Source profileQuality 92/100

awslabs/agent-plugins/plugins/aws-serverless/skills/aws-lambda/SKILL.md

aws-lambda

Design, build, deploy, test, and debug serverless applications with AWS Lambda. Triggers on phrases like: Lambda function, event source, serverless application, API Gateway, EventBridge, Step Functions, serverless API, event-driven architecture, Lambda trigger. For deploying non-serverless apps to AWS, use deploy-on-aws plugin instead.

Source repository stars
868
Declared platforms
0
Static risk flags
1
Last source update
2026-08-25
Source checked
2026-08-25

Decision brief

What it does: where it fits

Design, build, deploy, and debug serverless applications with AWS serverless services. This skill provides access to serverless development guidance through the AWS Serverless MCP Server, helping you to build production-ready serverless applications with best practices built-in.

Best for

    Not for

    • For detailed troubleshooting, see references/troubleshooting.md.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/awslabs/agent-plugins --skill "plugins/aws-serverless/skills/aws-lambda"
    Safe inspection promptEditorial

    Inspect the Agent Skill "aws-lambda" from https://github.com/awslabs/agent-plugins/blob/a35c295c62452468446d3a3fa7e2590cd27474ab/plugins/aws-serverless/skills/aws-lambda/SKILL.md at commit a35c295c62452468446d3a3fa7e2590cd27474ab. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Project Setup

      Do: Use saminit or cdk init with an appropriate template for your use case

      Do: Use saminit or cdk init with an appropriate template for your use caseDo: Set global defaults for timeout, memory, runtime, and tracing (Globals in SAM, construct props in CDK)Do: Use AWS Lambda Powertools for structured logging, tracing, metrics (EMF), idempotency, and batch processing — available for Python, TypeScript, Java, and .NET
    2. 02

      AWS CLI Setup

      This skill requires that AWS credentials are configured on the host machine:

      This skill requires that AWS credentials are configured on the host machine:Verify access: Run aws sts get-caller-identity to confirm credentials are valid
    3. 03

      SAM CLI Setup

      1. Install SAM CLI: Follow the SAM CLI installation guide 2. Verify: Run sam --version

      Install SAM CLI: Follow the SAM CLI installation guideVerify: Run sam --version1. Install SAM CLI: Follow the SAM CLI installation guide 2. Verify: Run sam --version
    4. 04

      Container Runtime Setup

      1. Install a Docker compatible container runtime: Required for samlocalinvoke and container-based builds 2. Verify: Use an appropriate command such as docker --version or finch --version

      Install a Docker compatible container runtime: Required for samlocalinvoke and container-based buildsVerify: Use an appropriate command such as docker --version or finch --version1. Install a Docker compatible container runtime: Required for samlocalinvoke and container-based builds 2. Verify: Use an appropriate command such as docker --version or finch --version
    5. 05

      When to Load Reference Files

      Load the appropriate reference file based on what the user is working on:

      Getting started, what to build, project type decision, or working with existing projects - see references/getting-started.mdSAM, CDK, deployment, IaC templates, CDK constructs, or CI/CD pipelines - see the aws-serverless-deployment skill (separate skill in this plugin)Web app deployment, Lambda Web Adapter, API endpoints, CORS, authentication, custom domains, or sam local start-api - see references/web-app-deployment.md

    Permission review

    Static risk signals and limitations

    Reads files

    low · line 21

    The documentation asks the agent to read local files, directories, or repositories.

    Load the appropriate reference file based on what the user is working on:

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score92/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars868SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    awslabs/agent-plugins
    Skill path
    plugins/aws-serverless/skills/aws-lambda/SKILL.md
    Commit
    a35c295c62452468446d3a3fa7e2590cd27474ab
    License
    Apache-2.0
    Collected
    2026-08-25
    Default branch
    main
    View the original SKILL.md

    AWS Lambda Serverless Development

    Design, build, deploy, and debug serverless applications with AWS serverless services. This skill provides access to serverless development guidance through the AWS Serverless MCP Server, helping you to build production-ready serverless applications with best practices built-in.

    Use SAM CLI for project initialization and deployment, Lambda Web Adapter for web applications, or Event Source Mappings for event-driven architectures. AWS handles infrastructure provisioning, scaling, and monitoring automatically.

    Key capabilities:

    • SAM CLI Integration: Initialize, build, deploy, and test serverless applications
    • Web Application Deployment: Deploy full-stack applications with Lambda Web Adapter
    • Event Source Mappings: Configure Lambda triggers for DynamoDB, Kinesis, SQS, Kafka
    • Lambda durable functions: Resilient multi-step applications with checkpointing — see the durable-functions skill for guidance
    • Lambda Managed Instances: Run Lambda on dedicated EC2 instances with managed lifecycle — see the managed-instances skill for evaluation, configuration, and migration guidance
    • Schema Management: Type-safe EventBridge integration with schema registry
    • Observability: CloudWatch logs, metrics, and X-Ray tracing
    • Performance Optimization: Right-sizing, cost optimization, and troubleshooting

    When to Load Reference Files

    Load the appropriate reference file based on what the user is working on:

    • Getting started, what to build, project type decision, or working with existing projects -> see references/getting-started.md
    • SAM, CDK, deployment, IaC templates, CDK constructs, or CI/CD pipelines -> see the aws-serverless-deployment skill (separate skill in this plugin)
    • Web app deployment, Lambda Web Adapter, API endpoints, CORS, authentication, custom domains, or sam local start-api -> see references/web-app-deployment.md
    • Event sources, DynamoDB Streams, Kinesis, SQS, Kafka, S3 notifications, or SNS -> see references/event-sources.md
    • EventBridge, event bus, event patterns, event design, Pipes, or schema registry -> see references/event-driven-architecture.md
    • Durable functions, checkpointing, replay model, saga pattern, or long-running Lambda workflows -> see the durable-functions skill (separate skill in this plugin with full SDK reference, testing, and deployment guides)
    • Lambda Managed Instances, LMI, capacity providers, multi-concurrency, EC2-backed Lambda, cold start elimination, or Lambda cost optimization with Reserved Instances -> see the managed-instances skill (separate skill in this plugin for evaluation, configuration, and migration)
    • Orchestration, workflows, or Durable Functions vs Step Functions -> see references/orchestration-and-workflows.md
    • Step Functions, ASL, state machines, JSONata, Distributed Map, SDK integrations, TestState API, mocking service integrations, or state machine unit tests -> see the aws-step-functions skill for comprehensive guidance
    • Observability, logging, tracing, metrics, alarms, or dashboards -> see references/observability.md
    • Optimization, cold starts, memory tuning, cost, or streaming -> see references/optimization.md
    • Powertools, idempotency, feature flags, parameters, parser, batch processing, or data masking -> see references/powertools.md
    • Troubleshooting, errors, debugging, or deployment failures -> see references/troubleshooting.md

    Best Practices

    Project Setup

    • Do: Use sam_init or cdk init with an appropriate template for your use case
    • Do: Set global defaults for timeout, memory, runtime, and tracing (Globals in SAM, construct props in CDK)
    • Do: Use AWS Lambda Powertools for structured logging, tracing, metrics (EMF), idempotency, and batch processing — available for Python, TypeScript, Java, and .NET
    • Don't: Copy-paste templates from the internet without understanding the resource configuration
    • Don't: Use the same memory and timeout values for all functions regardless of workload

    Security

    • Do: Follow least-privilege IAM policies scoped to specific resources and actions
    • Do: Use secure_esm_* tools to generate correct IAM policies for event source mappings
    • Do: Store secrets in AWS Secrets Manager or SSM Parameter Store, never in environment variables
    • Do: Use VPC endpoints instead of NAT Gateways for AWS service access when possible
    • Do: Enable Amazon GuardDuty Lambda Protection to monitor function network activity for threats (cryptocurrency mining, data exfiltration, C2 callbacks)
    • Don't: Use wildcard (*) resource ARNs or actions in IAM policies
    • Don't: Hardcode credentials or secrets in application code or templates
    • Don't: Store user data or sensitive information in module-level variables — execution environments can be reused across different callers

    Idempotency

    • Do: Write idempotent function code — Lambda delivers events at least once, so duplicate invocations must be safe
    • Do: Use the AWS Lambda Powertools Idempotency utility (backed by DynamoDB) for critical operations
    • Do: Validate and deduplicate events at the start of the handler before performing side effects
    • Don't: Assume an event will only ever be processed once

    For topic-specific best practices, see the dedicated guide files in the reference table above.

    Lambda Limits Quick Reference

    Limits that developers commonly hit:

    ResourceLimit
    Function timeout900 seconds (15 minutes)
    Memory128 MB – 10,240 MB
    1 vCPU equivalent1,769 MB memory
    Synchronous payload (request + response)6 MB each
    Async invocation payload1 MB
    Streamed response200 MB
    Deployment package (.zip, uncompressed)250 MB
    Deployment package (.zip upload, compressed)50 MB
    Container image10 GB
    Layers per function5
    Environment variables (aggregate)4 KB
    /tmp ephemeral storage512 MB – 10,240 MB
    Account concurrent executions (default)1,000 (requestable increase)
    Burst scaling rate1,000 new executions per 10 seconds

    Check Service Quotas for your account limits: aws lambda get-account-settings

    Troubleshooting Quick Reference

    ErrorCauseSolution
    Build FailedMissing dependenciesRun sam_build with use_container: true
    Stack is in ROLLBACK_COMPLETEPrevious deploy failedDelete stack with aws cloudformation delete-stack, redeploy
    IteratorAge increasingStream consumer falling behindIncrease ParallelizationFactor and BatchSize. Use esm_optimize
    EventBridge events silently droppedNo DLQ, retries exhaustedAdd RetryPolicy + DeadLetterConfig to rule target
    Step Functions failing silentlyNo retry on Task stateAdd Retry with Lambda.ServiceException, Lambda.AWSLambdaException
    Durable Function not resumingMissing IAM permissionsAdd lambda:CheckpointDurableExecution and lambda:GetDurableExecutionState — see durable-functions skill

    For detailed troubleshooting, see references/troubleshooting.md.

    Configuration

    AWS CLI Setup

    This skill requires that AWS credentials are configured on the host machine:

    Verify access: Run aws sts get-caller-identity to confirm credentials are valid

    SAM CLI Setup

    1. Install SAM CLI: Follow the SAM CLI installation guide
    2. Verify: Run sam --version

    Container Runtime Setup

    1. Install a Docker compatible container runtime: Required for sam_local_invoke and container-based builds
    2. Verify: Use an appropriate command such as docker --version or finch --version

    MCP Server Configuration

    Write access is enabled by default. The plugin ships with --allow-write in .mcp.json, so the MCP server can create projects, generate IaC, and deploy on behalf of the user.

    Access to sensitive data (like Lambda and API Gateway logs) is not enabled by default. To grant it, add --allow-sensitive-data-access to .mcp.json.

    SAM Template Validation Hook

    This plugin includes a PostToolUse hook that runs sam validate automatically after any edit to template.yaml or template.yml. If validation fails, the error is returned as a system message so you can fix it immediately. The hook requires SAM CLI and jq to be installed; if either is missing, validation is skipped with a system message. Users can disable it via /hooks.

    Verify: Run jq --version

    Language selection

    Default: TypeScript

    Override syntax:

    • "use Python" → Generate Python code
    • "use JavaScript" → Generate JavaScript code

    When not specified, ALWAYS use TypeScript

    IaC framework selection

    Default: CDK

    Override syntax:

    • "use CloudFormation" → Generate YAML templates
    • "use SAM" → Generate YAML templates

    When not specified, ALWAYS use CDK

    Serverless MCP Server Unavailable

    • Inform user: "AWS Serverless MCP not responding"
    • Ask: "Proceed without MCP support?"
    • DO NOT continue without user confirmation

    Resources

    Frequently asked questions

    What to verify before installation and use

    What does the aws-lambda source document cover?

    Design, build, deploy, and debug serverless applications with AWS serverless services. This skill provides access to serverless development guidance through the AWS Serverless MCP Server, helping you to build production-ready serverless applications with best practices built-in.

    How do I install aws-lambda?

    The source record exposes this install command: npx skills add https://github.com/awslabs/agent-plugins --skill "plugins/aws-serverless/skills/aws-lambda". Inspect the command and pinned source before running it.

    Which permission-related actions were detected?

    Static rules flagged read-files in the source; the page lists the matching lines and excerpts.

    Alternatives

    Compare before choosing

    Computed 9980

    vasilyu1983/AI-Agents-public

    qa-testing-ios

    Guides iOS testing with XCTest, XCUITest, Swift Testing, simctl, and xcresult. Use when choosing destinations, controlling flakes, or parsing test artifacts for native apps.

    Computed 97183

    microsoft/Sico

    android-tester

    Execute Android UI workflows on a sandbox device, review results, and produce a structured execution report.

    Computed 9639

    objectstack-ai/objectstack

    objectstack-platform

    Bootstrap, configure, extend, and operate ObjectStack runtimes. Covers project setup (`defineStack`, drivers, adapters, scaffolding), plugin and service development (PluginContext, DI, kernel hooks like `kernel:ready`), and operations (CLI commands, migrations, deployment, test harnesses via LiteKernel). Use when the user is writing `objectstack.config.ts`, building a plugin or driver, wiring a framework adapter, running `os` CLI commands, or planning deployment. Do not use for data schema desig

    Computed 9413

    OpenDigitalProductFactory/opendigitalproductfactory

    dev-portal-start

    Use when a DPF contributor needs to verify worktree edits on the **Contributor preview** runtime (port 3001) without rebuilding the Live portal image. Triggers — making any edit under apps/web/ that needs visual or HTTP-level confirmation; iterating on /build, /platform, /admin, or any other server-rendered route; debugging a UX change against real workspace data; reproducing a customer-visible bug in a worktree before opening a PR. This is a CONTRIBUTOR-ONLY workflow; customer installs do not s