Skip to content

aws/aws-startup-advisor

v2.0.3Apache-2.0

Personalized AWS guidance built on patterns from 350,000+ startups—architecture, cost, security, and migration, from day-one account setup to production-ready infrastructure. Migrate to AWS from GCP or Heroku—including your entire AI stack: OpenAI/Gemini/Anthropic SDK rewrites to Amazon Bedrock, agentic systems (LangChain, CrewAI, AutoGen) to AWS-native runtimes, and Temporal workers. Operate what you run with AWS DevOps Agent—incident investigation and release-readiness review, with the cost shown before anything is enabled. Includes AWS Activate credits eligibility and 60+ exclusive startup offers. Built by AWS Startup Solutions Architects, with multi-account, multi-region support.

aws-startup-advisor

Overview

This plugin brings AWS Startups expertise directly into your coding assistant. Its skills encode the patterns AWS Startup Solutions Architects use with founders every day — stage-aware architecture advice, credit-conscious cost planning, and phased migrations onto AWS — so your agent gives startup-appropriate answers instead of enterprise-sized ones. Currently, skills are provided to assist with the following capability areas:

  • Startup Architecture Advice — Recommend and review AWS architectures against a company's stage (pre-revenue through Series B+), team size, runway, and available credits, including preparing an architecture for a fundraise or technical diligence.
  • Guided Building — Run an interactive discovery flow (intent, scope, constraints, preferences), scan what the codebase already implies, then write an AWS architectural scaffold and implementation into the project.
  • AI Agent Runtimes — Choose a runtime for an agentic workload (Amazon Bedrock AgentCore, Amazon ECS, Amazon EKS, AWS Lambda), plan a migration for agents already running elsewhere, and build an executable proof of concept.
  • Cloud Migration — Migrate from Microsoft Azure, Google Cloud Platform, or Heroku to AWS through a phased flow: discover, clarify, design, estimate, generate artifacts, and collect feedback.
  • AI Stack Migration — Rewrite OpenAI, Gemini, or Anthropic API call sites to Amazon Bedrock, evaluate output quality against a golden prompt set, and deliver a ready-to-review git branch.
  • Operating on AWS — Investigate incidents, find root cause, and review pull requests for release readiness with AWS DevOps Agent, with the cost, account access, and code handling each confirmed before anything is enabled.
  • Terraform Quality Gate — Apply AWS Terraform authoring posture and a security baseline while generating a terraform/ directory, then run a read-only policy verdict over what was written.
  • Startup Reference Content — Answer factual questions about AWS Activate, credits, programs, and partner offers, and serve AWS-curated learn articles, sample architectures, and copy-paste prompts for AI coding agents.

Agent Skills

#SkillDescriptionDocumentation
1architect-for-startupsStage-aware AWS architecture guidance and reviews tuned to team size, runway, and credits — advice rather than code changesSKILL.md
2start-building-for-startupsInteractive discovery flow that gathers requirements, scans the codebase, then writes an AWS scaffold and implementation into the projectSKILL.md
3agent-advisorRuntime selection, migration planning, and an executable proof of concept for AI-agent workloads on AWSSKILL.md
4azure-to-awsSix-phase Microsoft Azure to AWS migration. Discovery reads Terraform (azurerm_*), a live az CLI capture (read-only, consent-gated), application code, and billing exports — not Bicep or ARM templates. Generate is opt-in, and the what-if workshop is optionalSKILL.md
5gcp-to-awsSix-phase Google Cloud to AWS migration: discover, clarify, design, estimate, generate artifacts, feedbackSKILL.md
6heroku-to-awsSix-phase Heroku to AWS migration with deterministic add-on mapping and an optional what-if repricing workshopSKILL.md
7llm-to-bedrockRewrite OpenAI, Gemini, or Anthropic API call sites to Amazon Bedrock, evaluate quality, and deliver a git branch. Requires gcp-to-aws installed alongside itSKILL.md
8tf-best-practicesAWS Terraform authoring posture, security-baseline spec, and a read-only policy gate over generated TerraformSKILL.md
9operate-on-awsIncident investigation, root-cause analysis, and release-readiness review with AWS DevOps Agent, behind cost, access, and code-egress gatesSKILL.md
10knowledge-base-for-startupsAWS Activate FAQ, credits guide, programs, partner offers, sample architectures, and AWS-curated learn articlesSKILL.md
11prompt-library-for-startupsAWS-curated copy-paste prompts for AI coding agents, plus downloadable installable agentsSKILL.md
12contextual-offers-for-startupsAppends at most one relevant AWS Activate partner offer as optional context after another skill's output is finalSKILL.md

contextual-offers-for-startups is consulted by the other skills rather than invoked directly: it runs only after a recommendation, plan, or build is already final, and it never influences the technical advice.

Bundled Resources

Alongside the skills, the plugin ships supporting material the skills load on demand:

  • skills/shared/ — Canonical reference material shared across skills rather than an invocable skill of its own: the phase-workflow interpreter contract, estimation schemas and complexity tiers, a snapshot of AWS infrastructure rates, phase-status schema, what-if workshop invariants, shared Clarify question fragments, and the AI-migration guardrails and Bedrock model references. Each consuming skill carries a byte-identical copy under its own references/vendored/ so the skill folder stays self-contained.
  • agents/ — Seven Claude Code subagent definitions: two generic, phase-agnostic migration phase workers (read/write and read/write/shell tiers) plus five specialists for the Bedrock rewrite flow (code analyzer, code rewriter, log ingestor, prompt evaluator, report generator).
  • scripts/ — Three Python helpers that validate generated artifacts and emit run summaries: a migration report validator, a startup-program artifact check, and a plan summary emitter. The Heroku flow's report validator ships inside skills/heroku-to-aws/scripts/.
  • fixtures/ — Reference and regression fixtures for the migration report and estimation artifacts, used to keep generated output within the documented contract. fixtures/azure-iac-terraform/ additionally carries deterministic asserters that pin the Azure Discover, Clarify, Design, and Estimate contracts against a committed synthetic estate.

MCP Servers

#ServerDescription
1aws-mcpAWS API access, documentation search, regional availability, and skill retrieval via AWS MCP Server

aws-mcp is a single stdio server launched through uvx mcp-proxy-for-aws-cli@latest. The skills use it for aws___search_documentation and aws___read_documentation (current AWS documentation), aws___get_regional_availability and aws___list_regions (service availability per region), aws___call_aws (authenticated AWS API calls), aws___run_script (sandboxed Python), and aws___retrieve_skill and aws___recommend (on-demand guidance). No other MCP server is required.

Installation

In Claude Code, install from this repository's marketplace:

/plugin marketplace add aws/agent-toolkit-for-aws
/plugin install aws-startup-advisor@agent-toolkit-for-aws
/reload-plugins

For Codex and Cursor, see Quick start.

For standalone skill installs — Kiro, fx, and other hosts that consume skills directly — point the skills CLI at this plugin. The repository's top-level skills/ tree does not contain these skills, so the command in Quick start will not install them:

npx skills add aws/agent-toolkit-for-aws/plugins/aws-startup-advisor/skills --skill '*'

Install all 12 skills together rather than a subset: agent-advisor delegates to gcp-to-aws, and the migration skills share vendored fragments. A standalone install covers the skills only — it does not configure the aws-mcp server declared in .mcp.json, which the host needs separately.

Startup Architecture Advice

The architect-for-startups skill answers "what should we build on AWS?" the way a Startup Solutions Architect would: it establishes the company's stage, team size, runway, and credit position first, then recommends the smallest architecture that clears the bar, and names what to revisit at the next stage.

How It Works

  • Stage-aware defaults — Recommendations differ for a pre-revenue prototype and a Series B workload with paying customers; the skill asks before it assumes.
  • Cost and credit awareness — Options are framed in terms of run-rate and credit burn, so the architecture stretches AWS Activate credits rather than consuming them in a month.
  • Reviews and diligence — Existing architectures can be reviewed for a fundraise or technical diligence conversation, with gaps ranked by what an investor or acquirer will ask about.
  • Advice, not edits — This skill recommends and reviews. When you want the architecture written into the repository, it hands off to start-building-for-startups.

Examples

  • "We're pre-seed with two engineers — what should our AWS architecture look like?"
  • "Review our architecture before our Series A technical diligence"
  • "How do we make our Activate credits last another six months?"
  • "Is Aurora Serverless the right call at our stage?"

Guided Building

The start-building-for-startups skill runs a structured discovery flow and then writes code. It gathers intent, scope, constraints, and preferences through picker-based questions, infers what it can from the existing codebase, and produces an AWS architectural scaffold and implementation in the project.

Examples

  • "Help me build the backend for our new app on AWS"
  • "Scaffold an AWS project for a multi-tenant SaaS MVP"
  • "Expand our existing service to add async processing"
  • "Refactor this app onto managed AWS services"

AI Agent Runtimes

The agent-advisor skill is the entry point for agentic work on AWS. It covers runtime selection, migration planning for agents already running elsewhere, and building an executable proof of concept, as one phased flow.

