amazon-workspaces-agent-access
Connects AI agents to remote Windows desktop applications on Amazon WorkSpaces Applications (AppStream 2.0) through the managed Agent Access MCP server, and guides reliable desktop automation. Covers connecting an agent to the MCP endpoint (SigV4, streaming URL, and Active Directory SAML/Domain Join
- 0
- Installs
- —
- Rating
- —
- Success rate
- 9
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 abf02eaacc6998ba… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Amazon WorkSpaces Applications — Agent Access
Domain expertise for connecting AI agents to remote Windows desktops on Amazon WorkSpaces Applications (AppStream 2.0) via the managed Agent Access MCP server, and for driving those desktops reliably.
How it works: Agent Access is MCP-only — there is no AWS CLI/SDK command that calls the desktop tools. Agents connect to https://agentaccess-mcp.{region}.api.aws/mcp over Streamable HTTP, SigV4-signed with service name agentaccess-mcp, and call MCP tools (screenshot, left_click, type_text, ...) to drive the desktop. The AWS CLI/SDK is used only for setup — appstream create-streaming-url, fleet/stack configuration. mcp-proxy-for-aws handles the SigV4 signing.
Recommended setup: use mcp-proxy-for-aws (Python) as the transport; it signs each request and manages the DELETE lifecycle. Any MCP client that supports Streamable HTTP + SigV4 works. When running the AWS CLI/SDK setup steps (create-streaming-url, stack/fleet configuration), the AWS MCP server is recommended for sandboxed execution and audit logging.
Guardrail — where this skill's own files live (MCP vs local install)
This skill can be loaded two ways, and they resolve the skill's own bundled files from different places. Determine how the skill was loaded before reading a reference:
- Loaded through the AWS MCP
retrieve_skilltool: The skill is not installed on the local filesystem. You MUST fetch each reference viaretrieve_skillwith thefileparameter (e.g.file="references/connection-setup.md"), and use the returned content. Do NOTfile_readthese paths locally — they do not exist on disk. - Installed locally (e.g.
.kiro/skills/amazon-workspaces-agent-access/or~/.claude/skills/amazon-workspaces-agent-access/): Read files from the local skill directory using relative paths.
This distinction applies only to the skill's own packaged files. User data and session artifacts are always read from and written to the user's working directory. Never fetch or write customer data through retrieve_skill.
Key facts agents get wrong (load the reference before answering in detail)
These are HTTP headers / metadata on the MCP connection — not tool parameters, and there is no connect_to_desktop tool. Do not invent tools or parameters; the desktop tools are exactly those in tools-reference.md.
-
Connect mode. Selected by the
X-Amzn-AgentAccess-Connect-ModeHTTP header (valueBLOCKING, the default, orPOLLING) — sent on the MCP request alongside the streaming-URL/SAML auth. It is NOT a JSON tool argument.-
❌ WRONG (common hallucination): calling a
connect_to_desktoptool with aconnection_mode: "POLLING"parameter, or asession_id/application_id/user_idargument. None of those exist. -
✅ RIGHT: set the
X-Amzn-AgentAccess-Connect-Mode: POLLINGheader. Thentools/listinitially returns only theconnection_statustool; the agent callsconnection_statusrepeatedly until its returned state isCONNECTED, and only then doestools/listreturn the full desktop tool set (screenshot,left_click, ...). (details: connection-modes.md)# Correct POLLING usage — the mode is an HTTP header on the MCP connection: async with aws_iam_streamablehttp_client( endpoint="https://agentaccess-mcp.us-east-1.api.aws/mcp", # use YOUR fleet's region aws_service="agentaccess-mcp", aws_region="us-east-1", # region must match the fleet (else 400) headers={ "X-Amzn-AgentAccess-Streaming-Session-Url": streaming_url, "X-Amzn-AgentAccess-Connect-Mode": "POLLING", # header, not a tool arg }, ) as (read, write, _): async with ClientSession(read, write) as session: await session.initialize() # tools/list now returns ONLY connection_status until the desktop is up: while json.loads((await session.call_tool("connection_status", {})).content[0].text)["state"] != "CONNECTED": await asyncio.sleep(2) tools = await session.list_tools() # now the full desktop tool set
-
-
Streaming session (non-domain-joined) is the
