Install
$ agentstack add skill-dnouri-ai-config-aws-sso ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README — it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
AWS SSO Re-Authentication
This skill handles AWS SSO token expiration. Use it when AWS commands fail with authentication errors.
Detect Auth Failure
Trigger this skill when you see errors like:
Token has expired and refresh failedThe SSO session has expiredError when retrieving credentialsThe SSO access token has expired
Re-Authentication Flow
Step 1: Start login in tmux
Run the login command in a tmux session with --no-browser to capture the URL:
tmux new-session -d -s aws-sso 'aws sso login --profile --no-browser > /tmp/pi-tmux-aws-sso.log 2>&1'
Step 2: Wait briefly, then read the URL
sleep 1
cat /tmp/pi-tmux-aws-sso.log
The output will contain:
Browser will not be automatically opened.
Please visit the following URL:
https://oidc..amazonaws.com/authorize?...
Step 3: Present URL to user
Show the user the URL and ask them to complete authentication:
⚠️ AWS SSO token expired for profile ``.
Please open this URL in your browser to authenticate:
Let me know when you've completed the login.
Step 4: Verify authentication
After user confirms, check if login succeeded:
cat /tmp/pi-tmux-aws-sso.log
Look for Successfully logged into Start URL: in the output.
Then verify credentials work:
aws sts get-caller-identity --profile
Step 5: Clean up
tmux kill-session -t aws-sso 2>/dev/null
rm -f /tmp/pi-tmux-aws-sso.log
List Available Profiles
grep '^\[profile' ~/.aws/config | sed 's/\[profile \(.*\)\]/\1/'
Check Token Status
aws sts get-caller-identity --profile 2>&1
Rules
- Only use this skill for auth failures - not for general AWS work
- Always use
--no-browser- lets us capture and show the URL - Use tmux - keeps the login process running independently
- Wait for user confirmation - never retry automatically after auth failure
- Be specific about which profile needs login
- Clean up the tmux session and log file when done
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: dnouri
- Source: dnouri/ai-config
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.