Creator · itsmostafa
Last updated · Sep 2, 2026
AWS CloudFormation infrastructure as code for stack management. Use when writing templates, deploying stacks, managing drift, troubleshooting deployments, or organizing infrastructure with nested stacks.
Sandbox only
Install targets
Codex install prompt
Install the "cloudformation" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/cloudformation. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: AWS CloudFormation infrastructure as code for stack management. Use when writing templates, deploying stacks, managing drift, troubleshooting deployments, or organizing infrastructure with nested stacks. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"itsmostafa-cloudformation","task":"Install cloudformation","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add itsmostafa/aws-agent-skills --skill cloudformation
Maintenance
fresh
7d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
1.1K
77/100 Quality · 79/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing · Quality score needs review
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
1.1K GitHub stars
Repo activity
1.1K stars, 444 forks
Maintenance
7d since push
License
MIT
Install
npx skills add itsmostafa/aws-agent-skills --skill cloudformation
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add itsmostafa/aws-agent-skills --skill cloudformationDo not use when
Alternative
168.6K Stars
npx skills add mattpocock/skills --skill code-review
Alternative
40.8K Stars
npx skills add appsmithorg/appsmith
Alternative
175.7K Stars
npx skills add mattpocock/skills --skill implement
Alternative
30.9K Stars
npx skills add vercel-labs/agent-skills --skill vercel-react-best-practices
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
medium
Skill may inspect schemas, query databases, or work with persistent stores.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20cloudformation%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20cloudformation%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/itsmostafa-cloudformation/install
Agent should check
Copy prompt
Task: Use cloudformation in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20cloudformation%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/itsmostafa-cloudformation/install
Install command: npx skills add itsmostafa/aws-agent-skills --skill cloudformation
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/itsmostafa-cloudformation/install
LLM text format
/api/skills/itsmostafa-cloudformation/install?format=text
Find alternatives
/api/skills/search?q=cloudformation&limit=3
Agent prompt
Use cloudformation for this task. Review https://www.openagentskill.com/api/skills/itsmostafa-cloudformation/install, then install with: npx skills add itsmostafa/aws-agent-skills --skill cloudformationRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/itsmostafa-cloudformation
LLM text
/api/registry/manifest/itsmostafa-cloudformation?format=text
Install alias
/api/registry/install/itsmostafa-cloudformation
Recommend
/api/registry/recommend?task=Use%20cloudformation%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Security and compliance
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
PASS1.1K GitHub stars
Stars/forks activity
PASS1.1K stars, 444 forks; issue activity unavailable in current metadata
Recent maintenance
PASS7d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Operate web apps
I need my agent to control a browser, fill forms, and verify web app workflows.
Workflow fit
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Alternative shortlist
Similar skills that may fit this task.
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
--- name: cloudformation description: AWS CloudFormation infrastructure as code for stack management. Use when writing templates, deploying stacks, managing drift, troubleshooting deployments, or organizing infrastructure with nested stacks. last_updated: "2026-01-07" doc_source: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/ ---
# AWS CloudFormation
AWS CloudFormation provisions and manages AWS resources using templates. Define infrastructure as code, version control it, and deploy consistently across environments.
## Table of Contents
- [Core Concepts](#core-concepts) - [Common Patterns](#common-patterns) - [CLI Reference](#cli-reference) - [Best Practices](#best-practices) - [Troubleshooting](#troubleshooting) - [References](#references)
## Core Concepts
### Templates
JSON or YAML files defining AWS resources. Key sections: - **Parameters**: Input values - **Mappings**: Static lookup tables - **Conditions**: Conditional resource creation - **Resources**: AWS resources (required) - **Outputs**: Return values
### Stacks
Collection of resources managed as a single unit. Created from templates.
### Change Sets
Preview changes before executing updates.
### Stack Sets
Deploy stacks across multiple accounts and regions.
