Skip to content

Clarify AWS resource-query authentication preflight 🤖🤖🤖 - #4486

Open
ringquistchase-collab wants to merge 1 commit into
github:mainfrom
ringquistchase-collab:fix/aws-resource-query-auth-preflight
Open

ringquistchase-collab wants to merge 1 commit into
github:mainfrom
ringquistchase-collab:fix/aws-resource-query-auth-preflight

Conversation

@ringquistchase-collab

Copy link
Copy Markdown

Pull Request Checklist

  • Read and followed CONTRIBUTING.md and the Code of Conduct.
  • Read the guidance for submissions involving paid services (discussion Guidance for submissions involving paid services #968).
  • Updated the existing skill in its current directory; no new resource added.
  • Preserved skill name, description, naming conventions, and every resource-query mapping.
  • Ran npm run skill:validate and npm run build; generated indexes remain unchanged.
  • Targets main.
  • Live AWS calls or a separate agent-model evaluation (not performed; see validation below).

Description

Tighten the existing aws-resource-query skill's safety contract and credential-context preflight without duplicating its current secret-value exclusions or changing its query examples.

  • Explain that describe-*, list-*, and get-* prefixes are not blanket authorization, including temporary-credential issuance operations.
  • Distinguish AWS Console/VS Code/MCP sign-in from AWS CLI authentication.
  • Verify the user-selected profile/account, stop on failed or unexpected identity, and avoid silent account fallback.
  • Carry the confirmed profile and region into subsequent resource queries.
  • Keep authentication renewal outside this read-only workflow and never request credentials in chat.
  • Clarify that caller identity proves authentication, not read-only IAM authorization, and that reads may disclose data or incur query charges.

Type of Contribution

  • Update to an existing skill.

Validation

  • npm ci --ignore-scripts --no-fund --no-audit in an isolated upstream checkout.
  • npm run skill:validate: all 426 skills valid.
  • npm run build: passed; generated README tables and marketplace have no changes. Existing external-plugin catalog warnings are unrelated to this edit.
  • Frontmatter equality and unchanged intent/command mappings checked against the base commit.
  • git diff --check: passed.
  • Editor diagnostics: no errors in the changed skill.

Reviewed scenarios: browser sign-in without CLI credentials stops before discovery; unexpected caller account stops without profile fallback; an explicitly selected profile remains in every query; credential-issuance get-* operations are not accepted merely by prefix.

No live AWS API requests, resource/IAM changes, secret retrieval, or model-behavior benchmark was performed. This is documentation guidance, not an enforceable IAM sandbox.

Additional Notes

One file only: skills/aws-resource-query/SKILL.md. No application code, project promotion, personal runtime data, credentials, images, or generated files are included. AI-assisted contribution prepared with GitHub Copilot. The contribution is submitted under this repository's MIT license.

Co-Authored-By: GitHub Copilot <noreply@github.com>
@ringquistchase-collab
ringquistchase-collab requested a review from a team as a code owner October 5, 2026 02:25
Copilot AI balanced review requested due to automatic review settings October 5, 2026 02:25
@github-actions github-actions Bot added the skills PR touches skills label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🔒 PR Risk Scan Results

Scanned 1 changed file(s).

Severity Count
🔴 High 0
🟠 Medium 0
ℹ️ Info 0

✅ No matching risk patterns were detected in changed files.

This is an automated soft-gate report. Findings indicate review targets and do not block merge by themselves.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

🚦 Submission status: ⏳ Awaiting automation

Risk tier: merge-risk:low — Documentation, metadata, generated output, or a small update to an existing resource
Required to merge: passing submission-gate checks plus 1 approval from reviewers with write access.

Why this tier
  • Small update (33 changed lines) to existing resources with no added or removed files

Automated checks

Check Status Details
Line endings ⏳ Pending Waiting for the check to start
Spelling ⏳ Pending Waiting for the check to start
Generated README consistency ⏳ Pending Waiting for the check to start
Skill validation ⏳ Pending Waiting for the check to start
Skill lint (vally) ⏳ Pending Waiting for the check to start
Risk scan ⏳ Pending Waiting for the check to start
Contributor reputation ⏳ Pending Waiting for the check to start
Duplicate resource scan ⏳ Pending (advisory, non-blocking) Waiting for the check to start
PR quality signal ⏳ Pending (advisory, non-blocking) Waiting for the check to start

Review

  • Approvals: 0/1
  • Assigned reviewer: not assigned yet — comment /request-review to ask for one
  • Review target date: not set
  • Still needed: 1 more approval(s)
  • No staffed reviewer pool owns these files yet; any reviewer with write access counts as the resource owner.

Commands

Command Who What it does
/rerun-checks PR author, maintainers Re-runs failed or incomplete checks and re-evaluates this gate
/request-review PR author, maintainers Asks the review rotation to assign a reviewer (adds needs-reviewer)

Updated for 3434444 · This comment is maintained automatically — see submission gate docs.

@github-actions github-actions Bot added the skill-check-error Skill validator reported errors label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🔍 Vally Lint Results

⛔ Findings need attention

Scope Checked
Skills 1
Agents 0
Total 1
Severity Count
❌ Errors 1
⚠️ Warnings 0
ℹ️ Advisories 0

Summary

Level Finding
❌ aws-resource-query (1/2 checks passed, 1 failed)
Full linter output
### Linting skills/aws-resource-query
❌ aws-resource-query (1/2 checks passed, 1 failed)
    ✗ [spec-compliance] 1 of 1 skill(s) have spec violations.
        ✗ spec-compliance: Spec checks failed.
            ✗ File length (659 lines) exceeds limit (500).
    ✓ [valid-refs] All file references across 1 skill(s) are valid.
        ✓ valid-refs: All file references resolve to existing files within the skill directory.

1 skill(s) linted, 1 failed

Note: Vally lint returned a non-zero exit code. Please review the findings above before merge.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused documentation update is consistent, actionable, validated, and introduces no unresolved issues.

Review effort: Balanced
Findings: None

What changed in this PR

Strengthens the AWS resource-query skill’s authentication and read-only safety guidance.

Changes:

  • Clarifies excluded credential and sensitive-data operations.
  • Adds explicit profile, account, region, and identity preflight instructions.
  • Prevents credential fallback and in-chat credential handling.
File Description
skills/​aws-resource-query/​SKILL.md Expands safety and AWS CLI authentication guidance.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions github-actions Bot added ready-for-review Submission passed intake validation and is ready for maintainer review awaiting-automation and removed awaiting-automation ready-for-review Submission passed intake validation and is ready for maintainer review labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting-automation merge-risk:low skill-check-error Skill validator reported errors skills PR touches skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants