AWS Builder Center
I Ran AWS's New Well-Architected Skills on a Real Client — Here's What Happened in 60 Seconds

I Ran AWS's New Well-Architected Skills on a Real Client — Here's What Happened in 60 Seconds

AWS released open-source skills that teach AI agents to apply the Well-Architected Framework. I installed them and ran a security assessment on a real production account — 3 critical findings in 60 seconds. Here's what happened, what it caught that I might have missed, and how I'm using it in my weekly client assessments going forward.

AWS Golden Jacket | Kiro Ambassador 🟣 | Founder & Global Lead — Golden Jackets
Skills That Teach Your AI Agent the Entire Framework
AWS released an open-source repository with 8 reusable skills that teach AI coding agents how to apply the Well-Architected Framework. Not as a chatbot answering "use Multi-AZ" — as
structured playbooks that systematically evaluate real infrastructure.
What's inside:
SkillWhat it does
wa-reviewFull review across all 6 pillars
security-assessmentDeep-dive security posture
cost-optimization-auditWaste, rightsizing, pricing models
reliability-improvement-planSPOFs, recovery, scaling
performance-efficiencyResource selection, caching
sustainability-optimizationCarbon footprint, utilization
migration-readiness7 Rs with migration plan
architecture-decision-recordWA-aligned ADRs
They work with Kiro, Claude Code, Cursor, Codex, Windsurf, GitHub Copilot, and Cline. MIT-0 license — no restrictions.
Installation is one command:
bash
git clone https://github.com/aws-samples/sample-well-architected-skills-and-steering.git
./install.sh --global --tool kiro
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

What I Did: Security Assessment on a Production Account

I installed the skills and immediately pointed them at a real client's production account — a financial services company with 26 AWS accounts, EKS clusters, RDS databases, and a Control
Tower implementation.
The security-assessment skill follows a structured playbook:
  1. Identity & Access Management — IAM policies, MFA, access keys, federation
  2. Detection & Monitoring — GuardDuty, Security Hub, CloudTrail, Config
  3. Infrastructure Protection — Security groups, NACLs, public endpoints, WAF
  4. Data Protection — Encryption at rest/transit, secrets management, backups
  5. Incident Response — Automation, forensics, runbooks
I didn't tell the agent "check if GuardDuty is on." I said: "Run a security assessment on this account." The skill handled the structure. The agent handled the execution.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

The Results: 60 Seconds, 5 Findings I Would Have Missed

Here's what came back:

Security Scorecard

DomainScoreKey Finding
Identity & Access3/5Root account without MFA
Detection1/5GuardDuty disabled, Security Hub not subscribed
Infrastructure Protection2/510+ security groups with 0.0.0.0/0 ingress
Data Protection3/538 EBS volumes without encryption at rest
Incident Response1/5No automated remediation identified
3 Critical findings. 2 Medium. In 60 seconds.
The kicker? This is a client with an active Control Tower implementation, 23 custom SCPs, and a dedicated security account. They're not negligent — they're a regulated financial
institution that takes security seriously. But gaps accumulate silently when you don't have systematic coverage.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

What the Skill Caught That I Might Have Missed

GuardDuty disabled in the production account. The client has GuardDuty in their security account, but the production account — where the actual workloads run — had no detector. Without the
skill's systematic check across all detection services, I might have assumed "they have GuardDuty" based on the security account alone.
38 unencrypted EBS volumes. In a sea of 200+ volumes, most were encrypted. But 38 slipped through — likely created before the encryption-by-default SCP was applied. The skill doesn't
sample. It checks everything.
Security groups from launch-wizard. The presence of launch-wizard-1 security groups in production tells a story: someone created resources manually via the console. In an environment that
mandates Terraform via SCP. The skill flagged it; I would have scrolled past it.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

The Difference: Consistency, Not Intelligence

I want to be clear: these skills don't make the AI smarter than a senior architect. They make it more consistent.
A senior architect on a good day, with enough coffee, will catch everything these skills catch. But:
  • On a bad day? You'll skip the sustainability pillar.
  • On a rushed assessment? You'll check IAM but forget to verify VPC Flow Logs.
  • On your 5th client this month? You'll miss the launch-wizard security group because you've seen 500 security groups today.
The skill never has a bad day. It never skips a step. It never gets tired.
Human ArchitectAI + WA Skills
Depth of analysisDeeper (contextual)Shallower (systematic)
ConsistencyVariable100% every time
Speed2-3 daysMinutes
CoverageDepends on memoryAll checks, every time
Best used asFinal validationFirst pass + structure
The winning combination: AI does the first pass with perfect coverage. Human does the deep analysis on what it finds.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

How I'm Using This Going Forward

I'm a TAM (Technical Account Manager) at an AWS partner. I do assessments weekly. Here's my new workflow:
  1. Install skills globally (done — one time)
  2. First pass: Ask the agent to run the relevant skill against the client's account
  3. Review findings: Validate, add context, remove false positives
  4. Deep dive: Focus human time on the critical findings, not on checking if CloudTrail is enabled
  5. Generate report: Structured output feeds directly into our client-facing documents
Time saved per assessment: 60-70%. Not because the AI does everything — because it does the tedious systematic checks that eat most of the time.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

What These Skills Are NOT

Let me save you some disappointment:
  • ❌ They don't replace a Well-Architected Review with an AWS SA
  • ❌ They don't understand your business context
  • ❌ They don't make architectural decisions for you
  • ❌ They don't execute remediation
They ARE:
  • ✅ A structured first pass that catches what humans forget
  • ✅ A consistency guarantee across assessments
  • ✅ A time-saver that lets you focus on what matters
  • ✅ A teaching tool for junior architects learning the framework
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Getting Started

bash
git clone https://github.com/aws-samples/sample-well-architected-skills-and-steering.git
cd sample-well-architected-skills-and-steering

For Kiro

./install.sh --global --tool kiro

For Claude Code

./install.sh --global --tool claude-code

For Cursor

./install.sh --global --tool cursor

For all tools

./install.sh --global --tool all
Then just ask your agent: "Run a security assessment on this AWS account" — and watch it follow the playbook.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

The Bigger Picture

AWS is doing something interesting here. They're not just documenting best practices anymore — they're making them executable. The Well-Architected Framework went from PDF → to Tool (WA
Tool in console) → to Skills (embedded in your development workflow).
The next logical step? These skills running automatically on every terraform apply, every PR, every deployment. Not as a gate — as a guide.
We're not there yet. But we're closer than we were last week.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Ricardo Gulias is a TAM, AWS Golden Jacket holder (12x certified), and Founder of Golden Jackets — a global community of professionals who earned all active AWS certifications.
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article