https://321skill.com/skills/agent-bom-discover-aws-x-5/raw/index.md to read the original Skill definition (Markdown format) for agent-bom discover aws, and install it according to the instructions.
Raw Markdown URL for AI: /skills/agent-bom-discover-aws-x-5/raw/index.md