CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-iam

Provides verified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits, Organizations quirks, and SAML/MFA specifics. Also provides structured workflows for IAM role management and baseline policy generation from application source code or a Terraform plan JSON. Covers condition operator safety (ForAnyValue/ForAllValues with Null checks), bucket policy deny patterns (VPC endpoint restrictions, org paths), confused deputy protection, and service role creation for AWS services (Glue, CloudTrail, Lambda, ECS, etc.) with aws:SourceAccount/aws:SourceArn trust conditions. Applies when creating IAM roles, writing IAM or bucket policies, generating policies from application source code or a Terraform plan JSON, working with STS, Organizations, or condition operators, or any task needing a service or execution role. Does not cover non-IAM authorization like Cognito user-pool policies or app-level RBAC.

76

Quality

95%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A high-quality, token-efficient body: dense verified corrections with exact API names, commands, and a copy-paste policy example, with detailed workflows correctly delegated to reference files. The weaker spots are structural — two of the four bundle files are invisible from SKILL.md (reachable only two levels deep) and the body's workflow routing lacks explicit validation checkpoints.

Suggestions

Surface references/common-pitfalls.md and references/service-authorization.md from SKILL.md (e.g., add condition-gated 'Read ... if ...' entries in Common Workflows) so all bundle files are discoverable one level deep instead of only via links inside aws-iam-policy-generation.md.

Add explicit validation checkpoints to the body's workflow routing — e.g., after role creation, verify assumability/policy attachment (such as a simulate-principal-policy or get-role check) — since verification currently lives only implicitly in the reference files.

Replace the hint-style 'Instance profiles: waiter + time.sleep(10) pattern' bullet with the concrete code or command sequence, and deduplicate the ForAllValues/Null JSON example between the body and common-pitfalls.md so each fact lives in one place.

DimensionReasoningScore

Conciseness

The body is a lean catalog of corrections Claude cannot reliably recall from pre-training — 'AcceptHandshake/DeclineHandshake logged in ACTING account ONLY', 'DuplicatePolicyAttachmentException (not PolicyAlreadyAttachedException)', 'Role chaining: max 1-hour session' — with zero padding and no explanation of IAM basics. Every bullet earns its place, matching the 5 anchor.

5 / 5

Actionability

Guidance is concrete and executable: exact API and exception names, a runnable CLI command ('aws organizations list-available-policy-types'), exact boto3 methods ('activate(), deactivate(), delete() — NO update()'), a complete copy-paste JSON policy for the ForAllValues/Null pattern, and documentation URLs. For an instruction/corrections skill this matches the 5 anchor; only one bullet ('waiter + time.sleep(10) pattern') is hint-style, which is not enough to drop to 4.

5 / 5

Workflow Clarity

'Common Workflows' provides clear conditional routing ('Read references/aws-iam-role-management.md if the user needs to create, scope, or maintain IAM roles') and the destructive account-closure case has explicit ordering ('Remove FIRST, then close'), but validation checkpoints are implicit in the body — the actual multi-step workflows and their verification steps live in the reference files. This sits between anchors 3 and 4, closer to 4: routing is unambiguous but body-level checkpoints are missing.

4 / 5

Progressive Disclosure

SKILL.md is a proper overview with well-signaled, condition-gated references to two files, but the bundle contains two more files (references/common-pitfalls.md and references/service-authorization.md) that are only discoverable via second-level links inside aws-iam-policy-generation.md, and the ForAllValues Null-check pattern is duplicated between the body and common-pitfalls.md. This matches anchor 4 ('most content appropriately placed; minor organization gaps') rather than 5's fully one-level-deep structure.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete capabilities, an explicit 'Applies when' trigger clause with natural synonyms, and explicit scope exclusions, all in third-person voice. The only (dimension-external) critique is length — at roughly 900 characters it is denser than typical, though every clause carries information rather than padding.

DimensionReasoningScore

Specificity

The description lists many concrete capabilities — 'verified corrections for IAM behaviors... policy evaluation edge cases, trust policy gotchas, STS session limits', 'condition operator safety (ForAnyValue/ForAllValues with Null checks)', 'confused deputy protection', and 'service role creation... with aws:SourceAccount/aws:SourceArn trust conditions' — comprehensive and entirely free of vague language. It exceeds the 4 anchor ('several specific actions; minor gaps') because coverage spans corrections, workflows, and generation with no apparent gap.

5 / 5

Completeness

It explicitly answers both questions: 'what' via three sentences of concrete capabilities and 'when' via the explicit 'Applies when...' trigger clause, and even adds scope boundaries ('Does not cover non-IAM authorization like Cognito user-pool policies or app-level RBAC'). This is a direct match for the 5 anchor; the 4 anchor's 'when could be more explicit' does not apply.

5 / 5

Trigger Term Quality

The 'Applies when' clause uses natural phrases users would say — 'creating IAM roles, writing IAM or bucket policies, generating policies from application source code or a Terraform plan JSON, working with STS, Organizations, or condition operators, or any task needing a service or execution role' — including synonyms (IAM/bucket policies, service/execution role). This matches the comprehensive-synonyms anchor; score 4 would require noticeably missing common terms, which is not the case.

5 / 5

Distinctiveness Conflict Risk

It occupies a clear AWS IAM niche with distinct triggers (IAM roles, bucket policies, STS, Organizations, Terraform plan JSON) and explicitly excludes adjacent domains ('Does not cover non-IAM authorization like Cognito user-pool policies or app-level RBAC'), minimizing overlap with security or Terraform-generic skills. Score 4's 'minor overlap risk with closely related skills' is not evidenced.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.