[Update] I tried out the new ability to check for skill updates and perform batch updates for Agent Toolkit for AWS using the AWS CLI

[Update] I tried out the new ability to check for skill updates and perform batch updates for Agent Toolkit for AWS using the AWS CLI

Using Kiro, I tested how agent skill update management changes with the newly added check-skill-updates and update-skill --all commands in the AWS CLI Agent Toolkit.
2026.10.06

This page has been translated by machine translation. View original

This is Ishikawa from the Cloud Business Division. The check-skill-updates command for checking whether installed skills have updates all at once, and the update-skill --all command for updating outdated skills all at once, have been added to the AWS CLI Agent Toolkit for AWS commands, so I tried them out with skills installed for Kiro.

https://aws.amazon.com/jp/about-aws/whats-new/2026/09/aws-cli-agent-toolkit-update-skill/

Two features for managing agent skill updates have been added to the AWS CLI Agent Toolkit for AWS commands.

  • aws agent-toolkit check-skill-updates: Compares all installed skills against the latest versions in the registry
  • aws agent-toolkit update-skill --all: Updates all outdated skills with a single command

Previously, it was necessary to check each skill individually for updates and update them one by one. Even teams that have installed skills in many areas such as serverless, storage, networking, and analytics can now keep the skills referenced by their coding agents up to date.

AWS CLI 2.37.0 or later is required.

https://docs.aws.amazon.com/agent-toolkit/latest/userguide/aws-cli.html

The Agent Toolkit integration features in AWS CLI (such as aws configure agent-toolkit and add-skill) themselves are introduced in the following article.

https://dev.classmethod.jp/articles/try-aws-cli-agent-toolkit-command/

What Are the Agent Toolkit for AWS Skill Management Commands?

Agent Toolkit for AWS is a set of tools for AI coding agents to build, deploy, and operate applications on AWS. It consists of the following four components.

Component Description
AWS MCP Server A managed server that provides agents with access to AWS via Model Context Protocol (MCP)
Agent skills Packages that bring together procedures, scripts, and reference materials for completing specific AWS tasks
Plugins Packages that install AWS MCP Server configuration and skills together for Claude Code and Codex
Rules files Files that configure agent behavior policies on a per-project basis

https://docs.aws.amazon.com/agent-toolkit/latest/userguide/what-is-agent-toolkit.html

The aws agent-toolkit command group in AWS CLI is for installing, updating, removing, listing, and searching agent skills from the command line. Installation, updates, and removal apply to all detected agents by default. Agents are detected by the presence of a configuration directory (in Kiro's case, ~/.kiro), and you can narrow down the target with the --agent option.

The newly added commands and options are as follows. As of October 5, 2026, these were not yet documented on the AWS CLI page of the user guide, so I confirmed the specifications using the CLI help (aws agent-toolkit <command> help).

Command Behavior
check-skill-updates Displays installed skills with their local version and latest version side by side. By default, only skills with available updates are shown. No file downloads or modifications are performed
check-skill-updates --all Displays all installed skills, including those that are already up to date
update-skill --all Updates all installed skills that are outdated. Cannot be used together with --skill-name

The procedure I tried is as follows.

Let's Try It

Prerequisites

  • AWS CLI 2.37.9 (macOS, arm64)
  • Region: us-east-1
  • Target agent: Kiro (--agent kiro specified in all commands)

Skills are installed globally in each agent's configuration directory. To avoid modifying my local Kiro or other agent configurations, I validated this by temporarily pointing the HOME environment variable to a temporary directory and creating only an empty .kiro directory inside it. This is equivalent to the following state.

% export HOME=/path/to/sandbox-home
% mkdir -p ~/.kiro

Also, the skill management commands only support us-east-1. Since AWS MCP Server added support for the Tokyo region, I thought ap-northeast-1 might also be supported, but it resulted in an error.

Specifying a region other than us-east-1 results in the following error.

% aws agent-toolkit list-available-skills --region ap-northeast-1
aws: [ERROR]: AgentToolkit is only available in us-east-1

Therefore, --region us-east-1 is specified in the subsequent commands.

Installing Old Versions of Skills

To create a state requiring updates, I installed 3 skills by specifying old versions with --skill-version in add-skill. For comparison, aws-cloudformation was installed without specifying a version, so the latest version was installed.

% aws agent-toolkit add-skill --skill-name aws-cdk --skill-version v1 --agent kiro --region us-east-1
aws agent-toolkit add-skill --skill-name aws-serverless --skill-version v4 --agent kiro --region us-east-1
aws agent-toolkit add-skill --skill-name aws-iam --skill-version v1 --agent kiro --region us-east-1
aws agent-toolkit add-skill --skill-name aws-cloudformation --agent kiro --region us-east-1
  Installed aws-cdk (v1) to Kiro — ~/.kiro/skills.
  Installed aws-serverless (v4) to Kiro — ~/.kiro/skills.
  Installed aws-iam (v1) to Kiro — ~/.kiro/skills.
  Installed aws-cloudformation (v3) to Kiro — ~/.kiro/skills.

