Repository navigation
Clarify AWS resource-query authentication preflight 🤖🤖🤖 - #4486
ringquistchase-collab wants to merge 1 commit into
Conversation
Co-Authored-By: GitHub Copilot <noreply@github.com>
🔒 PR Risk Scan ResultsScanned 1 changed file(s).
✅ No matching risk patterns were detected in changed files.
|
🚦 Submission status: ⏳ Awaiting automationRisk tier: Why this tier
Automated checks
Review
Commands
Updated for |
🔍 Vally Lint Results⛔ Findings need attention
Summary
Full linter output
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused documentation update is consistent, actionable, validated, and introduces no unresolved issues.
Review effort: Balanced
Findings: None
What changed in this PR
Strengthens the AWS resource-query skill’s authentication and read-only safety guidance.
Changes:
- Clarifies excluded credential and sensitive-data operations.
- Adds explicit profile, account, region, and identity preflight instructions.
- Prevents credential fallback and in-chat credential handling.
| File | Description |
|---|---|
skills/aws-resource-query/SKILL.md |
Expands safety and AWS CLI authentication guidance. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Pull Request Checklist
npm run skill:validateandnpm run build; generated indexes remain unchanged.main.Description
Tighten the existing
aws-resource-queryskill's safety contract and credential-context preflight without duplicating its current secret-value exclusions or changing its query examples.describe-*,list-*, andget-*prefixes are not blanket authorization, including temporary-credential issuance operations.Type of Contribution
Validation
npm ci --ignore-scripts --no-fund --no-auditin an isolated upstream checkout.npm run skill:validate: all 426 skills valid.npm run build: passed; generated README tables and marketplace have no changes. Existing external-plugin catalog warnings are unrelated to this edit.git diff --check: passed.Reviewed scenarios: browser sign-in without CLI credentials stops before discovery; unexpected caller account stops without profile fallback; an explicitly selected profile remains in every query; credential-issuance
get-*operations are not accepted merely by prefix.No live AWS API requests, resource/IAM changes, secret retrieval, or model-behavior benchmark was performed. This is documentation guidance, not an enforceable IAM sandbox.
Additional Notes
One file only:
skills/aws-resource-query/SKILL.md. No application code, project promotion, personal runtime data, credentials, images, or generated files are included. AI-assisted contribution prepared with GitHub Copilot. The contribution is submitted under this repository's MIT license.