CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-lambda-microvms

Builds, runs, debugs, and operates applications on AWS Lambda MicroVMs — Firecracker-isolated, snapshot-resumable serverless compute environments running inside a container with up to 8 hr lifetimes. Applicable when workloads need strong isolation between tenants, isolated serverless compute, sandbox compute, or secure multi-tenant execution. Also suited for AI/agent code-execution sandboxes, interactive code playgrounds and notebooks (Jupyter, REPLs, dev environments running user-supplied code), reinforcement-learning environments, multi-tenant CI executors and build runners, sessionful game or simulation servers, or isolated security scanners. Also applicable when the workload needs long-lived sessions, a real port-listening server (gRPC, WebSocket, custom TCP protocols), state preserved across periods of inactivity (suspend/resume), container-level access (FUSE, eBPF, custom syscalls), or session-affine routing.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body with excellent progressive disclosure — real reference files, one level deep, indexed by task — and copy-paste-ready CLI examples throughout. The main weakness is redundancy: the When-to-use section and hook callouts duplicate content already present in the description and hook tables, costing tokens without adding guidance.

Suggestions

Compress the "When to use" section: the bulleted workload list restates the frontmatter description almost verbatim — keep only the two comparison subsections (vs. Lambda functions, vs. ECS/EC2) which add genuinely new decision guidance.

Delete the "Why implement /ready?" and "Why implement /validate?" blockquotes — they restate the purpose column of the hook table directly above them; fold the prefetch detail into the table cell if it is not already there.

Add an explicit validation checkpoint to the main workflow between CreateMicrovmImage and RunMicrovm (e.g., wait for the build to reach ACTIVE / check build status), so the sequence doesn't rely on the getting-started reference for error recovery.

DimensionReasoningScore

Conciseness

The body is mostly dense tables and executable commands, but the "When to use" bullet list repeats the frontmatter description almost verbatim, and the "Why implement /ready? / /validate?" callouts restate the already-verbose hook table cells. This matches the anchor of mostly efficient content that includes unnecessary explanation and could be tightened.

3 / 5

Actionability

Fully executable, copy-paste-ready CLI blocks: create-microvm-image, run-microvm with concrete flag values, token minting via --query, curl, and websocat WebSocket invocation — specific commands cover the common cases, matching the top anchor.

5 / 5

Workflow Clarity

The numbered 0–6 workflow is a clear, correctly-ordered sequence with concrete commands, and hooks provide implicit checkpoints (/ready, /validate). It falls short of anchor 5 because explicit wait-and-verify steps (e.g., confirming the image build succeeded before RunMicrovm) are deferred to the reference file rather than stated as checkpoints in the main flow.

4 / 5

Progressive Disclosure

SKILL.md is a genuine overview: six one-level-deep reference files, all of which exist on disk, each with a task-matched one-line description in the Reference index ("Pick the reference that matches your task"). This matches the clear-overview anchor with well-signaled, easily navigable references.

5 / 5

Total

17

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that answers what and when explicitly, with unusually rich natural-language trigger coverage spanning AI sandboxes, notebooks, CI runners, game servers, and security scanners. The only weaknesses are minor: capability enumeration stops short of full coverage and a few broad trigger phrases could over-fire on generic sandboxing requests.

DimensionReasoningScore

Specificity

Lists several concrete actions ("Builds, runs, debugs, and operates applications") plus concrete capability detail ("Firecracker-isolated, snapshot-resumable", "up to 8 hr lifetimes"), but stops short of the comprehensive anchor-5 coverage of capabilities such as image building, auth tokens, or lifecycle control.

4 / 5

Completeness

Explicitly answers both what ("Builds, runs, debugs, and operates applications on AWS Lambda MicroVMs...") and when ("Applicable when...", "Also suited for...", "Also applicable when...") with concrete trigger phrases, matching the anchor-5 example structure. It is long, but each clause is a distinct trigger scenario rather than padding.

5 / 5

Trigger Term Quality

Comprehensive natural trigger terms with synonyms: "sandbox compute", "code playgrounds and notebooks (Jupyter, REPLs)", "multi-tenant CI executors and build runners", "game or simulation servers", "security scanners", "gRPC, WebSocket" — matches the comprehensive-synonyms anchor, and none of it is pure jargon.

5 / 5

Distinctiveness Conflict Risk

Clear niche anchored to a named AWS service with distinct triggers, but broad phrases like "sandbox compute" and "secure multi-tenant execution" create minor overlap risk with generic sandboxing or container skills that would fire on requests not actually needing this service.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.