Guarded S3-to-S3 Object Copy
List accessible S3 buckets and copy one approved object between two explicit S3 locations.
Works with
name: guarded-s3-to-s3-object-copy description: "List accessible S3 buckets and copy one approved object between two explicit S3 locations."
Guarded S3-to-S3 Object Copy
List accessible S3 buckets and copy one approved object between two explicit S3 locations.
Required Aident Actions
- <action-tag>cli:aws:s3_list_buckets</action-tag> (required inputs: inspect the current schema): List accessible S3 buckets as structured JSON. Surfaces bucket metadata; treat as sensitive.
- <action-tag>cli:aws:s3_cp</action-tag> (required inputs: source, destination): Copy a file between local disk and S3 (or between S3 paths). Risk-gated write - agent must surface user acknowledgement before invoking.
Use Aident Loadout to read the current Action schema before constructing inputs. Check the required integration connection in Aident Vault. If an Action is billable or mutating, run Aident preflight, show the affected target and quoted cost or risk, and wait for explicit user confirmation before execution. Action · S3 List Bucketssource material, destination, audience, constraints, and acceptance criteria. 2. Apply the source-derived guidance below to create a concrete pAction · S3 Cp an Action. 3. Select only the Aident Actions whose documented effect directly advances the requested outcome. Do not invoke every listed Action by default. 4. Inspect the current schema and prepare the minimum valid input for each selected Action. 5. Preflight each selected Action. Execute it only after any required confirmation, in dependency order, and carry returned IDs or asset URLs into later steps. 6. Verify the returned IDs, URLs, statuses, or artifacts against the acceptance criteria. Report partial completion precisely and do not repeat paid or mutating calls blindly.
Source-Derived Guidance
- Use cli:aws:s3_list_buckets to confirm the source and destination buckets in the authenticated AWS account.
- Require explicit s3://bucket/nonempty-object-key source and destination strings; reject local or file:// paths, bucket-only or trailing-slash prefixes, wildcards, and recursive requests.
- Show overwrite, region, encryption, and data-exposure risks and obtain confirmation before using cli:aws:s3_cp once.
- Report the exact returned copy result and destination URI without claiming remote checksum or existence verification, policy, lifecycle, website, or replication changes.
Execution Boundaries
- Treat upstream provider-specific commands as background knowledge only. Execute the workflow through the exact Aident Actions above.
- Never request raw credentials in chat. Use Aident Vault connection flows for required accounts.
- Preserve user-provided wording, brand constraints, rights restrictions, and target identifiers. Do not invent authorization.
- Read current state before a mutation, state the exact target, and include a rollback or recovery step in the result.
- Stop when a required integration is disconnected, preflight rejects the input, the target is ambiguous, or the user declines a required confirmation.
Output
Return the execution plan, selected Action names, confirmed targets, Aident result identifiers or asset URLs, verification evidence, and any remaining blocked step.
Attribution
This Skill adapts the reviewed upstream workflow. See for the pinned source and for the preserved license.