What problem does it solve? Operations and security teams need to know exactly which EC2 instances are safe and ready to send for Nessus Manager, patch, CIS, VA, or validation scans, without risking accidental changes to AWS resources or scanning the wrong hosts. ## Core Features & Use Cases - Read-only evidence gathering: Collects instance state, tags, SSM PingStatus, and Nessus agent readiness without relinking, restarting, installing, patching, or mutating any AWS resource. - Candidate classification: Sorts hosts into scan-ready, not-ready, cleanup-after-scan, retain, and needs-owner-confirmation buckets with clear blockers and cautions. - Ops-ready reporting: Produces a RESULT.md with target tables, blockers, and a draft message for Ops/Kishore handoff, plus routing of cleanup candidates to Terraform/Terragrunt cleanup workflows. - Use Case: When Amit asks which PROD EC2s should go to Kishore for a Nessus Manager scan, the skill verifies SSM Online status and agent linkage per host, then delivers a compact target table distinguishing ready hosts from those needing cleanup or owner confirmation. ## Quick Start Ask which EC2 instances in the PROD account are ready for the Nessus Manager scan and request a target table with read-only evidence.