← Files SugerARCHIVED FILE

SKILL.md

10.1 KB · Oct 2, 2026 · 00:17 UTC

↓ Download file

---
name: aws-resource-tag
description: "Guide the user through tagging AWS resources with the aws-apn-id tag for AWS Partner Revenue Measurement (PRM), retrieving the product code from AWS Partner Central SaaS products page."
---

# Tag AWS Resources for PRM

Browser-only automation. Never offer CLI/Terraform/CloudFormation alternatives. Never explain what you will do — just do it. Never ask the user to click anything — you click it.

This is a SaaS product only — never mention AMI, containers, or other product types.

## Tag Format (NEVER deviate)

- **Key**: `aws-apn-id` (the ONLY key — never `product`, `suger:product`, `product_code`, or anything else)
- **Value**: `pc:<product-code>` (product code from AWS Partner Central — never Product ID `prod-xxx`)
- You already know the tag. **Never ask the user what key or value to use.**

## Tool Rules

- Call `get_ui_context` at the start. Call `extract_page` before every `click` or `fill`.
- When a click opens a new tab → `list_tabs` → switch to new tab → `extract_page`.
- Read-only actions are pre-approved. Only pause before saving tags.
- Do not stop on failure. Finish the flow, report at the end.
- Prefer `click` on visible links/buttons between related pages. Use `navigate` only for the top-level service URLs listed in the execution flow below (SaaS products, AWS Console home, EC2 home, RDS home) — always substitute the `<region>` placeholder with the region you noted at the start.
- **Region preservation**: Note the user's current AWS region at the start. Always substitute that exact region into the `<region>` placeholder of every `navigate` URL. If a navigation still lands you in a different region, switch back before proceeding.
- **Status messages**: Output a short status at each major step (e.g. "Navigating to SaaS products...", "Found product code: X", "Moving to EC2...").
- **Turn continuation (CRITICAL)**: The ONLY places you are allowed to end your turn during execution are:
  (a) right after calling `show_quick_choices` to wait for a user selection, or
  (b) after you output the final success/failure report at the very end of the flow.
  Outputting a status message like "Moving to EC2..." or "Found product code: X" is NEVER a reason to end your turn — immediately continue with the next tool call in the same turn. If you catch yourself about to stop after a status message, don't: make the next tool call instead.

**IMPORTANT: Never use backend APIs, database tools, or MCP tools to look up products or resources. ALL lookups must be done by navigating the browser.**

When triggered, immediately proceed to the Planning stage.

## Planning Stage

First output this plan as text:

**Plan: Tag AWS Resources for PRM**

| Setting        | Default                                     |
| -------------- | ------------------------------------------- |
| Product code   | Look up from AWS Partner Central            |
| Tag to apply   | aws-apn-id = pc:\<product-code\>            |
| Resource types | Both EC2 and RDS                            |
| Account        | Same account for product code and resources |

**Steps:**

1. Navigate to AWS Partner Central → find your SaaS product → get product code
2. Navigate to EC2 console → list instances for you to pick
3. Navigate to RDS console → list databases for you to pick
4. For each selected resource, add the tag
5. Confirm with you before saving each tag

Then end your turn with the question **"Ready to start?"** and IMMEDIATELY call `show_quick_choices` with choices `["Approve plan", "Change something", "Cancel"]`. End your turn there and wait for the user's reply on the next turn.

When the user replies on the next turn:

- If reply is **"Approve plan"** → proceed to the execution flow below.
- If reply is **"Cancel"** → say "No problem!" and stop.
- If reply is **"Change something"** → ask "What would you like to change?" and call `show_quick_choices` with choices `["I already have the product code", "EC2 only", "RDS only", "Resources are in a different account"]`. End your turn. When the user replies, update the plan accordingly and re-ask for approval using the same pattern.

## After "Approve plan": Execution Flow

You MUST complete Step 1 (get product code) before doing anything else. Never skip to EC2/RDS without the product code.

1. Output: `Plan approved! Starting execution...\n\nStep 1: Navigating to SaaS products to get the product code...`
2. Call `get_ui_context` → `extract_page`. Note the current AWS region — you will reuse it for every subsequent `navigate` call.
3. **Navigate to SaaS products**: `navigate` to `https://aws.amazon.com/marketplace/management/products/saas?region=<region>`.
4. `extract_page`. If a new tab opened: `list_tabs` → switch → `extract_page`.
5. Proceed to Step 1.

## Step 1: Get the Product Code

This step is MANDATORY. Never skip it unless the user already gave you the product code.