How It Works

  • Runtime selection — Compares Amazon Bedrock AgentCore, Amazon ECS, Amazon EKS, and AWS Lambda against the workload's latency, session, tool-calling, and operational requirements.
  • Migration planning — Plans a move for existing agent workloads, including adding AgentCore capabilities (memory, gateway, identity, policy, observability) to an agent that already runs on AWS.
  • Durable execution — Covers running Temporal workers on AWS and the Temporal Cloud versus self-hosted decision. Temporal workflow code is not rewritten into another orchestrator.
  • Proof of concept — Produces a runnable POC rather than a slide-level recommendation.

The skill requires at least one agentic component. Non-agent compute or data migrations route to azure-to-aws, gcp-to-aws, or heroku-to-aws, and a pure LLM SDK rewrite routes to llm-to-bedrock.

Examples

  • "Which runtime should I use for my agent — AgentCore, ECS, EKS, or Lambda?"
  • "Move our LangGraph agents to AWS"
  • "Add memory and a gateway to the agent we already run on ECS"
  • "We orchestrate with Temporal — how does that run on AWS?"

Cloud Migration

The azure-to-aws, gcp-to-aws, and heroku-to-aws skills run the same six-phase flow: discover, clarify, design, estimate, generate, and feedback. Clarify must finish before design, estimate, or generate, so the plan is never built on unstated assumptions. Generate runs only after you choose to produce the artifacts at the post-estimate decision gate. The what-if workshop is optional and sits beside estimate; it is not an extra phase.

How It Works

  • Discover — azure-to-aws and gcp-to-aws read Terraform files, application code, and billing exports. heroku-to-aws can additionally discover live through the authenticated Heroku CLI (read-only and consent-gated) or from Procfile and app.json.
  • Clarify — Resolves the requirements that change the target architecture: availability, compliance, data residency, cutover tolerance, and team capacity.
  • Design — Maps source resources to AWS services using deterministic mapping tables — for example Heroku dynos to AWS Elastic Beanstalk, Heroku Postgres to Amazon RDS or Aurora, Heroku Redis to Amazon ElastiCache, Heroku Kafka to Amazon MSK, Cloud SQL to Amazon RDS, GKE to Amazon EKS, Cloud Run to AWS Fargate, Azure App Service to AWS Elastic Beanstalk, AKS to Amazon EKS, Azure SQL to Amazon RDS, and Cosmos DB to Amazon DynamoDB or DocumentDB.
  • Estimate — Costs the target architecture from the plugin's bundled rate reference data and a documented cost algorithm, with an estimation schema and complexity tiers so two runs of the same workload agree. Estimates are planning figures; confirm them against the AWS Pricing Calculator before committing budget.
  • Generate — Emits migration artifacts, including Terraform, gated by the tf-best-practices policy check and a validated migration report. On the infrastructure route, heroku-to-aws, gcp-to-aws, and azure-to-aws also emit baseline.tf — an account-wide security baseline (GuardDuty, CloudTrail, IMDSv2, EBS encryption, budget alerts) — with AWS Config and Security Hub controls added when the declared compliance set includes SOC 2, PCI, HIPAA, or FedRAMP. gcp-to-aws's AI-only and billing-only routes emit monitoring or skeleton Terraform instead and skip the baseline.
  • Workshop mode — After estimate, azure-to-aws, gcp-to-aws, and heroku-to-aws can reprice region, high-availability, compute, and AWS Graviton scenarios without repeating discovery.

Examples

  • "Migrate us off Heroku to AWS"
  • "Move our Azure estate to AWS — map AKS onto EKS"
  • "We want to move from GCP — what would this cost on AWS?"
  • "Map our Cloud Run services onto Fargate"
  • "Reprice the migration with Graviton in us-west-2"

AI Stack Migration

The llm-to-bedrock skill is a focused model and SDK rewrite. It assesses the codebase, rewrites OpenAI, Gemini, or Anthropic API call sites to Amazon Bedrock, evaluates the rewritten behavior against a golden prompt set, and delivers a ready-to-review git branch with a migration report.

Requires gcp-to-aws installed alongside it. llm-to-bedrock delegates its assess phase to the gcp-to-aws skill and has no standalone fallback — installing llm-to-bedrock on its own stops at the first step. Install both together:

npx skills add aws/agent-toolkit-for-aws/plugins/aws-startup-advisor/skills --skill llm-to-bedrock --skill gcp-to-aws

(The --skill '*' install above already includes both.)

