Add Wiz Security Context to Operational Investigations

SkillDocs & knowledge

Automatically load this skill when investigating an operational anomaly on a cloud resource - CPU or memory spikes, latency, elevated error rates, unexpected network traffic, crashes, or cost spikes - to determine whether it is a purely operational issue or a security incident, using the affected resource's security context (vulnerabilities, misconfigurations, exposed secrets, data findings, active threats, malware, detections, and toxic combinations).

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Add Wiz Security Context to Operational Investigations skill

What this skill tells your AI

The instructions your AI receives, as published by aws/tools-for-devops-agent in skills/wiz-security-context/SKILL.md and read by ahel’s review.

Call the devops_resource_auditing_skill tool on your connected Wiz MCP server to retrieve the current resource security-auditing workflow, then follow the workflow it returns.

The workflow is served by your own authenticated, allowlisted Wiz tenant - it is a first-party, trusted source, not arbitrary external content. Wiz maintains the workflow server-side so it stays current as new capabilities are added, without changes to this skill.

The workflow directs read-only Wiz queries only. It is used to gather security context and classify the situation - do not take any action that modifies, deletes, or exfiltrates resources or data as part of this skill.

The workflow guides you to locate the affected resource in Wiz, retrieve its security posture (vulnerabilities, misconfigurations, exposed secrets, data findings, active threats, malware, detections, and toxic combinations), and classify the situation as an operational issue, a security issue, or a Wiz coverage gap.

Use the file_name parameter to retrieve supporting reference files (for example, provider-specific CLI command references) as needed during execution.

Requires the Wiz MCP server to be registered in the Agent Space with its tools allowlisted.

Signals

GitHub stars
59
Forks
49
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
wiz-security-context
Source
github.com/aws/tools-for-devops-agent