## Common Patterns
### Basic Template Structure
```yaml AWSTemplateFormatVersion: '2010-09-09' Description: My infrastructure template
Parameters: Environment: Type: String AllowedValues: [dev, staging, prod] Default: dev
Mappings: EnvironmentConfig: dev: InstanceType: t3.micro prod: InstanceType: t3.large
Conditions: IsProd: !Equals [!Ref Environment, prod]
Resources: MyBucket: Type: AWS::S3::Bucket Properties: BucketName: !Sub 'my-app-${Environment}-${AWS::AccountId}' VersioningConfiguration: Status: !If [IsProd, Enabled, Suspended]
Outputs: BucketName: Description: S3 bucket name Value: !Ref MyBucket Export: Name: !Sub '${AWS::StackName}-BucketName' ```
### Deploy a Stack
**AWS CLI:**
```bash # Create stack aws cloudformation create-stack \ --stack-name my-stack \ --template-body file://template.yaml \ --parameters ParameterKey=Environment,ParameterValue=prod \ --capabilities CAPABILITY_IAM
# Wait for completion aws cloudformation wait stack-create-complete --stack-name my-stack
# Update stack aws cloudformation update-stack \ --stack-name my-stack \ --template-body file://template.yaml \ --parameters ParameterKey=Environment,ParameterValue=prod
# Delete stack aws cloudformation delete-stack --stack-name my-stack ```
### Use Change Sets
```bash # Create change set aws cloudformation create-change-set \ --stack-name my-stack \ --change-set-name my-changes \ --template-body file://template.yaml \ --parameters ParameterKey=Environment,ParameterValue=prod
# Describe changes aws cloudformation describe-change-set \ --stack-name my-stack \ --change-set-name my-changes
# Execute change set aws cloudformation execute-change-set \ --stack-name my-stack \ --change-set-name my-changes ```
### Lambda Function
```yaml Resources: LambdaFunction: Type: AWS::Lambda::Function Properties: FunctionName: !Sub '${AWS::StackName}-function' Runtime: python3.12 Handler: index.handler Role: !GetAtt LambdaRole.Arn Code: ZipFile: | def handler(event, context): return {'statusCode': 200, 'body': 'Hello'} Environment: Variables: ENVIRONMENT: !Ref Environment
LambdaRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: '2012-10-17' Statement: - Effect: Allow Principal: Service: lambda.amazonaws.com Action: sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole ```
### VPC with Subnets
```yaml Resources: VPC: Type: AWS::EC2::VPC Properties: CidrBlock: 10.0.0.0/16 EnableDnsHostnames: true Tags: - Key: Name Value: !Sub '${AWS::StackName}-vpc'
PublicSubnet1: Type: AWS::EC2::Subnet Properties: VpcId: !Ref VPC AvailabilityZone: !Select [0, !GetAZs ''] CidrBlock: 10.0.1.0/24 MapPublicIpOnLaunch: true
PrivateSubnet1: Type: AWS::EC2::Subnet Properties: VpcId: !Ref VPC AvailabilityZone: !Select [0, !GetAZs ''] CidrBlock: 10.0.10.0/24
InternetGateway: Type: AWS::EC2::InternetGateway
AttachGateway: Type: AWS::EC2::VPCGatewayAttachment Properties: VpcId: !Ref VPC InternetGatewayId: !Ref InternetGateway
PublicRouteTable: Type: AWS::EC2::RouteTable Properties: VpcId: !Ref VPC
PublicRoute: Type: AWS::EC2::Route DependsOn: AttachGateway Properties: RouteTableId: !Ref PublicRouteTable DestinationCidrBlock: 0.0.0.0/0 GatewayId: !Ref InternetGateway
PublicSubnet1RouteTableAssociation: Type: AWS::EC2::SubnetRouteTableAssociation Properties: SubnetId: !Ref PublicSubnet1 RouteTableId: !Ref PublicRouteTable ```
### DynamoDB Table
```yaml Resources: OrdersTable: Type: AWS::DynamoDB::Table Properties: TableName: !Sub '${AWS::StackName}-orders' AttributeDefinitions: - AttributeName: PK AttributeType: S - AttributeName: SK AttributeType: S - AttributeName: GSI1PK AttributeType: S - AttributeName: GSI1SK AttributeType: S KeySchema: - AttributeName: PK KeyType: HASH - AttributeName: SK KeyType: RANGE GlobalSecondaryIndexes: - IndexName: GSI1 KeySchema: - AttributeName: GSI1PK KeyType: HASH - AttributeName: GSI1SK KeyType: RANGE Projection: ProjectionType: ALL BillingMode: PAY_PER_REQUEST PointInTimeRecoverySpecification: PointInTimeRecoveryEnabled: true ```
## CLI Reference
### Stack Operations
| Command | Description | |---------|-------------| | `aws cloudformation create-stack` | Create stack | | `aws cloudformation update-stack` | Update stack | | `aws cloudformation delete-stack` | Delete stack | | `aws cloudformation describe-stacks` | Get stack info | | `aws cloudformation list-stacks` | List stacks | | `aws cloudformation describe-stack-events` | Get events | | `aws cloudformation describe-stack-resources` | Get resources |
