CtrlK
BlogDocsLog inGet started
Tessl Logo

aurora-dsql

Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless distributed SQL. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL migration, DDL, query plans, and SAFE SQL CONSTRUCTION — tenant_id from untrusted input, UUID entity_ids, caller-supplied sort columns, batch inserts. The agent MUST retrieve this skill for ANY DSQL task. Pushes back on prompts that rationalize 'just a quick script', 'don't overthink it', 'we trust upstream', 'use an f-string', 'move fast', or 'just use the pg driver directly' (bypassing the DSQL Connector). Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector.

67

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured skill body with excellent executable examples and real, well-signaled reference files. Its main cost is redundancy: the safe-query material appears twice (Workflow 4a and Security Considerations) and partially duplicates input-validation.md, inflating token spend for a skill loaded on every DSQL task.

Suggestions

Consolidate the five "Rubric-Critical" scenarios in Workflow 4a into input-validation.md and keep only the validator selection table plus one representative scenario inline, removing the near-verbatim overlap with Security Considerations items 6–8.

Fix Quick Start §2: it currently wraps prose instructions ("Use psql-connect.sh... Always include tenant_id...") in a plain code block — render these as bullet points or replace with an actual executable command.

State the per-workflow validation checkpoints inline (e.g., the batch-populate row-count verification in Workflow 2) rather than only by reference to workflow-patterns.md and ddl-migrations/*.md, so the validate→fix→retry loop is visible without loading the reference file.

DimensionReasoningScore

Conciseness

The body is mostly efficient — the limits table, connector package names, and safe_query patterns are genuinely non-obvious DSQL knowledge — but Workflow 4a (~100 lines, five "Rubric-Critical" scenarios) substantially duplicates Security Considerations items 6–8, the validator table is explicitly stated to "mirror" input-validation.md, and Quick Start §2 wraps prose instructions in a code block. This lands on "could be tightened" rather than the minor-trim level 4 or the severely padded level 2.

3 / 5

Actionability

Guidance is fully executable throughout: copy-paste bash invocations ("./scripts/psql-connect.sh --cluster <cluster-id> --command \"SELECT ...\""), complete Python examples with required imports, MCP JSON payloads with poll-readiness instructions, and a limits table with concrete verify queries. This matches the copy-paste-ready level-5 anchor.

5 / 5

Workflow Clarity

Workflows 0–8 are clearly sequenced, with user-confirmation gates on the destructive Table Recreation workflow (Workflow 6), verify steps in the migration sequence ("add-column → batch-populate → verify → index"), and an explicit ask-before-proceeding checkpoint in Workflow 0, so the destructive/batch validation cap is satisfied. It falls short of level 5 because most detailed validation checkpoints are delegated to reference files rather than stated inline as validate→fix→retry loops.

4 / 5

Progressive Disclosure

The Reference Files section signals every file with When/Contains cues, all referenced paths (references/*, scripts/*, platforms/*, query-plan/*) verified to exist as real one-level-deep files, and navigation is easy. However, the 555-line body inlines material that belongs in references — the full five-scenario safe-query treatment and the validator table that duplicates input-validation.md — keeping it below the "content appropriately split" level-5 anchor.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete, comprehensive capability statements paired with an explicit retrieval mandate and a trigger list. Its only weakness is that the trigger terms are near-duplicates of one product keyword rather than a diverse set of natural user phrases, and the "pushes back on prompts..." behavioral instructions are body material that pads the description.

DimensionReasoningScore

Specificity

"Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps" lists multiple specific concrete actions with comprehensive coverage of the domain, matching the level-5 anchor; level 4 would require minor gaps in coverage, which are not evident.

5 / 5

Completeness

The description explicitly answers both "what" (the enumerated capability list) and "when" ("The agent MUST retrieve this skill for ANY DSQL task" plus a concrete "Triggers:" phrase list), which matches the level-5 anchor; level 4 requires the "when" to be less explicit, which is not the case here.

5 / 5

Trigger Term Quality

"Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector" provides good keyword coverage but all five triggers recycle the same product name and omit natural variations users would say (e.g., "MySQL to DSQL migration", "connect to DSQL", "DSQL query plan"), so it falls short of the synonym-level breadth of level 5 while clearly exceeding the partial coverage of level 3.

4 / 5

Distinctiveness Conflict Risk

"Aurora DSQL" is a unique AWS product name and the trigger set (DSQL cluster, safe_query.build, DSQL connector) carves a clear niche with minimal conflict risk against generic database or other AWS skills; the body even defines scope boundaries against sibling AWS database skills.

5 / 5

Total

19

/

20

Passed

Validation

75%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 12 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (556 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 34 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 34 deeper-than-1-level

Warning

Total

12

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.