CtrlK
BlogDocsLog inGet started
Tessl Logo

terraform-state-leak

Exploit exposed Terraform state files — secrets, cloud creds, RDS passwords, IAM keys, and infrastructure topology in plain JSON.

63

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/cloud/terraform-state-leak/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with copy-paste-ready commands and a clear six-step workflow including an IAM-key validation checkpoint. It is concise and well-structured, with only minor trimming and organization opportunities.

DimensionReasoningScore

Conciseness

The body is largely lean and command-focused, assuming Claude's competence; minor instances of prose ('This data alone is high-value recon for a follow-on engagement', 'Best practice is to store it encrypted in S3 with KMS') could be trimmed without losing clarity.

4 / 5

Actionability

Fully executable, copy-paste-ready curl/feroxbuster, aws CLI, jq, and git commands cover discovery, parsing, validation, and pivoting across the common cases, with specific field selectors for IAM keys and RDS passwords.

5 / 5

Workflow Clarity

Numbered sections 1-6 give a clear Discover -> Parse -> Topology -> Validate -> Pivot -> Promote sequence, and step 4 provides explicit IAM-key validation; it stops short of explicit validate-fix-retry feedback loops, leaving minor checkpoint gaps.

4 / 5

Progressive Disclosure

A single self-contained file with well-organized numbered sections and no nested references; it exceeds 50 lines so the simple-skill 5 does not apply, and the inlined exemplars/CVSS/remediation sections are minor organization gaps rather than content that must be split out.

4 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, distinct, and keyword-rich, clearly conveying what the skill does. Its main weakness is the absence of an explicit 'Use when...' trigger clause, which leaves the 'when to use' guidance implicit and caps completeness.

Suggestions

Add an explicit 'Use when...' clause, e.g. 'Use when you find an exposed terraform.tfstate file, a public S3 state bucket, or committed tfstate in git history.'

Include the natural synonym 'tfstate' and the file extension '.tfstate' in the description so it matches phrasings users actually say.

Keep the enumerated secret types but consider leading with the trigger condition before the action to strengthen the 'when' half.

DimensionReasoningScore

Specificity

Names the domain ('exposed Terraform state files') and the concrete action ('Exploit') plus enumerates specific extracted artifacts (secrets, cloud creds, RDS passwords, IAM keys, infrastructure topology), giving several specific outcomes with only minor coverage gaps.

4 / 5

Completeness

The 'what' is clear (exploit exposed state files and extract the listed secrets), but there is no 'Use when...' clause or equivalent explicit trigger guidance in the description field, which caps completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

Good natural keyword coverage ('Terraform state files', 'secrets', 'RDS passwords', 'IAM keys', 'infrastructure topology'), though it omits the common synonym 'tfstate' and file-extension terms that a user might actually say.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (exposed Terraform state exploitation) with distinct, specific triggers; minimal risk of conflicting with other skills.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.