X-Amzn-AgentAccess-Streaming-Session-Urlheader. Domain-joined fleets instead pass the SAML assertion + stack ARN via MCP_metakeysaws.agentaccess/workspacesApplicationsSamlAssertionandaws.agentaccess/workspacesApplicationsStackArn. (details: connection-setup.md) -
Expire-on-delete is the
X-Amzn-AgentAccess-Expire-Streaming-Session-On-Deleteheader (true/false; defaultfalse). Expiry happens on the client's explicit HTTPDELETE—mcp-proxy-for-awssends it automatically on clean close. (details: session-lifecycle.md) -
Forwarded tools are namespaced by server:
forwarded___<server-name>___<tool-name>(e.g.forwarded___filesystem___read_file) — notforwarded___<tool-name>. (details: tool-forwarding.md) -
COMPUTER_INPUTrequiresCOMPUTER_VISIONto also be ENABLED in the stack'sAgentAccessConfig. (details: enabling-agent-access.md)
Routing
| User need | Read |
|---|---|
Enable agent access on a stack (AgentAccessConfig: COMPUTER_INPUT/COMPUTER_VISION/FORWARD_MCP_TOOLS, screen resolution/format, prerequisites) — the admin setup step before any agent can connect | enabling-agent-access.md |
| Connect an agent to the MCP server — endpoint, SigV4, streaming URL (non-domain-joined), or Active Directory SAML/Domain Join | connection-setup.md |
Choose BLOCKING vs POLLING; poll connection_status until the desktop is ready | connection-modes.md |
| The computer-use tool set (mouse, keyboard, screenshot) and their parameters | tools-reference.md |
| Automate reliably — screenshot budget, action batching, trusting UI actions, coordinate planning, dialog recovery | automation-best-practices.md |
Expose your own MCP servers on the fleet as forwarded___<server>___<tool> tools; prefer forwarded tools for file/web tasks | tool-forwarding.md |
| Session lifecycle — cleanup, expire-on-delete, idle timeout, one-agent-per-session | session-lifecycle.md |
Debug an error (exact string → cause → fix): dcv session not ready, client_disconnected, 400/401/403, Unknown tool | troubleshooting.md |
Security Considerations
- The agent acts under the caller's AWS identity. Every MCP request is SigV4-signed with service
agentaccess-mcp; the desktop session runs with those credentials. Grant only the specificagentaccess-mcpactions the agent calls (e.g.InvokeMcp,GetScreenshot,LeftClick,TypeText) and scope them with theagentaccess-mcp:StackArncondition key — avoid a blanketagentaccess-mcp:*orResource: *. Prefer IAM roles over long-lived users. (Full action list + example: connection-setup.md → IAM permissions.) - Screenshots can capture sensitive data.
COMPUTER_VISIONcaptures whatever is on the desktop — treat screenshots as potentially containing PII or secrets. If screenshot storage is enabled, the S3 bucket must enforce encryption at rest and in transit and least-privilege access: grant the AppStream service principal only what it needs and the connecting agent onlys3:PutObject(see enabling-agent-access.md). - Enable only the capabilities you need.
COMPUTER_INPUT,COMPUTER_VISION, andFORWARD_MCP_TOOLSare independent — do not enable input/forwarding on stacks that only need vision. - Tool forwarding executes code on the fleet. Forwarded MCP servers run on the instance under the session context. Install only trusted servers system-wide, gate with
FORWARD_MCP_TOOLS, and scope theCallForwardedToolIAM action byagentaccess-mcp:StackArn(see tool-forwarding.md). - Keep a human in the loop where warranted.
UserControlMode: VIEW_STOPlets an observer watch the live session and stop the agent. Treat agent-driven desktop actions as capable of arbitrary UI operations. - Audit with CloudTrail. Agent session events are logged; tool calls are CloudTrail data events and require a trail configured to log them. Create a trail with
agentaccess-mcpdata events enabled, encrypt it with SSE-KMS, and add CloudWatch alarms for anomalous patterns (e.g. high screenshot volume, unexpectedTypeText, repeated auth failures). If screenshot storage is enabled, turn on S3 server access logging for the bucket. - Protect federation material. For domain-joined (SAML) fleets, safeguard the IdP signing certificate and the IAM SAML provider/role trust policy, and do not log the SAML assertion. Traffic is HTTPS + SigV4 — never disable TLS verification.
- Treat typed input as potentially sensitive.
type_textcan enter secrets (passwords, tokens); these may then appear in screenshots, screenshot-storage S3, and CloudTrail data events. Avoid typing long-lived secrets into the desktop where possible, and restrict who can read those sinks. - Refer to the current Agent Access documentation and AWS security best practices for the latest guidance.
