CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-network-monitoring

Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. Covers agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/specialized-skills/operations-skills/aws-network-monitoring/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured index-style SKILL.md with excellent progressive disclosure and concrete, actionable routing details. Its weaknesses are minor redundancy between the Routing and Files tables and the absence of an explicit end-to-end workflow sequence with validation checkpoints in the body itself.

Suggestions

Merge the Routing and Files tables into one table (columns: user need, file, content summary) to eliminate near-duplicate content and save tokens.

Add a brief 4-5 step end-to-end sequence in the body (attach IAM policy → install via SSM Distributor or CLI → activate (SSM path only) → verify metrics publishing), with an explicit verification checkpoint, so the top-level workflow is not implicit in the references.

Trim the second Overview paragraph ("Network Flow Monitor agents are lightweight software that publish performance metrics...") to a single clause, since the metrics-publishing purpose is already implied by the routing entries.

DimensionReasoningScore

Conciseness

The body is lean and mostly non-padded, but the Routing table ("Installing Network Flow Monitor agents... Read agent-install-ec2.md") and the Files table ("agent-install-ec2.md | End-to-end... installation") largely duplicate each other, and the Overview restates the frontmatter description. This matches the 4 anchor (efficient, minor instances that could be trimmed) rather than 5 (every token earns its place) because the two tables could be merged.

4 / 5

Actionability

The body is a router, but it routes concretely: specific file paths per user need, exact policy names ("CloudWatchNetworkFlowMonitorAgentPublishPolicy", "AmazonSSMManagedInstanceCore"), and exact VPC endpoint patterns ("com.amazonaws.<region>.ssm"). This is mostly executable guidance with minor gaps (the actual commands live in the references), matching 4 rather than 5 (copy-paste ready commands in the body itself) or 3 (incomplete/pseudocode).

4 / 5

Workflow Clarity

The multi-step process (IAM setup → install → activate → verify → troubleshoot) exists with validation steps in the references (e.g. agent-install-ec2.md "Step 1: Verify SSM connectivity"), but the body itself presents only a need-based routing table with no sequenced workflow or checkpoints. This lands at the 3 anchor (sequence present but checkpoints implicit/missing at the top level) — not 4, since the body never surfaces the install-order dependency (IAM before install) that the references carry.

3 / 5

Progressive Disclosure

Clear overview with well-signaled one-level-deep references: the Routing table maps each user need to a specific file, all three referenced files (agent-install-ec2.md, agent-permissions.md, troubleshooting.md) exist in references/, and cross-references between them are sibling-level, not nested. Matches the 5 anchor (clear overview, easy navigation, appropriate split) — the body is an index and the detail is correctly externalized.

5 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, well-scoped description with strong trigger terms and near-zero conflict risk, written in third person. Its main weakness is the missing explicit "Use when..." trigger clause, which caps completeness at 3.

Suggestions

Add an explicit trigger clause, e.g. "Use when installing or setting up CloudWatch Network Flow Monitor agents on EC2, or when agents report no metrics, HTTP 403 errors, or connectivity failures."

Include a few natural synonyms users might say, such as "CloudWatch Network Flow Monitor", "packet loss", or "latency", to broaden trigger-term coverage.

Lead with the full product name "Amazon CloudWatch Network Flow Monitor" at least once so searches for "CloudWatch" match the skill.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — "Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances" plus "agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures" — with comprehensive coverage including specific failure modes. It clearly matches the 5 anchor (multiple specific concrete actions, comprehensive) rather than 4, which allows minor coverage gaps.

5 / 5

Completeness

The "what" is explicit ("Installs, configures, and troubleshoots Network Flow Monitor agents...") but there is no "Use when..." clause or equivalent explicit trigger guidance, which per the judging guidelines caps completeness at 3. It is not a 4 because the "when" is only weakly implied by the listed coverage areas, never stated as usage guidance.

3 / 5

Trigger Term Quality

Good natural-term coverage: "agents reporting no metrics", "HTTP 403 errors", "connectivity failures", "IAM permissions" are phrases users would plausibly say. A few natural variants are missing (e.g. "CloudWatch", "packet loss", "latency", "network path"), so it falls at the 4 anchor (good coverage, a few natural terms missing) rather than 5 (comprehensive synonyms/extensions).

4 / 5

Distinctiveness Conflict Risk

"Network Flow Monitor agents on EC2 instances" carves out a clear niche with distinct triggers (403 errors, no metrics, agent installation) and minimal overlap with generic monitoring or EC2 skills. Matches the 5 anchor (clear niche, minimal conflict risk); it is not generic or broad enough to fall to 3 or 4.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.