Checking the installed files, files such as SKILL.md and a file called .aws-skill-metadata were created for each skill.

% cd ~ && find .kiro -maxdepth 3 | sort
.kiro
.kiro/skills
.kiro/skills/aws-cdk
.kiro/skills/aws-cdk/.aws-skill-metadata
.kiro/skills/aws-cdk/references
.kiro/skills/aws-cdk/SKILL.md
.kiro/skills/aws-cloudformation
.kiro/skills/aws-cloudformation/.aws-skill-metadata
.kiro/skills/aws-cloudformation/references
.kiro/skills/aws-cloudformation/SKILL.md
.kiro/skills/aws-iam
.kiro/skills/aws-iam/.aws-skill-metadata
.kiro/skills/aws-iam/references
.kiro/skills/aws-iam/SKILL.md
.kiro/skills/aws-serverless
.kiro/skills/aws-serverless/.aws-skill-metadata
.kiro/skills/aws-serverless/assets
.kiro/skills/aws-serverless/references
.kiro/skills/aws-serverless/SKILL.md

.aws-skill-metadata records the installed version in JSON format.

% cd ~/.kiro/skills && for d in */; do echo "== ${d%/}/.aws-skill-metadata"; cat "${d}.aws-skill-metadata"; echo; done
== aws-cdk/.aws-skill-metadata
{"version": "v1"}

== aws-cloudformation/.aws-skill-metadata
{"version": "v3"}

== aws-iam/.aws-skill-metadata
{"version": "v1"}

== aws-serverless/.aws-skill-metadata
{"version": "v4"}
~/.kiro/skills directory
% tree -a
.
├── aws-cdk
│   ├── .aws-skill-metadata
│   ├── references
│   │   ├── bootstrap-and-project-setup.md
│   │   ├── compliance-and-drift.md
│   │   ├── construct-patterns.md
│   │   ├── import-and-migrate.md
│   │   ├── refactor-and-prevent-replacement.md
│   │   ├── troubleshooting-credentials.md
│   │   ├── troubleshooting-deployment.md
│   │   ├── troubleshooting-synth.md
│   │   └── v1-to-v2-migration.md
│   └── SKILL.md
├── aws-cloudformation
│   ├── .aws-skill-metadata
│   ├── references
│   │   ├── author-cloudformation-best-practices.script.md
│   │   ├── check-cloudformation-template-compliance.script.md
│   │   ├── cloudformation-language-server.md
│   │   ├── cloudformation-pre-deploy-validation.script.md
│   │   ├── deploy-with-express-mode.script.md
│   │   ├── lookup-resource-properties.script.md
│   │   ├── persist-template-context.script.md
│   │   ├── retrieve-template-context.script.md
│   │   ├── security-considerations.md
│   │   ├── template-safety-guidance.md
│   │   ├── troubleshoot-deployment.script.md
│   │   ├── troubleshoot-failed-stack.script.md
│   │   ├── validate-with-cfn-lint.script.md
│   │   ├── validate-with-cloudformation-validate.script.md
│   │   └── validation-tool-selection.md
│   └── SKILL.md
├── aws-iam
│   ├── .aws-skill-metadata
│   ├── references
│   │   ├── aws-iam-policy-generation.md
│   │   ├── aws-iam-role-management.md
│   │   ├── common-pitfalls.md
│   │   └── service-authorization.md
│   └── SKILL.md
└── aws-serverless
    ├── .aws-skill-metadata
    ├── assets
    │   └── powertools-handler.py
    ├── references
    │   ├── api-gateway.md
    │   ├── architecture.md
    │   ├── concurrency.md
    │   ├── deployment.md
    │   ├── event-sources.md
    │   ├── lambda.md
    │   ├── orchestration.md
    │   ├── production.md
    │   └── troubleshooting.md
    └── SKILL.md

10 directories, 46 files

Checking for Skills with Updates Using check-skill-updates

I ran check-skill-updates without any options.

% aws agent-toolkit check-skill-updates --agent kiro --region us-east-1
{
    "skills": [
        {
            "agent": "Kiro",
            "name": "aws-cdk",
            "path": "/path/to/sandbox-home/.kiro/skills/aws-cdk/SKILL.md",
            "installedVersion": "v1",
            "latestVersion": "v2",
            "updateAvailable": true
        },
        {
            "agent": "Kiro",
            "name": "aws-iam",
            "path": "/path/to/sandbox-home/.kiro/skills/aws-iam/SKILL.md",
            "installedVersion": "v1",
            "latestVersion": "v2",
            "updateAvailable": true
        },
        {
            "agent": "Kiro",
            "name": "aws-serverless",
            "path": "/path/to/sandbox-home/.kiro/skills/aws-serverless/SKILL.md",
            "installedVersion": "v4",
            "latestVersion": "v5",
            "updateAvailable": true
        }
    ]
}

Only the 3 skills with updates were displayed. installedVersion is the local version, and latestVersion is the latest version. aws-cloudformation, which had the latest version installed, is not shown.

