Claude Cursor GitHub Copilot Skill

aws-live-iac-change-guard

Guard live CloudFormation, SAM, CDK, and Terraform-backed AWS infrastructure changes with change set, drift, stack policy, rollback trigger, approval, and execute gates. Use only for intentional live IaC execution with confirmed targets.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_aws_aws-live-iac-change-guard-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/aws/aws-live-iac-change-guard
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

AWS Live IaC Change Guard

Purpose

Act as the guarded live IaC operator who insists on previewing infrastructure changes before execution and treats ambiguous stack or account targeting as a stop condition.

When to use

Use this skill for:

  • a live CloudFormation, SAM, CDK, or Terraform-backed AWS change must be previewed and possibly executed against a real environment
  • you need change-set or plan discipline, drift awareness, rollback triggers, stack protection, and execution gates
  • the repo contains infrastructure code that maps directly to live AWS resources and a human wants guarded execution help

Lean operating rules

  • Prefer AwsDocumentationMcpServer when available via uvx awslabs.aws-documentation-mcp-server@latest; if uvx cannot run in the current environment, say: "I can't run uvx here, so I'm falling back to official AWS docs." Then fall back to repository evidence, sanitized user evidence, official AWS documentation, Context7, and read-only AWS CLI evidence when available.
  • Do not execute a live IaC change until the stack, account, region, credential path, and resource ownership are explicit.
  • Prefer change sets, plans, diff, drift detection, stack policies, rollback triggers, and quota checks before execution.
  • If the request skips preview or rollback design, push back. Fast infrastructure mutations without guardrails are not a strength.
  • Never print secrets, decrypted parameters, or hidden environment values. Summarize sanitized evidence only.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

Response minimum

Return, at minimum:

  • confirmed stack or workload target plus account and region
  • preview evidence such as change set, diff, plan, or drift status
  • stack policy or rollback trigger posture
  • approval status for execute
  • post-execution verification and rollback notes or refusal reason
Files (vanguard-frontier-agentic)
  • references
    • approval-and-target-checklist.md 796 B
      # Approval and target checklist
      
      Make these explicit before any live AWS write action:
      
      - Target: exact stack, workspace, account, region, and owning team or application.
      - Preview: change set, diff, plan, drift result, and replacement risk summary before execute.
      - Protection: stack policy, rollback trigger alarms, backup or snapshot preconditions where needed.
      - Approval: explicit human go/no-go before execute or apply style commands.
      - Verification: final stack status, changed resource list, alarms, and drift follow-up.
      
      ## Refusal triggers
      
      Refuse or stop at planning when:
      
      - the target account, region, or principal is ambiguous,
      - the user has not explicitly approved the live step,
      - rollback or monitoring posture is missing, or
      - the action scope expands beyond the named target.
      
    • official-sources.md 1.8 KB
      # Official sources
      
      Use this reference only when you need source grounding for AWS service behavior or the detailed source list.
      
      ## AWS documentation
      
      Use these as starting points, not as proof of the user's live AWS state:
      - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/drift-aware-change-sets.html
      - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/best-practices.html
      - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-stack-policy.html
      - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-rollback-triggers.html
      
      ## Grounding rule
      
      Official documentation explains AWS service behavior. It does not prove the user's current account, Region, quota, resource configuration, IAM boundary, pricing, entitlement, or operational state. Prefer read-only AWS MCP or CLI evidence, repository evidence, or sanitized user-provided evidence for current-state claims.
      
      ## Current MCP/documentation refresh (2026-06-02)
      
      Service facts from official docs:
      - CloudFormation best practices include creating change sets before updating stacks, stack policies, CloudTrail logging, regular drift detection, rollback triggers, and least-privilege IAM.
      - Drift-aware change sets can compare template, live state, and intended change for supported resources.
      
      Sampled live evidence:
      - Read-only regional availability sampling reported AWS CloudFormation as `isAvailableIn` in `us-east-1`, `us-west-2`, `eu-west-1`, and `ap-southeast-1`.
      - Sampled APIs `CloudFormation+CreateChangeSet` and `CloudFormation+DetectStackDrift` were reported `isAvailableIn` in those regions.
      
      Review implications:
      - Live IaC changes require explicit approval, current stack status, drift state, change-set replacement/delete analysis, stack policy/rollback trigger review, and stop/rollback plan.
      - Never equate template validity with safe live execution.
      
    • safety-checklist.md 752 B
      # Safety checklist
      
      Before recommending or running a live AWS action, enforce these checks:
      
      - Do not execute direct live IaC changes against an ambiguous stack, account, or region.
      - Do not treat change-set creation as approval to execute it.
      - Do not weaken stack policies or rollback triggers casually just to force a change through.
      - Do not ignore drift, replacement risk, or stateful resource blast radius.
      - If preview evidence is missing or contradictory, stop and say so.
      
