aws-well-architected-reviewlisted
Install: claude install-skill sandbaseai/workbuddy-skill
# AWS Well-Architected Review
## Purpose and boundary
Perform a structured review of an AWS workload against the six Well-Architected pillars:
operational excellence, security, reliability, performance efficiency, cost optimization, and
sustainability. Combine repository/IaC evidence with authorized read-only live evidence; do not
pretend that a static template proves deployed state.
The default deliverable is a report and remediation backlog in an authorized documentation path.
Do not create GitHub Issues, change IaC, call mutating AWS APIs, alter budgets/alarms, or deploy
fixes unless the user separately authorizes that exact side effect. Never include credentials,
secret values, customer data, or unrestricted policy documents in findings.
## Review contract
Define before inspection:
- workload, account, regions, environments, revision, and review date;
- IaC sources and live resource scope, including systems deliberately excluded;
- relevant AWS Framework version, lenses, regulatory or business constraints;
- evidence permissions, sensitive-data handling, and intended audience;
- risk scale, owner, remediation deadline, and whether backlog publication is authorized.
Label every statement as **observed**, **derived**, **inferred**, or **unknown**. A missing live
permission or absent IaC file is a coverage gap, not evidence that the control is absent.
## Step 1: load current references and discover the workload
Use the current AWS Well-Architected Framework and rele