Model mapping is compatibility-guided rather than one-to-one parity. Validate prompts, tool-calling behavior, and evaluation metrics before cutover.

Examples

  • "Migrate our OpenAI calls to Bedrock"
  • "Move off the Gemini API to Amazon Bedrock"
  • "Which Bedrock model is closest to what we use today?"
  • "Score our prompts against Bedrock before we switch"

Startup Reference Content

Two skills serve AWS-curated content rather than performing work on your account:

  • knowledge-base-for-startups — AWS Activate FAQ, credits guide, programs, partner offers, sample architectures, and learn articles spanning generative AI, cloud architecture, cost optimization, security, fundraising, and go-to-market. Answers come from the bundled references/ tree.
  • prompt-library-for-startups — Copy-paste prompts for AI coding agents (MVP scaffolding, RAG chatbot on Amazon Bedrock, security baseline evaluation, cost anomaly detection, GPU quota requests, Amazon EKS deployment, Well-Architected review) plus downloadable installable agents.

Neither skill can look up account-specific state such as your credits balance, Activate membership, or application status. Those questions belong at AWS Startups.

Examples

  • "Am I eligible for AWS Activate credits?"
  • "Show me a sample architecture for a RAG application"
  • "Give me a prompt to set up a security baseline"
  • "Which Activate provider credits apply to us?"

Operating on AWS

The operate-on-aws skill connects a startup with no dedicated DevOps or SRE engineer to AWS DevOps Agent, which investigates incidents autonomously, finds probable root cause, and reviews pull requests before they ship. DevOps Agent is metered, so the skill treats consent as the core of the workflow.

How It Works

  • Detect first — Checks for an existing DevOps Agent connection and goes straight to work if there is one. Someone already set up is never walked through setup again.
  • Recommend only when it fits — Looks for evidence of a live workload or active pull requests, and recommends nothing to a team with neither. If credit runway is short, it recommends against setup and points to the free alternative.
  • Three separate gates — Cost and credit impact, read access to the AWS account, and (for release review) copying source code out of the account are each confirmed on their own. Automated verification testing defaults to off.
  • Propose, never apply — Findings and proposed fixes are shown for approval; nothing is changed in the account without an explicit decision.

The DevOps Agent MCP server is region-specific and per-user, so the skill registers it during setup rather than the plugin declaring it. If the aws-agents-for-devsecops plugin is already installed, the skill reuses its aws-devops-agent connection instead of creating a second one, and still runs its own cost and consent gates on top.

Examples

  • "Our API has been returning 502s since the last deploy — what broke?"
  • "Is this PR safe to merge?"
  • "Set up AWS DevOps Agent for us — what will it cost?"
  • "Pause DevOps Agent, we're burning credits"

Supported Environments

Using the plugin in your local compute

In your local environment, configure AWS credentials and set your target region to get started.

Prerequisites

  • An AWS account
  • Local AWS credentials and config
  • uv (for MCP server)
  • Python 3 (for the bundled validation scripts)
  • Git (the llm-to-bedrock flow delivers its rewrite on a branch)
  • The Heroku CLI, authenticated, only if you want live discovery in heroku-to-aws
  • Terraform, only if you want to run fmt, init, or validate over generated Terraform

Authentication and Authorization

Configure AWS credentials using one of the following methods:

Documentation search, regional availability lookups, and the reference-content skills need no AWS credentials. Credentials are needed when a skill inspects or provisions resources in your account. The relevant IAM action namespaces are:

  • sts - Caller identity and account context checks
  • bedrock, bedrock-runtime - Model availability and prompt evaluation for the Bedrock migration flow
  • ec2, rds, s3 - Read-only discovery of existing compute, database, and storage resources
  • iam - Reviewing roles and policies referenced by a design or security baseline
  • cloudformation - Inspecting and deploying generated infrastructure

Start with read-only credentials for discovery, advice, and estimation, and scope write permissions to the resources your workload actually uses.

Configuration

Customizing Skills for Your Organization

The skills in this plugin follow AWS best practices, but they are fully customizable. You can fork the repository and modify any SKILL.md to reflect your organization's standards, naming conventions, approved services, or internal tooling. Workspace-level skills take precedence over global skills, so teams can maintain their own versions without affecting other users.

Related Resources

License

This project is licensed under the Apache 2.0 License.