AWS Observability & Incident Response

$2.99Official

Invoke to instrument or investigate a live AWS workload: CloudWatch alarms and metric math, Logs Insights, X-Ray traces, CloudTrail forensics, incident triage.

cloudawsobservabilitycloudwatchlogs-insightsx-raycloudtrailincident-response· by SkillingMain

What you get

  • Runnable Shell / Python included
  • 7-point quality checklist
  • 9 pitfalls to avoid
  • Installs into 6 tools
Version
v1
Last updated
today
Length
11 min read
Requires
Best with a strong model (Claude Opus 5)

Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes · Built for large codebases

What you'll need to set up

Some setup · 15-30 min

An AWS account already emitting CloudWatch metrics and logs with at least one active CloudTrail trail, plus a read-only principal (IAM Identity Center profile or role) the agent can assume in the incident's region.

AWS_PROFILEAWS_REGIONAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYAWS_SESSION_TOKEN
Full setup guide · 20 API calls

Preview

When to use

Invoke when the task is to observe, instrument, or investigate a running AWS workload:

  • A live incident is open ("latency spiked", "5xx is up", "the queue is backing up") and you must find root cause fast, or an alarm fired and you must decide whether it is real.
  • Someone asks "what happened at 14:20 UTC?" and the answer lives in CloudWatch metrics, Logs Insights, X-Ray, or CloudTrail.
  • A service has no alarms, no dashboard, or unbounded log retention and must be instrumented.
  • Change forensics: who called DeleteBucket, which role assumed what, when a security group opened.

Do not invoke for provisioning, cost optimization, or IAM policy authoring; this skill is read-h

🔒 Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.