1. `extract_page`. The table shows product rows with a radio button and **Product title** column.
2. If exactly 1 product → `click` the radio button next to it to select it, then `click` the **"View details"** button above the table. Do not ask the user.
3. If multiple products → ask "Which product?" and call `show_quick_choices` with choices set to the product titles plus "All products". End your turn and wait for the user's reply. When they reply, `click` the radio button for the chosen product, then `click` **"View details"**.
4. After clicking "View details" → `list_tabs`. The product detail page may open in a new tab. If so, switch to it.
5. `extract_page`. Find the **Product Summary** section.
   - **Product ID** (`prod-xxx`) ← WRONG. Never use this.
   - **Product code** (long alphanumeric, 20+ chars, no prefix) ← CORRECT. Use this.
6. Record the product code.
7. Output: `Found product code: <code>. Tag will be aws-apn-id = pc:<code>.\n\nMoving to EC2...` — this is a status message, NOT an end-of-turn. Do NOT stop after this line. Do NOT wait for the user. Immediately continue with step 8 in the same turn.
8. **Navigate back to the AWS Console**: `navigate` to `https://<region>.console.aws.amazon.com/console/home?region=<region>`.
9. `extract_page` to confirm you're on the AWS Console. Then continue directly to Step 2 — do NOT end your turn between Step 1 and Step 2.

## Step 1.5: Switch to Resource Account (if needed)

Only if the user mentioned resources are in a different account.

1. Say "Please sign into the AWS account where your resources live." and call `show_quick_choices` with choices `["I'm signed in"]`. End your turn and wait for the user's reply.
2. When the user confirms on the next turn → `extract_page`.

## Step 2: Tag EC2

Skip if user chose RDS only.

1. **Navigate to EC2**: `navigate` to `https://<region>.console.aws.amazon.com/ec2/home?region=<region>#Home:`.
2. `extract_page` to confirm you are on the EC2 dashboard in the expected region. If a new tab opened: `list_tabs` → switch → `extract_page`.
3. `click` **Instances** → `extract_page`.
4. Ask the user which instances to tag (list the instances found in your message) and call `show_quick_choices` with choices set to the instance names plus "All instances". End your turn and wait for the user's reply.
5. If user chose "All instances" → tag every instance one by one without asking again. For each instance:
   - `click` instance row → `extract_page`.
   - In the lower detail pane, `click` the **Tags** tab → `extract_page`.
   - If `aws-apn-id` already exists with correct value → skip. Wrong value → replace.
   - `click` **Manage tags** → `extract_page`.
   - `click` **Add new tag**. Never edit existing tags.
   - `fill` Key: `aws-apn-id` → `fill` Value: `pc:<product-code>`.
   - `extract_page` to verify → `click` **Save** → `extract_page`.
   - Output status: "Tagged [instance name]." then IMMEDIATELY `click` the next instance. Do NOT stop. Do NOT say "ready for next". Do NOT end your turn. Just click the next one.
   - After ALL instances are tagged, output "All EC2 instances tagged."
6. If user chose specific instances → same as above but only for those instances. Before saving each one, ask "Ready to save tag on [instance]: aws-apn-id = pc:<code>. Proceed?" and call `show_quick_choices` with choices `["Proceed", "Skip"]`. End your turn and wait for the user's reply.

## Step 3: Tag RDS

Skip if user chose EC2 only.

1. Output: `Moving to RDS...` — this is a status message, NOT an end-of-turn. Do NOT stop here. Immediately continue with step 2 in the same turn.
2. **Navigate to RDS**: `navigate` to `https://<region>.console.aws.amazon.com/rds/home?region=<region>`.
3. `extract_page` to confirm you are on the RDS dashboard in the expected region. If a new tab opened: `list_tabs` → switch → `extract_page`.
4. `click` **Databases** → `extract_page`.
5. Ask the user which databases to tag (list the databases found in your message) and call `show_quick_choices` with choices set to the DB names plus "All databases". End your turn and wait for the user's reply.
6. If user chose "All databases" → tag every database one by one without asking again. For each database:
   - `click` DB identifier → `extract_page` → `click` **Tags** tab → `extract_page`.
   - If `aws-apn-id` already exists with correct value → skip. Wrong value → replace.
   - `click` **Add tags** or **Manage tags** → `extract_page`.
   - `click` **Add tag**. Never edit existing tags.
   - `fill` Key: `aws-apn-id` → `fill` Value: `pc:<product-code>`.
   - `extract_page` to verify → `click` **Save** → `extract_page`.
   - Output status: "Tagged [db name]." then IMMEDIATELY `click` the next database. Do NOT stop. Do NOT say "ready for next". Do NOT end your turn. Just click the next one.
   - After ALL databases are tagged, output "All RDS databases tagged."
7. If user chose specific databases → same as above but only for those. Before saving each one, ask "Ready to save tag on [db]: aws-apn-id = pc:<code>. Proceed?" and call `show_quick_choices` with choices `["Proceed", "Skip"]`. End your turn and wait for the user's reply.

## Report

When done, summarize: each resource → `tagged` / `already tagged` / `skipped` / `failed`. For failures: what went wrong + fix suggestion.

SHA-256: 31cc9b709f0ddabcd5d3988b9f9db7826af865f25c762f12ad3d3a1ca330a8ef