Five plugins split AWS work by job
Agent Toolkit for AWS packages 5 named plugins rather than presenting one huge instruction file. aws-core covers service choice, infrastructure, serverless, containers, storage, observability, billing, SDK use, and deployment. Other plugins focus on Bedrock and AgentCore, data analytics, development security work, or startup architecture and migration. Claude Code, Codex, and Cursor can install these bundles, which combine agent skills with the AWS MCP Server configuration.
The toolkit has 3 separable layers. Skills are local instruction folders loaded when a task matches. Rules files tell an agent how a project expects AWS work to happen. The managed MCP server supplies live documentation, API access, and script execution. Kiro and fx users configure that server and install skills independently. This separation is useful when a team wants better AWS answers before it is ready to let the agent touch an account.
What happened when we ran it
No sandbox result exists for this repository. Our harness did not support its Python ecosystem, and the repository provides no Dockerfile that the lab could use as a defined runtime path. We therefore have no measured install duration, dependency footprint, build result, test count, vulnerability audit, or runtime behavior. Any claim that it was easy to install or passed tests would be invented.
The missing run matters more here because the product spans local files, client plugin formats, a proxy launched through uvx, and a managed AWS endpoint. The Kiro example contacts an endpoint in us-east-1 while passing us-west-2 as the working region. A useful evaluation must include the exact client, region, authentication method, IAM policy, and a harmless API call whose CloudTrail record you can inspect. Our lab did none of those things.
The server reaches 300-plus AWS services, so IAM decides the risk
The AWS MCP Server advertises access across more than 300 AWS services through one authenticated endpoint. It also offers isolated Python script execution and current AWS documentation search. Documentation lookup and local skill discovery do not need AWS credentials. API calls and scripts do. That distinction lets a team begin with research, then add account access only after it has decided what the agent may read or change.
AWS supplies IAM context conditions intended to distinguish agent actions from human actions. The README also points to 2 operating records: CloudTrail events for requests and CloudWatch metrics for monitoring. Those controls are the strongest reason to prefer this toolkit over handing a model a broadly configured shell. They are not automatic least privilege. A role that can create, delete, or modify resources remains powerful when the caller is an agent, even if every call is recorded.
Claude Code and Codex get direct plugin commands, with one Codex fault
Claude Code can install 3 main plugins, aws-core, aws-agents, and aws-data-analytics, from Anthropic's official marketplace. Codex users add the AWS repository as a plugin marketplace and browse aws-core through /plugins. Cursor has a team marketplace route. Kiro and fx use direct MCP JSON plus skills. Every route eventually needs a deliberate choice between local guidance and authenticated execution.
Open issue 198 narrows a current Codex problem to the aws-agents-for-devsecops plugin version 1.0.0. Its MCP URL contains shell-style region interpolation that Codex 0.145.0.289 keeps as literal text, so the HTTP client fails before MCP initialization. The reporter tested aws-core, aws-agents, and aws-data-analytics successfully in the same installation. This is not evidence that every Codex plugin is broken, but it is a reason to verify each installed bundle.
The GA badge arrived before a GitHub release
GitHub showed 2,758 stars, 28 open issues, and 17 open pull requests on September 30, 2026. The repository was created on April 23 and pushed on September 30. Recent activity included startup migration work, observability guidance, model catalog updates, and Well-Architected proposals. That combination shows a young repository receiving daily work, not a finished interface that changes only on a slow release schedule.
There was no latest GitHub release to inspect on September 30, even though the README status badge says GA. Teams that require immutable release artifacts should decide whether to pin a commit, consume a marketplace version, or wait for repository tags. Open issue 64 also records an x86 limit in remote post-transform verification for a Graviton migration path. Active development is useful, but these details belong in an adoption ticket.
It replaces a collection only when the supported path covers your task
AWS began publishing MCP servers, skills, and plugins through AWS Labs in 2025, and now calls Agent Toolkit their successor. The older awslabs/mcp project remains available and accepts contributions while selected work moves over. That makes the toolkit the sensible starting point, especially for agent-aware IAM conditions and central audit records. It does not mean every specialized Labs server has an equivalent bundle here today.
Adopt it one permission slice at a time. Start with 1 read-only account role, confirm the CloudTrail identity, then authorize narrow changes with a person reviewing the plan. The toolkit makes that progression possible across several coding agents. Its value disappears if the first setup step attaches broad credentials and treats an audit log as permission to let the model do anything.
