![[Update] I tried out the new ability to check for skill updates and perform batch updates for Agent Toolkit for AWS using the AWS CLI](https://devio2024-media.developers.io/image/upload/f_auto,q_auto,w_3840/f_auto,q_auto/v1790874832/eyecatch/ka0q8r1fii0ptkuwmyu2.png)
[Update] I tried out the new ability to check for skill updates and perform batch updates for Agent Toolkit for AWS using the AWS CLI
This page has been translated by machine translation. View original
This is Ishikawa from the Cloud Business Division. The check-skill-updates command for checking whether installed skills have updates all at once, and the update-skill --all command for updating outdated skills all at once, have been added to the AWS CLI Agent Toolkit for AWS commands, so I tried them out with skills installed for Kiro.
Two features for managing agent skill updates have been added to the AWS CLI Agent Toolkit for AWS commands.
aws agent-toolkit check-skill-updates: Compares all installed skills against the latest versions in the registryaws agent-toolkit update-skill --all: Updates all outdated skills with a single command
Previously, it was necessary to check each skill individually for updates and update them one by one. Even teams that have installed skills in many areas such as serverless, storage, networking, and analytics can now keep the skills referenced by their coding agents up to date.
AWS CLI 2.37.0 or later is required.
The Agent Toolkit integration features in AWS CLI (such as aws configure agent-toolkit and add-skill) themselves are introduced in the following article.
What Are the Agent Toolkit for AWS Skill Management Commands?
Agent Toolkit for AWS is a set of tools for AI coding agents to build, deploy, and operate applications on AWS. It consists of the following four components.
| Component | Description |
|---|---|
| AWS MCP Server | A managed server that provides agents with access to AWS via Model Context Protocol (MCP) |
| Agent skills | Packages that bring together procedures, scripts, and reference materials for completing specific AWS tasks |
| Plugins | Packages that install AWS MCP Server configuration and skills together for Claude Code and Codex |
| Rules files | Files that configure agent behavior policies on a per-project basis |
The aws agent-toolkit command group in AWS CLI is for installing, updating, removing, listing, and searching agent skills from the command line. Installation, updates, and removal apply to all detected agents by default. Agents are detected by the presence of a configuration directory (in Kiro's case, ~/.kiro), and you can narrow down the target with the --agent option.
The newly added commands and options are as follows. As of October 5, 2026, these were not yet documented on the AWS CLI page of the user guide, so I confirmed the specifications using the CLI help (aws agent-toolkit <command> help).
| Command | Behavior |
|---|---|
check-skill-updates |
Displays installed skills with their local version and latest version side by side. By default, only skills with available updates are shown. No file downloads or modifications are performed |
check-skill-updates --all |
Displays all installed skills, including those that are already up to date |
update-skill --all |
Updates all installed skills that are outdated. Cannot be used together with --skill-name |
The procedure I tried is as follows.
Let's Try It
Prerequisites
- AWS CLI 2.37.9 (macOS, arm64)
- Region: us-east-1
- Target agent: Kiro (
--agent kirospecified in all commands)
Skills are installed globally in each agent's configuration directory. To avoid modifying my local Kiro or other agent configurations, I validated this by temporarily pointing the HOME environment variable to a temporary directory and creating only an empty .kiro directory inside it. This is equivalent to the following state.
% export HOME=/path/to/sandbox-home
% mkdir -p ~/.kiro
Also, the skill management commands only support us-east-1. Since AWS MCP Server added support for the Tokyo region, I thought ap-northeast-1 might also be supported, but it resulted in an error.
Specifying a region other than us-east-1 results in the following error.
% aws agent-toolkit list-available-skills --region ap-northeast-1
aws: [ERROR]: AgentToolkit is only available in us-east-1
Therefore, --region us-east-1 is specified in the subsequent commands.
Installing Old Versions of Skills
To create a state requiring updates, I installed 3 skills by specifying old versions with --skill-version in add-skill. For comparison, aws-cloudformation was installed without specifying a version, so the latest version was installed.
% aws agent-toolkit add-skill --skill-name aws-cdk --skill-version v1 --agent kiro --region us-east-1
aws agent-toolkit add-skill --skill-name aws-serverless --skill-version v4 --agent kiro --region us-east-1
aws agent-toolkit add-skill --skill-name aws-iam --skill-version v1 --agent kiro --region us-east-1
aws agent-toolkit add-skill --skill-name aws-cloudformation --agent kiro --region us-east-1
Installed aws-cdk (v1) to Kiro — ~/.kiro/skills.
Installed aws-serverless (v4) to Kiro — ~/.kiro/skills.
