CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-cloudformation

Authors, validates, and troubleshoots AWS CloudFormation templates. Covers template authoring with secure defaults, local validation with either cfn-lint or cloudformation-validate, cfn-guard security and compliance checks as a recommended default, account-aware CloudFormation service pre-deployment validation, CloudFormation Express mode for faster deployments, and root-cause diagnosis of failed stacks using CloudFormation events and CloudTrail correlation. Also covers author-time template intelligence with the CloudFormation Language Server and published cloudformation-validate libraries.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./plugins/aws-core/skills/aws-cloudformation/SKILL.md

The canonical home for this skill is aws-cloudformation in aws/agent-toolkit-for-aws

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured index-style skill body: concrete commands and defaults, explicitly sequenced workflows with mandatory safety gates, and exemplary progressive disclosure into a verified flat reference bundle. The main cost is token efficiency — repeated boilerplate across the six safety sections and a verbose install-mode guardrail could be condensed without losing clarity.

Suggestions

Collapse the six safety sections' repeated 'You MUST follow the ... procedure in template-safety-guidance.md before advising or editing' sentence into a single stated rule with per-section links, saving ~10 lines of duplicated boilerplate.

Condense the MCP-vs-local-install guardrail to its two resolution rules and the 'never fetch or write customer data' constraint; the examples of mistaken local-file matches can be trimmed.

Inline one or two explicit validation checkpoints (e.g. 'run cfn-lint, fix, re-run until clean') in the validate-before-deploy section so the feedback loop is visible in the body, not only in the referenced guide.

DimensionReasoningScore

Conciseness

The body is dense and never explains concepts Claude already knows, but it could be tightened: the six safety sections each repeat the identical formula 'You MUST follow the ... procedure in [template-safety-guidance.md](references/template-safety-guidance.md) before advising or editing', and the ~20-line MCP-vs-local-install guardrail could be halved. This is 'mostly efficient but includes some... could be tightened' (3) rather than the 4 anchor, where over-explanation would be only minor.

3 / 5

Actionability

Concrete, executable specifics throughout: '--deployment-config "{\"mode\": \"EXPRESS\"}" on create-stack', 'cdk deploy --express', 'wc -c' for size limits, 'list-imports' before touching exports, '!Sub "${AWS::StackName}-..."', '{{resolve:secretsmanager:...}}', and named S3 properties ('PublicAccessBlockConfiguration (all four true)'). Mostly executable with minor gaps (no complete example template inline — detail is correctly delegated to SOPs), so 4 rather than the copy-paste-comprehensive 5.

4 / 5

Workflow Clarity

The authoring task is explicitly sequenced (retrieve embedded context → best-practices checklist → property lookup → persist context → attribution marker) with mandatory pre-edit gates ('Before touching any Export, you MUST check list-imports') and a destructive-operation guard ('Run destructive operations... only on direct user instruction'). It is not 5 because the validate→fix→retry feedback loops themselves live in the referenced SOPs rather than being stated as explicit checkpoints in the body.

4 / 5

Progressive Disclosure

A clear overview with well-signaled one-level-deep references: all ten inline links (e.g. references/validation-tool-selection.md, references/persist-template-context.script.md, references/template-safety-guidance.md) resolve to real bundle files, the Decision Guide table maps user intents to SOPs, and cross-links between reference files are flat sibling links — the validation-tool-selection guide acts as a clean sub-index for the validator SOPs. Content is appropriately split with key points inline and detail in files, matching the 5 anchor; it does not fall to 4 since navigation is easy and no reference is buried or nested.

5 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, tool-rich description that comprehensively states what the skill does with minimal conflict risk. Its one structural weakness is the complete absence of a 'Use when...' trigger clause, which caps completeness at 3 and leaves trigger-term coverage short of synonyms and file extensions.

Suggestions

Append an explicit trigger clause, e.g. 'Use when the user mentions CloudFormation, CloudFormation templates/stacks, cfn-lint, cfn-guard, stack deployment failures, or wants to validate or troubleshoot a CloudFormation template.'

Add natural synonyms and format terms users actually say — 'stacks', 'YAML/JSON templates', 'infrastructure as code'/'IaC' — to broaden trigger-term coverage.

Trim the dense enumeration in the second sentence; a shorter tool list plus the trigger clause would read more naturally without losing specificity.

DimensionReasoningScore

Specificity

Lists multiple concrete actions with named tools across the full lifecycle — 'Authors, validates, and troubleshoots AWS CloudFormation templates', 'local validation with either cfn-lint or cloudformation-validate', 'cfn-guard security and compliance checks', 'CloudFormation Express mode', 'root-cause diagnosis of failed stacks using CloudFormation events and CloudTrail correlation'. Coverage is comprehensive rather than having minor gaps, so it matches the 5 anchor, not the 4.

5 / 5

Completeness

The 'what' is clear and detailed, but there is no 'Use when...' clause or equivalent explicit trigger guidance anywhere in the description — 'when' is only weakly implied by the domain. Per the rubric guideline this caps completeness at 3; it cannot reach 4, which requires both what and when.

3 / 5

Trigger Term Quality

Good natural keyword coverage ('CloudFormation templates', 'validate', 'deploy', 'failed stacks', 'cfn-lint', 'cfn-guard', 'troubleshoots'), but common variations users would say — 'infrastructure as code'/'IaC', 'YAML'/'JSON' templates, file extensions, 'stack' beyond 'failed stacks' — are absent. Fits 'good keyword coverage; a few natural terms missing' rather than the 5 anchor's synonym/extension comprehensiveness.

4 / 5

Distinctiveness Conflict Risk

'AWS CloudFormation templates' is a clear niche with distinct triggers, and tool names (cfn-lint, cfn-guard, CloudFormation Express mode, CloudFormation Language Server) further pin it to this one domain. Minimal conflict risk with adjacent skills (e.g., CDK or Terraform), matching the 5 anchor; it is not merely 'mostly distinct' as in the 4 anchor.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.