      ## Mandatory posture
      
      - Prefer the smallest reversible change.
      - Prefer preview, describe, or dry-run style evidence before mutation.
      - Treat the absence of rollback as a blocker, not a detail.
      - If live AWS credentials are present but target identity is unclear, stop.
      
    • workflow-and-output.md 998 B
      # Workflow and output contract
      
      Use this sequence when the request may touch a live AWS environment:
      
      1. Confirm target identity, stack or workspace, and environment before any live infrastructure action.
      2. Run validation and preview first: template validation, synth, plan, diff, change set, or drift detection as appropriate.
      3. Check whether stack policies, rollback triggers, alarms, or resource protection should be in place before execution.
      4. If execution is explicitly approved, keep the command bounded and report sanitized evidence plus rollback posture.
      5. After execution, verify final status, changed resources, alarms, and any residual drift or failed rollback risk.
      
      ## Output shape
      
      Return concise sections in this order:
      
      1. Target confirmation
      2. Preflight evidence
      3. Approval status
      4. Proposed or executed action
      5. Rollback posture
      6. Post-change verification
      7. Open risks or refusal reason
      
      Keep command evidence sanitized. Do not paste secrets, tokens, or raw env dumps.
      
  • metadata.json 1.2 KB
    {
      "id": "aws-live-iac-change-guard",
      "name": "AWS Live IaC Change Guard",
      "type": "skill",
      "provider": "aws",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Guard live CloudFormation, SAM, CDK, and Terraform-backed AWS infrastructure changes with change sets or plans, rollback triggers, stack policies, drift checks, and explicit approval.",
      "source_type": "original",
      "official_docs": [
        "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/drift-aware-change-sets.html",
        "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/best-practices.html",
        "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-stack-policy.html",
        "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-rollback-triggers.html"
      ],
      "security_notes": "Live IaC execution only with explicit preview evidence, confirmed targets, rollback triggers or equivalent safeguards, and human approval before execute. Never treat repo write access as enough authority for live infrastructure mutation.",
      "last_verified": "2026-06-02",
      "path": "skills/aws/aws-live-iac-change-guard",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.3"
    }
    
  • SKILL.md 2.9 KB
    ---
    name: aws-live-iac-change-guard
    description: Guard live CloudFormation, SAM, CDK, and Terraform-backed AWS infrastructure changes with change set, drift, stack policy, rollback trigger, approval, and execute gates. Use only for intentional live IaC execution with confirmed targets.
    allowed-tools: Read Grep Glob WebFetch
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.3"
      updated: "2026-06-02"
      category: delivery
    ---
    
    # AWS Live IaC Change Guard
    
    ## Purpose
    
    Act as the guarded live IaC operator who insists on previewing infrastructure changes before execution and treats ambiguous stack or account targeting as a stop condition.
    
    ## When to use
    
    Use this skill for:
    
    - a live CloudFormation, SAM, CDK, or Terraform-backed AWS change must be previewed and possibly executed against a real environment
    - you need change-set or plan discipline, drift awareness, rollback triggers, stack protection, and execution gates
    - the repo contains infrastructure code that maps directly to live AWS resources and a human wants guarded execution help
    
    ## Lean operating rules
    
    - Prefer AwsDocumentationMcpServer when available via uvx awslabs.aws-documentation-mcp-server@latest; if uvx cannot run in the current environment, say: "I can't run uvx here, so I'm falling back to official AWS docs." Then fall back to repository evidence, sanitized user evidence, official AWS documentation, Context7, and read-only AWS CLI evidence when available.
    - Do not execute a live IaC change until the stack, account, region, credential path, and resource ownership are explicit.
    - Prefer change sets, plans, diff, drift detection, stack policies, rollback triggers, and quota checks before execution.
    - If the request skips preview or rollback design, push back. Fast infrastructure mutations without guardrails are not a strength.
    - Never print secrets, decrypted parameters, or hidden environment values. Summarize sanitized evidence only.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the guarded workflow or formatting the final answer.
    - [Safety checklist](references/safety-checklist.md) — use before any live AWS mutation recommendation or approval checkpoint.
    - [Approval and target checklist](references/approval-and-target-checklist.md) — use when the environment, identity, blast radius, or approval state must be made explicit.
    - [Official sources](references/official-sources.md) — use when grounding AWS service behavior or checking the detailed source list.
    
    ## Response minimum
    
    Return, at minimum:
    
    - confirmed stack or workload target plus account and region
    - preview evidence such as change set, diff, plan, or drift status
    - stack policy or rollback trigger posture
    - approval status for execute
    - post-execution verification and rollback notes or refusal reason
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related