Checking Including Up-to-Date Skills with --all

Adding --all displays all installed skills, including those that are already up to date. Since JSON output is difficult to compare, I used --query to narrow down the fields and output them in table format.

% aws agent-toolkit check-skill-updates --all --agent kiro --region us-east-1 \
  --query 'skills[].{Name:name,Installed:installedVersion,Latest:latestVersion,UpdateAvailable:updateAvailable}' \
  --output table
------------------------------------------------------------------
|                       check-skill-updates                      |
+-----------+---------+----------------------+-------------------+
| Installed | Latest  |        Name          |  UpdateAvailable  |
+-----------+---------+----------------------+-------------------+
|  v1       |  v2     |  aws-cdk             |  True             |
|  v3       |  v3     |  aws-cloudformation  |  False            |
|  v1       |  v2     |  aws-iam             |  True             |
|  v4       |  v5     |  aws-serverless      |  True             |
+-----------+---------+----------------------+-------------------+

aws-cloudformation with UpdateAvailable as False was added to the results without options.

Updating All at Once with update-skill --all

I ran update-skill --all.

% aws agent-toolkit update-skill --all --agent kiro --region us-east-1
  Updated aws-cdk (v2) to Kiro — ~/.kiro/skills.
  Updated aws-iam (v2) to Kiro — ~/.kiro/skills.
  Updated aws-serverless (v5) to Kiro — ~/.kiro/skills.

The 3 outdated skills were updated with a single command. aws-cloudformation, which was already at the latest version, was not targeted for update.

Checking the State After Update

Running check-skill-updates --all showed that all skills now have UpdateAvailable = False.

% aws agent-toolkit check-skill-updates --all --agent kiro --region us-east-1 \
  --query 'skills[].{Name:name,Installed:installedVersion,Latest:latestVersion,UpdateAvailable:updateAvailable}' \
  --output table
------------------------------------------------------------------
|                       check-skill-updates                      |
+-----------+---------+----------------------+-------------------+
| Installed | Latest  |        Name          |  UpdateAvailable  |
+-----------+---------+----------------------+-------------------+
|  v2       |  v2     |  aws-cdk             |  False            |
|  v3       |  v3     |  aws-cloudformation  |  False            |
|  v2       |  v2     |  aws-iam             |  False            |
|  v5       |  v5     |  aws-serverless      |  False            |
+-----------+---------+----------------------+-------------------+

Without options, since there are no skills with updates, an empty list was returned.

% aws agent-toolkit check-skill-updates --agent kiro --region us-east-1
{
    "skills": []
}

Re-running update-skill --all When There Are No Targets to Update

I ran update-skill --all again with all skills at the latest version.

% aws agent-toolkit update-skill --all --agent kiro --region us-east-1
All installed AWS skills are already up to date.

A message indicating there were no targets to update was displayed, and the exit code was 0.

Observations

  • Check and update can be run separately: Since check-skill-updates does not download or modify files, you can follow a procedure of checking which skills have updates and what versions they are before running update-skill --all.
  • Only outdated skills are updated: aws-cloudformation, which was already at the latest version, had no change in the hash value of SKILL.md or file count even after running update-skill --all.
  • Files other than SKILL.md are also updated: After updating, aws-cdk and aws-serverless each had one more file than before.
  • Version is recorded in .aws-skill-metadata: The installed version is recorded in .aws-skill-metadata in each skill's directory in the format {"version": "v1"}. After running update-skill, this value was also rewritten to the new version.
  • Use --agent to narrow down the target: According to the documentation, if --agent is omitted, all detected agents are targeted. If you want to limit the scope, such as when you only want to update Kiro, specify --agent.
  • Specify us-east-1: The skill management commands only support us-east-1. If your default region is different, run the commands with --region us-east-1.
  • Documentation: As of October 5, 2026, check-skill-updates and update-skill --all were not yet documented on the AWS CLI page of the user guide. The specifications can be confirmed using the CLI help.

Conclusion

I tried the flow of checking for skills with updates using check-skill-updates and updating them all at once with update-skill --all, using skills installed for Kiro. The 3 outdated skills were updated to the latest versions with a single command, and the skill that was already up to date was not modified.

Since it is no longer necessary to check and update skills one by one, if you have many skills installed, you can adopt an operational approach of periodically checking for updates with check-skill-updates and running update-skill --all as needed. In environments using multiple agents, please specify the target with --agent.

Read Together

https://dev.classmethod.jp/articles/try-aws-cli-agent-toolkit-command/

https://dev.classmethod.jp/articles/20260507-aws-mcp-server-ga/

Share this article

AWSのお困り事はクラスメソッドへ