Note: Regional endpoints, feature availability, and quotas change. When precision matters, confirm against the current Agent Access MCP server documentation. The references focus on the values and gotchas that are easy to get wrong.
Files
9- SKILL.md
723bf0e1f410.7 KB - references/automation-best-practices.md
e5e4b02ee33.4 KB - references/connection-modes.md
99b70acfa82.1 KB - references/connection-setup.md
47877ee3087.3 KB - references/enabling-agent-access.md
c4459c80f43.9 KB - references/session-lifecycle.md
b06e7971ab3.0 KB - references/tool-forwarding.md
00faee071e3.4 KB - references/tools-reference.md
617ed1d8722.3 KB - references/troubleshooting.md
1c96e24d7d3.1 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from aws/agent-toolkit-for-aws8
Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query). Trigger for Aurora MySQL cluster operations, ACU sizing, I/O-Optimized storage, commitment pricing, or MySQL upgrade planning. Aurora MySQL uses fu
Amazon Aurora PostgreSQL — creates, modifies, and advises on Aurora PostgreSQL clusters specifically (PostgreSQL-compatible engine, Aurora serverless, express configuration, pgvector, Babelfish). Trigger for Aurora PostgreSQL cluster operations, express-configuration quick-start, ACU sizing, I/O-Opt
Builds generative AI applications on Amazon Bedrock. Covers model invocation (Converse API, InvokeModel), RAG with Knowledge Bases, Bedrock Agents, Guardrails, and AgentCore (including the Harness managed agent loop). Applies when invoking models, setting up Knowledge Bases, creating agents, applyin
Runs quantum computing workflows on AWS through Amazon Braket — discovering devices (QPUs and simulators) and their availability, building gate-model circuits and analog Hamiltonian programs, submitting quantum tasks, program sets and hybrid jobs, looking up prices, and capping spend with spending l
Manages Amazon DocumentDB end-to-end — serverless-on-8.0 cluster setup, TLS/VPC/driver config, flexible-schema and vector-search data modeling, MongoDB compatibility assessment, DMS-based migration, slow-query diagnosis, major version upgrades (4.0->5.0->8.0), Well-Architected reviews (41-check wa_r
Creates and automates custom image builds with EC2 Image Builder - Linux, Windows, and macOS AMIs, and container images to ECR. Covers the build IAM role, Amazon-managed and custom components, image recipes, infrastructure and distribution configuration (launch templates, SSM parameters, other Regio
Activate when developers have latent caching needs: slow API responses, database read bottlenecks, DynamoDB throttling or cost, RDS/Aurora scaling pressure, Bedrock latency or cost, or adding a cache; activate when working with Redis, Valkey, Memcached, or any in-memory data store, cache-aside patte
Builds, runs, debugs, and operates event-driven applications using EventBridge Event Bus - a managed, centrally governed publish/subscribe event bus that an organization can share across many teams and accounts. Applicable when workloads need event-driven architectures, decoupling, choreography, asy
Related ai-ml skillsscan passed
Regression testing strategies for AI-assisted development. Sandbox-mode API testing without database dependencies, automated bug-check workflows, and patterns to catch AI blind spots where the same model writes and reviews code. Use when adding regression coverage to AI-assisted code, or when the sa
Pair a remote AI agent with your browser. (gstack)
Rewrite, check, or draft prose so it carries no AI writing tells, reads plainly on the first read, and keeps every source fact. Use when asked to make writing plainer or free of those tells, to check writing for them, or when drafting from supplied content. Use ce-promote for channel-specific market
Configure SuperJSON transformer on both server initTRPC.create({ transformer: superjson }) and every client terminating link (httpBatchLink, httpLink, wsLink, httpSubscriptionLink) to support Date, Map, Set, BigInt over the wire. Transformer must match on both sides. In v11, transformer goes on indi
Generates python code that evaluates SageMaker models. Supports two evaluation types: LLM-as-Judge and Custom Scorer. Use when the user says "evaluate my model", "run a benchmark", "test model performance", "how did my model perform", "compare models", or other similar requests.
Builds voice and chat AI agents with LiveKit Agents and LiveKit Cloud. Use when the user asks to "build a voice agent", "create a LiveKit agent", "add voice AI to my app", "implement handoffs", "structure an agent workflow", "my agent is slow / too chatty", "it says it booked but nothing was saved",