Installed aws-iam (v1) to Kiro — ~/.kiro/skills.
Installed aws-cloudformation (v3) to Kiro — ~/.kiro/skills.
Checking the installed files, files such as SKILL.md and a file called .aws-skill-metadata were created for each skill.
% cd ~ && find .kiro -maxdepth 3 | sort
.kiro
.kiro/skills
.kiro/skills/aws-cdk
.kiro/skills/aws-cdk/.aws-skill-metadata
.kiro/skills/aws-cdk/references
.kiro/skills/aws-cdk/SKILL.md
.kiro/skills/aws-cloudformation
.kiro/skills/aws-cloudformation/.aws-skill-metadata
.kiro/skills/aws-cloudformation/references
.kiro/skills/aws-cloudformation/SKILL.md
.kiro/skills/aws-iam
.kiro/skills/aws-iam/.aws-skill-metadata
.kiro/skills/aws-iam/references
.kiro/skills/aws-iam/SKILL.md
.kiro/skills/aws-serverless
.kiro/skills/aws-serverless/.aws-skill-metadata
.kiro/skills/aws-serverless/assets
.kiro/skills/aws-serverless/references
.kiro/skills/aws-serverless/SKILL.md
.aws-skill-metadata records the installed version in JSON format.
% cd ~/.kiro/skills && for d in */; do echo "== ${d%/}/.aws-skill-metadata"; cat "${d}.aws-skill-metadata"; echo; done
== aws-cdk/.aws-skill-metadata
{"version": "v1"}
== aws-cloudformation/.aws-skill-metadata
{"version": "v3"}
== aws-iam/.aws-skill-metadata
{"version": "v1"}
== aws-serverless/.aws-skill-metadata
{"version": "v4"}
~/.kiro/skills directory
% tree -a
.
├── aws-cdk
│ ├── .aws-skill-metadata
│ ├── references
│ │ ├── bootstrap-and-project-setup.md
│ │ ├── compliance-and-drift.md
│ │ ├── construct-patterns.md
│ │ ├── import-and-migrate.md
│ │ ├── refactor-and-prevent-replacement.md
│ │ ├── troubleshooting-credentials.md
│ │ ├── troubleshooting-deployment.md
│ │ ├── troubleshooting-synth.md
│ │ └── v1-to-v2-migration.md
│ └── SKILL.md
├── aws-cloudformation
│ ├── .aws-skill-metadata
│ ├── references
│ │ ├── author-cloudformation-best-practices.script.md
│ │ ├── check-cloudformation-template-compliance.script.md
│ │ ├── cloudformation-language-server.md
│ │ ├── cloudformation-pre-deploy-validation.script.md
│ │ ├── deploy-with-express-mode.script.md
│ │ ├── lookup-resource-properties.script.md
│ │ ├── persist-template-context.script.md
│ │ ├── retrieve-template-context.script.md
│ │ ├── security-considerations.md
│ │ ├── template-safety-guidance.md
│ │ ├── troubleshoot-deployment.script.md
│ │ ├── troubleshoot-failed-stack.script.md
│ │ ├── validate-with-cfn-lint.script.md
│ │ ├── validate-with-cloudformation-validate.script.md
│ │ └── validation-tool-selection.md
│ └── SKILL.md
├── aws-iam
│ ├── .aws-skill-metadata
│ ├── references
│ │ ├── aws-iam-policy-generation.md
│ │ ├── aws-iam-role-management.md
│ │ ├── common-pitfalls.md
│ │ └── service-authorization.md
│ └── SKILL.md
└── aws-serverless
├── .aws-skill-metadata
├── assets
│ └── powertools-handler.py
├── references
│ ├── api-gateway.md
│ ├── architecture.md
│ ├── concurrency.md
│ ├── deployment.md
│ ├── event-sources.md
│ ├── lambda.md
│ ├── orchestration.md
│ ├── production.md
│ └── troubleshooting.md
└── SKILL.md
10 directories, 46 files
Checking for Skills with Updates Using check-skill-updates
I ran check-skill-updates without any options.
% aws agent-toolkit check-skill-updates --agent kiro --region us-east-1
{
"skills": [
{
"agent": "Kiro",
"name": "aws-cdk",
"path": "/path/to/sandbox-home/.kiro/skills/aws-cdk/SKILL.md",
"installedVersion": "v1",
"latestVersion": "v2",
"updateAvailable": true
},
{
"agent": "Kiro",
"name": "aws-iam",
"path": "/path/to/sandbox-home/.kiro/skills/aws-iam/SKILL.md",
"installedVersion": "v1",
"latestVersion": "v2",
"updateAvailable": true
},
{
"agent": "Kiro",
"name": "aws-serverless",
"path": "/path/to/sandbox-home/.kiro/skills/aws-serverless/SKILL.md",
"installedVersion": "v4",
"latestVersion": "v5",
"updateAvailable": true
}
]
}
Only the 3 skills with updates were displayed. installedVersion is the local version, and latestVersion is the latest version. aws-cloudformation, which had the latest version installed, is not shown.
