CtrlK
BlogDocsLog inGet started
Tessl Logo

agents-connect

Use when connecting your agent to external APIs, tools, or services via Gateway, or restricting tool access with Cedar policies. Handles gateway setup, target types, outbound auth (OAuth, API key, IAM), credentials, and Cedar policy authoring. Triggers on: "connect to API", "add gateway", "connect to MCP server", "Lambda tools", "OpenAPI", "gateway target", "Cedar policy", "restrict tools", "policy engine", "gateway auth error", "store API key", "outbound credential", "env var API key", "API key None after deploy", "credential not available after deploy", "should this be a gateway target", "give my agent tools", "add tools to agent". Not for inbound auth (who can call your agent) — use agents-harden. Not for debugging agent behavior — use agents-debug. Not for VPC networking errors (agent can't reach APIs due to VPC) — use agents-build. Not for creating or hosting a new MCP server project — use agents-get-started.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable and pedagogically strong — the mental-model section, default-first triage, and security warnings are genuine value — but it is overlong for a SKILL.md. Repetition of the same CLI-limitation guidance and the inlining of feature-level and credential-level detail that belong in reference files cost it both conciseness and progressive-disclosure points.

Suggestions

Deduplicate guidance that appears multiple times: state the MCP-target API-key limitation and the 2LO/3LO CLI-vs-SDK split once (Step 3's auth matrix) and reference it from Path A and Troubleshooting instead of restating it.

Move the semantic-search section, custom-headers section, and the Path D credential/decorator detail into references/ files (e.g., references/search.md, references/credentials.md), leaving the body with the triage table, per-path CLI commands, and one client-code example.

Replace Path D's 'Before you reach for Path D' bullet list with a pointer back to the earlier direct-call justification table — the two lists cover the same five situations.

DimensionReasoningScore

Conciseness

The body is mostly AgentCore-specific knowledge Claude would not know, but repeats the same guidance multiple times: the 'API key not supported for MCP targets' limitation appears in Step 3, Path A, and Troubleshooting; the 2LO-vs-3LO CLI limitation is explained nearly verbatim twice; and Path D's 'check if it's actually the right path' bullet list duplicates the direct-call justification table from the earlier 'prefer a Gateway target' section. This matches 'mostly efficient but includes some unnecessary explanation or could be tightened'.

3 / 5

Actionability

Concrete, runnable CLI commands for every path and complete framework-agnostic MCP client code put this above the midpoint, but the Strands snippet references get_gateway_tools/os/asyncio without imports and the LangGraph snippet has undefined llm and an unexplained @app.entrypoint — minor gaps in copy-paste readiness. The 'Mostly executable guidance; concrete code or commands with minor gaps' anchor fits.

4 / 5

Workflow Clarity

Steps 0–3 are clearly sequenced with a triage heuristic routing to Paths A–D, and validation exists (CLI version check, 'agentcore fetch access'/'agentcore status' verification, log-based diagnosis in Troubleshooting). It falls short of the 5 anchor because some checkpoints are implicit — e.g., no explicit 'verify the tool call succeeds after deploy' step, and the 'agentcore logs' recovery guidance is tucked into Troubleshooting rather than the path workflows.

4 / 5

Progressive Disclosure

The one bundle reference (references/policy.md, which exists) is clearly signaled, but the ~550-line body inlines substantial material that belongs in separate reference files — the auth matrix with per-type 3LO/IAM boto3 detail, the semantic-search feature guide, custom-header passing, and the full Path D credential/decorator guide. This matches 'some structure but… content that should be separate is inline'; it is above the buried-reference anchors but below the well-split 4–5 anchors.

3 / 5

Total

14

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete capability list, explicit 'Use when' guidance, a rich natural-language trigger list, and explicit negative boundaries against sibling skills. Every phrase earns its place despite the length; the only nit is that the trigger list is longer than strictly necessary, which costs nothing on clarity.

DimensionReasoningScore

Specificity

The description lists multiple concrete capabilities — 'gateway setup, target types, outbound auth (OAuth, API key, IAM), credentials, and Cedar policy authoring' — with no vague filler, matching the comprehensive-coverage anchor. It is not merely naming the domain; each named function is a distinct actionable capability.

5 / 5

Completeness

It explicitly answers both 'what' ('Handles gateway setup, target types, outbound auth…') and 'when' ('Use when connecting your agent to external APIs…' plus the concrete trigger list), which is the exact shape of the 5-anchor example. The 'Not for…' clauses add further use-conditions rather than padding.

5 / 5

Trigger Term Quality

An explicit 'Triggers on:' list gives ~17 natural phrases a user would actually say ('connect to API', 'add gateway', 'store API key', 'give my agent tools', 'API key None after deploy'), covering synonyms, commands, and even error-message phrasings. This exceeds the comprehensive-coverage anchor's bar for natural term variation.

5 / 5

Distinctiveness Conflict Risk

Four explicit disambiguation clauses ('Not for inbound auth — use agents-harden', 'Not for debugging agent behavior — use agents-debug', 'Not for VPC networking errors… use agents-build', 'Not for creating or hosting a new MCP server project — use agents-get-started') carve out a clear niche with minimal conflict risk. The trigger terms (Gateway, Cedar policy, credential) are specific to this skill's domain.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (557 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 4 suspicious

Warning

Total

14

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.