AWS: diagnose Bedrock Agents and action-group Lambdas
The AWS integration adds two read-only Bedrock Agent diagnostic tools that use the same SSO or IAM session as your other aws_* tools — no new Opsphere secrets. Focus is operational diagnosis for Bedrock Agents (status, aliases, action groups, IAM, knowledge bases, and findings), not Agent Core product marketing.
aws_bedrock_agent_diagnose returns agent health, IAM warnings, KB status, linked Lambdas, and a relationship graph in one call. aws_lambda_agent_diagnose drills into action-group Lambdas with config, IAM policies, and CloudWatch error signals (environment values redacted). The guided prompt investigate-bedrock-agent runs the same read-only flow in web chat and MCP playbooks.
This extends the existing AWS integration — no new vendor chip on the hub. The full Opsphere gateway catalog reaches 318 operational tools.
