CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-security

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured routing skill with concrete, executable guidance and an excellent one-level-deep reference organization where all bundle files are real and clearly signaled. It is slightly verbose in its global-rules and security-considerations sections, and workflow validation is implicit rather than explicit per-path validate-fix-retry loops.

DimensionReasoningScore

Conciseness

The body is mostly lean — a routing registry, disambiguation table, and on-demand reference table — with no padding of concepts Claude already knows, but the nine global rules plus a separate security-considerations section add length that could be tightened or partly delegated to references.

4 / 5

Actionability

Provides concrete, executable routing instructions ('read references/{sub-skill-id}.md and follow its procedure'), standard AWS CLI syntax, and named commands such as get-coverage-statistics, list-automation-rules-v2, and 'list-policies --filter', covering the common cases directly.

5 / 5

Workflow Clarity

'How this skill works' gives a clear 4-step sequence with an explicit routing checkpoint and a 'Verify, don't guess' feedback rule, but validation steps are framed as routing discipline rather than explicit validate-then-proceed loops for each operational path.

4 / 5

Progressive Disclosure

Excellent two-tier structure: SKILL.md is an overview/router with well-signaled, one-level-deep references, and every referenced file (e.g. guardduty-findings.md, security-hub-cspm-configuration.md) exists in references/ with clear 'When to Route/Load' guidance, making navigation easy.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, complete, and well-differentiated, clearly stating what the skill covers and when to use it in third person. Trigger-term coverage is strong but slightly jargon-heavy and lacks common synonyms/extensions, which is the only meaningful gap.

DimensionReasoningScore

Specificity

Lists multiple concrete services and actions — Security Hub V2 (OCSF) findings/connectors/aggregators/automation rules, CSPM controls, GuardDuty/Inspector/Macie/Detective findings, Security Lake aggregation — giving comprehensive, specific coverage rather than vague language.

5 / 5

Completeness

Explicitly answers both 'what' (the enumerated AWS security service workflows) and 'when' via the 'Applicable when questions involve...' clause with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Includes strong natural phrases ('security posture', 'Exposure findings', 'CSPM failed controls', 'threat findings', 'vulnerability findings', 'sensitive data findings', 'automation rules'), but the set leans toward service jargon and omits common synonyms or file-extension-style triggers a user might naturally say.

4 / 5

Distinctiveness Conflict Risk

Carves a clear AWS cross-service security niche with distinct triggers (OCSF/ASFF, Exposure findings, attack sequences), making conflict with unrelated skills minimal.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.