Checking Including Up-to-Date Skills with --all
Adding --all displays all installed skills, including those that are already up to date. Since JSON output is difficult to compare, I used --query to narrow down the fields and output them in table format.
% aws agent-toolkit check-skill-updates --all --agent kiro --region us-east-1 \
--query 'skills[].{Name:name,Installed:installedVersion,Latest:latestVersion,UpdateAvailable:updateAvailable}' \
--output table
------------------------------------------------------------------
| check-skill-updates |
+-----------+---------+----------------------+-------------------+
| Installed | Latest | Name | UpdateAvailable |
+-----------+---------+----------------------+-------------------+
| v1 | v2 | aws-cdk | True |
| v3 | v3 | aws-cloudformation | False |
| v1 | v2 | aws-iam | True |
| v4 | v5 | aws-serverless | True |
+-----------+---------+----------------------+-------------------+
aws-cloudformation with UpdateAvailable as False was added to the results without options.
Updating All at Once with update-skill --all
I ran update-skill --all.
% aws agent-toolkit update-skill --all --agent kiro --region us-east-1
Updated aws-cdk (v2) to Kiro — ~/.kiro/skills.
Updated aws-iam (v2) to Kiro — ~/.kiro/skills.
Updated aws-serverless (v5) to Kiro — ~/.kiro/skills.
The 3 outdated skills were updated with a single command. aws-cloudformation, which was already at the latest version, was not targeted for update.
Checking the State After Update
Running check-skill-updates --all showed that all skills now have UpdateAvailable = False.
% aws agent-toolkit check-skill-updates --all --agent kiro --region us-east-1 \
--query 'skills[].{Name:name,Installed:installedVersion,Latest:latestVersion,UpdateAvailable:updateAvailable}' \
--output table
------------------------------------------------------------------
| check-skill-updates |
+-----------+---------+----------------------+-------------------+
| Installed | Latest | Name | UpdateAvailable |
+-----------+---------+----------------------+-------------------+
| v2 | v2 | aws-cdk | False |
| v3 | v3 | aws-cloudformation | False |
| v2 | v2 | aws-iam | False |
| v5 | v5 | aws-serverless | False |
+-----------+---------+----------------------+-------------------+
Without options, since there are no skills with updates, an empty list was returned.
% aws agent-toolkit check-skill-updates --agent kiro --region us-east-1
{
"skills": []
}
Re-running update-skill --all When There Are No Targets to Update
I ran update-skill --all again with all skills at the latest version.
% aws agent-toolkit update-skill --all --agent kiro --region us-east-1
All installed AWS skills are already up to date.
A message indicating there were no targets to update was displayed, and the exit code was 0.
Observations
- Check and update can be run separately: Since
check-skill-updatesdoes not download or modify files, you can follow a procedure of checking which skills have updates and what versions they are before runningupdate-skill --all. - Only outdated skills are updated:
aws-cloudformation, which was already at the latest version, had no change in the hash value ofSKILL.mdor file count even after runningupdate-skill --all. - Files other than
SKILL.mdare also updated: After updating,aws-cdkandaws-serverlesseach had one more file than before. - Version is recorded in
.aws-skill-metadata: The installed version is recorded in.aws-skill-metadatain each skill's directory in the format{"version": "v1"}. After runningupdate-skill, this value was also rewritten to the new version. - Use
--agentto narrow down the target: According to the documentation, if--agentis omitted, all detected agents are targeted. If you want to limit the scope, such as when you only want to update Kiro, specify--agent. - Specify us-east-1: The skill management commands only support us-east-1. If your default region is different, run the commands with
--region us-east-1. - Documentation: As of October 5, 2026,
check-skill-updatesandupdate-skill --allwere not yet documented on the AWS CLI page of the user guide. The specifications can be confirmed using the CLI help.
Conclusion
I tried the flow of checking for skills with updates using check-skill-updates and updating them all at once with update-skill --all, using skills installed for Kiro. The 3 outdated skills were updated to the latest versions with a single command, and the skill that was already up to date was not modified.
Since it is no longer necessary to check and update skills one by one, if you have many skills installed, you can adopt an operational approach of periodically checking for updates with check-skill-updates and running update-skill --all as needed. In environments using multiple agents, please specify the target with --agent.
Read Together
