CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-iam

Provides verified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits, Organizations quirks, and SAML/MFA specifics. Also provides structured workflows for IAM role management and baseline policy generation from application source code or a Terraform plan JSON. Covers condition operator safety (ForAnyValue/ForAllValues with Null checks), bucket policy deny patterns (VPC endpoint restrictions, org paths), confused deputy protection, and service role creation for AWS services (Glue, CloudTrail, Lambda, ECS, etc.) with aws:SourceAccount/aws:SourceArn trust conditions. Applies when creating IAM roles, writing IAM or bucket policies, generating policies from application source code or a Terraform plan JSON, working with STS, Organizations, or condition operators, or any task needing a service or execution role. Does not cover non-IAM authorization like Cognito user-pool policies or app-level RBAC.

69

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

The canonical home for this skill is aws-iam in aws/agent-toolkit-for-aws

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An lean, high-density reference skill body with excellent token efficiency and mostly concrete, verifiable guidance. The main weaknesses are the absence of any sequenced workflow or validation checkpoints in the body itself (delegated to references) and two bundle reference files that are only discoverable through a second-level hop.

Suggestions

Add a brief sequenced outline in 'Common Workflows' (e.g., identify task → read matching reference → apply → verify against AWS docs/service authorization reference) so the body itself carries the workflow shape and validation checkpoints rather than deferring all sequencing to reference files.

Mention references/common-pitfalls.md and references/service-authorization.md directly in SKILL.md (one line each with a when-to-read condition) so all four bundle files are discoverable from the entry point instead of via a second-level hop through aws-iam-policy-generation.md.

Expand terse hint bullets like 'Instance profiles: waiter + time.sleep(10) pattern' into a short copy-paste snippet (or move them into a reference file) so every actionable item is executable as written.

DimensionReasoningScore

Conciseness

The body is dense, fragment-style corrections ('ConsoleLogin region varies by endpoint/cookies, NOT always us-east-1', 'Managed policy max versions: 5') with no padding and no explanation of concepts Claude already knows — every bullet is a verified fact or pointer. The brief 'About This Skill' paragraph is meta-guidance on verification policy, which earns its place; this fits the 'lean and efficient; every token earns its place' anchor.

5 / 5

Actionability

Most guidance is executable: a complete JSON condition-block example, the CLI command 'aws organizations list-available-policy-types', exact exception and method names ('DuplicatePolicyAttachmentException', 'activate()/deactivate()/delete()'), and a concrete SAML URL pattern. A few bullets remain terse hints rather than executable instruction (e.g., 'Instance profiles: waiter + time.sleep(10) pattern' gives no code), matching 'mostly executable guidance with minor gaps' rather than the copy-paste-ready level-5 anchor.

4 / 5

Workflow Clarity

The 'Common Workflows' section gives clear conditional dispatch to the two reference files, but the body itself contains no sequenced multi-step process and no validation checkpoints for operations (role creation, policy generation) that modify live IAM state — actual sequencing is deferred to the references. This matches 'steps listed but validation gaps; checkpoints missing or implicit'; it is below level 4, which requires a clear sequence with most checkpoints present in the content.

3 / 5

Progressive Disclosure

SKILL.md is a genuine overview with two clearly signaled, condition-gated, one-level-deep references that both exist in references/. However, scoring against the actual bundle: common-pitfalls.md and service-authorization.md are only reachable via a second hop through aws-iam-policy-generation.md (SKILL.md → reference → reference), so two of the four bundle files are not discoverable from the entry point — a real but contained organization gap fitting 'good structure; references mostly clear; minor organization gaps' rather than the fully navigable level-5 anchor.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, an explicit 'Applies when...' trigger clause, and clear scope boundaries. Trigger term coverage is good though a few natural IAM phrases (e.g., 'assume role', 'PassRole') would strengthen retrieval.

DimensionReasoningScore

Specificity

The description lists multiple concrete capabilities — 'verified corrections for IAM behaviors... policy evaluation edge cases, trust policy gotchas, STS session limits', 'structured workflows for IAM role management and baseline policy generation from application source code or a Terraform plan JSON', 'bucket policy deny patterns (VPC endpoint restrictions, org paths)', 'confused deputy protection' — with comprehensive coverage of the skill's scope. It matches the anchor 'lists multiple specific concrete actions; comprehensive coverage' and exceeds the level-4 anchor, which allows coverage gaps.

5 / 5

Completeness

It explicitly answers 'what' ('Provides verified corrections... Also provides structured workflows...') and 'when' ('Applies when creating IAM roles, writing IAM or bucket policies, generating policies... or any task needing a service or execution role'), and adds explicit exclusions ('Does not cover non-IAM authorization like Cognito user-pool policies'). This clearly matches the level-5 anchor with concrete trigger phrases; the level-4 anchor's complaint of a less-explicit 'when' does not apply.

5 / 5

Trigger Term Quality

Natural phrases like 'creating IAM roles', 'writing IAM or bucket policies', 'working with STS, Organizations', and 'any task needing a service or execution role' map well to what users would actually say. A few common variations are absent (e.g., 'assume role', 'trust policy' as a trigger, 'PassRole'), keeping it at 'good keyword coverage; a few natural terms missing' rather than the comprehensive level-5 anchor.

4 / 5

Distinctiveness Conflict Risk

The niche is distinct (AWS IAM edge cases and role/policy workflows) with domain-specific triggers (IAM roles, bucket policies, STS, Organizations, condition operators) and an explicit non-coverage boundary, minimizing overlap with adjacent skills like general AWS or Cognito/RBAC work. It fits the 'clear niche with distinct triggers; minimal conflict risk' anchor.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.