AWS Observability & Incident Response
$2.99OfficialInvoke to instrument or investigate a live AWS workload: CloudWatch alarms and metric math, Logs Insights, X-Ray traces, CloudTrail forensics, incident triage.
cloudawsobservabilitycloudwatchlogs-insightsx-raycloudtrailincident-response· by SkillingMain
What you get
- ✓Runnable Shell / Python included
- ✓7-point quality checklist
- ✓9 pitfalls to avoid
- ✓Installs into 6 tools
- Version
- v1 →
- Last updated
- today
- Length
- 11 min read
- Requires
- Best with a strong model (Claude Opus 5)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes · Built for large codebases
What you'll need to set up
Some setup · 15-30 minAn AWS account already emitting CloudWatch metrics and logs with at least one active CloudTrail trail, plus a read-only principal (IAM Identity Center profile or role) the agent can assume in the incident's region.
AWS_PROFILEAWS_REGIONAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYAWS_SESSION_TOKENPreview
When to use
Invoke when the task is to observe, instrument, or investigate a running AWS workload:
- A live incident is open ("latency spiked", "5xx is up", "the queue is backing up") and you must find root cause fast, or an alarm fired and you must decide whether it is real.
- Someone asks "what happened at 14:20 UTC?" and the answer lives in CloudWatch metrics, Logs Insights, X-Ray, or CloudTrail.
- A service has no alarms, no dashboard, or unbounded log retention and must be instrumented.
- Change forensics: who called
DeleteBucket, which role assumed what, when a security group opened.
Do not invoke for provisioning, cost optimization, or IAM policy authoring; this skill is read-h
…
🔒 Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.