CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-security

Use when assessing cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open security group rules, or IaC security gaps. Covers AWS, Azure, and GCP posture assessment with MITRE ATT&CK mapping.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body dominated by executable commands, severity tables, and explicit workflow validation. Minor conciseness and reference-delegation gaps keep it just below maximum.

Suggestions

Move the full IAM/S3/SG check matrices into references/cspm-checks.md and keep only a representative subset inline to reduce token load and deepen progressive disclosure.

Trim the distinction-from-other-skills and provider coverage tables, or push them into the reference, since they are contextual rather than directly actionable.

DimensionReasoningScore

Conciseness

Efficient table-driven layout with executable commands and minimal padding, though some explanatory prose (e.g., the distinction table and provider coverage matrix) could be trimmed slightly.

4 / 5

Actionability

Copy-paste ready commands throughout — concrete CLI invocations, severity matrices, and a bad/good Terraform example — fully cover the common IAM, S3, SG, and IaC cases.

5 / 5

Workflow Clarity

Three clearly sequenced workflows with explicit validation checkpoints (exit code meanings, 'Exit code 2 = block deployment') and feedback loops for the CI/CD destructive/batch gating case.

5 / 5

Progressive Disclosure

Good structure with a table of contents and one-level-deep references to real files (references/cspm-checks.md, scripts/cloud_posture_check.py), though bulk check matrices are inlined rather than fully delegated to the reference.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, concise description that explicitly pairs a 'Use when' trigger with a comprehensive list of concrete cloud security capabilities. It is specific, naturally triggered, and well-distinguished from neighboring security skills.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities — 'IAM privilege escalation paths,' 'S3 public exposure,' 'open security group rules,' and 'IaC security gaps' — giving comprehensive coverage of the skill's actions.

5 / 5

Completeness

Explicitly answers both: 'when' via 'Use when assessing...' and 'what' via the enumerated capability list, with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural trigger phrases users would say ('cloud infrastructure,' 'security misconfigurations,' 'IAM privilege escalation,' 'S3 public exposure') are present with comprehensive variation.

5 / 5

Distinctiveness Conflict Risk

Clear CSPM niche with distinct triggers ('cloud infrastructure,' 'posture assessment'), low overlap risk; the body further distinguishes it from incident-response and pen-testing skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 4 suspicious

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.