CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-secrets-manager

Secret safety for AWS Secrets Manager, secret management, credentials, API keys, tokens, and passwords. Prevents AI agents from directly fetching secret values and teaches runtime dynamic references with asm-exec so plaintext never enters the LLM context window.

56

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/aws-core/skills/aws-secrets-manager/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body with excellent executable examples and thoughtful error-recovery guidance. Its main weaknesses are inlined implementation internals that inflate token cost and a bundle file (references/asm-exec) that is never referenced by path, leaving a gap in how the agent locates and invokes the wrapper.

Suggestions

Reference the script explicitly, e.g. 'The wrapper lives at references/asm-exec; copy it to PATH or invoke it as `python references/asm-exec -- <command>`', so the agent can actually run it.

Move the 'SigV4 signing' internals and 'How It Works' resolution mechanics into a short reference beside the script (the script's docstring already covers much of it) and keep only the resolution order and security note in SKILL.md.

Add a pre-flight validation step before first use (e.g. check SMA on localhost:2773 or 'aws sts get-caller-identity') to complete the workflow's checkpoint sequence.

DimensionReasoningScore

Conciseness

The rules, syntax table, and usage examples are lean, but sections like 'SigV4 signing' (credential resolution order, service/region inference from hostname) and 'How It Works' (re.sub callable mechanics, subprocess internals) explain implementation details the agent never acts on — these belong in or alongside the bundled script. Not 4 because two full paragraphs of signing internals and resolution-order mechanics are clearly trimmable; not 2 because there is no padding explaining concepts Claude already knows.

3 / 5

Actionability

Concrete, copy-paste-ready bash examples covering psql, curl, mysql, docker, and config templating, plus a precise syntax table and actionable troubleshooting (specific stderr formats, 'aws sts get-caller-identity', ASM_EXEC_MCP_TIMEOUT). Not 5 because the skill never states where the asm-exec script lives or how to make it invokable — the references/asm-exec bundle file is not mentioned by path, so the agent cannot fully execute the guidance unaided.

4 / 5

Workflow Clarity

The usage pattern is unambiguous (MUST NOT fetch directly; MUST use {{resolve:...}} via asm-exec), and the troubleshooting section provides a genuine feedback loop (read the stderr cause line first, check credentials/region/permissions, interpret 401 vs. missing secret, raise timeout). Not 5 because there is no pre-flight checkpoint (verify SMA is running or credentials are resolvable before first use) and no guidance on obtaining/invoking the script itself; well above 3 since error recovery is explicit and the single action is clear.

4 / 5

Progressive Disclosure

Sections are well-organized, but the bundle contains references/asm-exec and the body never signals that path — 'How It Works' and 'SigV4 signing' implementation detail is inlined in SKILL.md where a one-level-deep reference to the script (or a short README for it) belongs. Fits anchor 3 ('references present but not clearly signaled; content that should be separate is inline'); not 4 because the sole bundle file is unreferenced and navigable discovery of it depends on guesswork.

3 / 5

Total

14

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A focused, third-person description with strong natural trigger terms and a distinct niche. Its main weakness is the missing 'Use when...' trigger clause, which caps completeness, and a capability list that names only two concrete actions.

Suggestions

Add an explicit trigger clause, e.g. 'Use when an agent needs to use secrets, credentials, API keys, tokens, or passwords with AWS Secrets Manager — for database connections, API authentication, or container configuration.'

Broaden trigger-term coverage with natural synonyms users would say: 'secrets', 'environment variables', 'get-secret-value', 'rotate/retrieve credentials'.

Enumerate one or two more concrete capabilities (e.g. resolving references in Docker env vars or config-file templating) to lift specificity.

DimensionReasoningScore

Specificity

Names the domain ('AWS Secrets Manager, secret management, credentials, API keys, tokens, and passwords') and two concrete actions ('Prevents AI agents from directly fetching secret values and teaches runtime dynamic references with asm-exec'), but coverage is not comprehensive — resolution backends, config templating, and enforcement hook capabilities are absent. Not 4 because only two actions are listed with minor gaps beyond domain naming; not 2 because the actions are genuinely concrete, not generic.

3 / 5

Completeness

The 'what' is clear (prevents direct secret fetching, teaches runtime dynamic references with asm-exec so plaintext never enters the LLM context window), but there is no 'Use when...' clause or equivalent explicit trigger guidance — the rubric guideline caps this at 3. Not 4 because the 'when' is entirely absent rather than merely imprecise.

3 / 5

Trigger Term Quality

Good natural keyword coverage: 'credentials', 'API keys', 'tokens', 'passwords', 'secret management', 'AWS Secrets Manager' — phrases users would naturally say. Not 5 because common variations like 'secrets', 'environment variables', or tool-specific phrases (e.g. 'get-secret-value') are missing; clearly above 3 since synonyms beyond the bare domain name are present.

4 / 5

Distinctiveness Conflict Risk

A clear niche — preventing agents from fetching AWS Secrets Manager values and resolving them at runtime via asm-exec — with distinct triggers unlikely to fire for unrelated skills. Not 5 because generic terms like 'credentials', 'API keys', and 'passwords' could overlap with other secret-handling or security skills; well above 3 given the highly specific behavioral framing.

4 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.