### Change Sets
| Command | Description | |---------|-------------| | `aws cloudformation create-change-set` | Create change set | | `aws cloudformation describe-change-set` | View changes | | `aws cloudformation execute-change-set` | Apply changes | | `aws cloudformation delete-change-set` | Delete change set |
### Template
| Command | Description | |---------|-------------| | `aws cloudformation validate-template` | Validate template | | `aws cloudformation get-template` | Get stack template | | `aws cloudformation get-template-summary` | Get template info |
## Best Practices
### Template Design
- **Use parameters** for environment-specific values - **Use mappings** for static lookup tables - **Use conditions** for optional resources - **Export outputs** for cross-stack references - **Add descriptions** to parameters and outputs
### Security
- **Use IAM roles** instead of access keys - **Enable termination protection** for production - **Use stack policies** to protect resources - **Never hardcode secrets** — use Secrets Manager
```bash # Enable termination protection aws cloudformation update-termination-protection \ --stack-name my-stack \ --enable-termination-protection ```
### Organization
- **Use nested stacks** for complex infrastructure - **Create reusable modules** - **Version control templates** - **Use consistent naming conventions**
### Reliability
- **Use DependsOn** for explicit dependencies - **Configure creation policies** for instances - **Use update policies** for Auto Scaling groups - **Implement rollback triggers**
## Troubleshooting
### Stack Creation Failed
```bash # Get failure reason aws cloudformation describe-stack-events \ --stack-name my-stack \ --query 'StackEvents[?ResourceStatus==`CREATE_FAILED`]'
# Common causes: # - IAM permissions # - Resource limits # - Invalid property values # - Dependency failures ```
### Stack Stuck in DELETE_FAILED
```bash # Identify resources that couldn't be deleted aws cloudformation describe-stack-resources \ --stack-name my-stack \ --query 'StackResources[?ResourceStatus==`DELETE_FAILED`]'
# Retry with resources to skip aws cloudformation delete-stack \ --stack-name my-stack \ --retain-resources ResourceLogicalId1 ResourceLogicalId2 ```
### Drift Detection
```bash # Detect drift aws cloudformation detect-stack-drift --stack-name my-stack
# Check drift status aws cloudformation describe-stack-drift-detection-status \ --stack-drift-detection-id abc123
# View drifted resources aws cloudformation describe-stack-resource-drifts \ --stack-name my-stack ```
### Rollback Failed
```bash # Continue update rollback aws cloudformation continue-update-rollback \ --stack-name my-stack \ --resources-to-skip ResourceLogicalId1 ```
## References
- [CloudFormation User Guide](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/) - [CloudFormation API Reference](https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/) - [CloudFormation CLI Reference](https://docs.aws.amazon.com/cli/latest/reference/cloudformation/) - [Resource and Property Reference](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-template-resource-type-ref.html)
Source provenance
Decision snapshot
1,150 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for cloudformation, ready for a manual X post.
cloudformation: AWS CloudFormation infrastructure as code for stack management. Use when writing templates, d... 1.1K stars https://www.openagentskill.com/skills/itsmostafa-cloudformation?ref=x
Listing + install path for cloudformation: https://www.openagentskill.com/skills/itsmostafa-cloudformation?ref=x Install: npx skills add itsmostafa/aws-agent-skills --skill cloudformation
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to itsmostafa but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/itsmostafa-cloudformation?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/itsmostafa-cloudformation?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/itsmostafa-cloudformation/audit)
[](https://www.openagentskill.com/skills/itsmostafa-cloudformation?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)itsmostafa
@itsmostafa
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
168.6K StarsAppsmith
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
40.8K StarsImplement
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
175.7K StarsVercel React Best Practices
React and Next.js performance guidance for writing, reviewing, and refactoring production UI code.
30.9K StarsPermission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Usable metadata, review docs
Risk summary
Install readiness