CtrlK
BlogDocsLog inGet started
Tessl Logo

cloudfront

Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a distribution, caching, and Flat Rate Pricing (FRP) versus pay-as-you-go pricing); managing custom-domain TLS certificates (ACM in us-east-1); configuring multi-tenant distributions; protecting origins with origin access control (OAC), VPC origins, and origin mutual TLS (mTLS); securing content with signed URLs and cookies, geographic restrictions, viewer mutual TLS, and edge token validation; and observing traffic with standard and real-time logs. Applicable when the customer wants to put CloudFront in front of content, choose pricing, lock an origin, restrict who can view content, or analyze logs. Not applicable for the Route 53 DNS side of a CloudFront custom domain or failover between distributions (see the route53-cloudfront skill), or for pure-Route 53 DNS work (see the route53 skill).

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-designed router: it routes every task to a real, one-level-deep reference file, gives concrete execution and region guidance, and disambiguates the tricky cases. The minor costs are slight redundancy between the overview, description, and routing notes, and the absence of any inline executable example or validation checkpoint in the body itself.

DimensionReasoningScore

Conciseness

The body is a lean router that assumes competence — it explains no CloudFront basics and spends its tokens only on non-obvious facts ('its API calls... are made in us-east-1', 'Execute commands using the AWS MCP server when connected... Fall back to the AWS CLI otherwise'). It is not a 5 because the Overview paragraph and parts of the Routing notes repeat information already carried by the description and the routing table.

4 / 5

Actionability

Concrete, executable guidance for a router: a goal-to-reference table ('Make CloudFront the only way to reach the origin (S3 OAC, VPC origins...) → protecting-your-origins.md'), explicit execution instructions (MCP server first, AWS CLI fallback), and the us-east-1 region rule. It is not a 5 because the body itself contains no commands or examples — everything executable lives in the references — though the routing guidance itself is specific rather than vague.

4 / 5

Workflow Clarity

The process is stated unambiguously ('Read the matching reference in full before acting, then follow its constraints and steps') and the Routing notes resolve the confusing pairs (viewer vs origin mTLS, protecting origins vs securing content, DNS cutover ownership). It is not a 5 because the body delegates all validation and error-recovery steps to the references and offers no checkpoint of its own, and not a 3 because the sequence and edge-case handling are explicit rather than implicit.

4 / 5

Progressive Disclosure

Exemplary progressive disclosure: a concise overview, a routing table linking each goal to one of six one-level-deep reference files (all of which exist under references/ and are self-contained per the body's own claim), plus routing notes for disambiguation. Navigation is easy and nothing that belongs in a reference is inlined.

5 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it concretely enumerates capabilities across all six workflows, gives explicit positive and negative trigger conditions, and disambiguates against neighboring Route 53 skills. The only weakness is missing a few natural synonyms (CDN, cache, accelerate, edge) users might say.

DimensionReasoningScore

Specificity

The description enumerates concrete actions across all six workflows — 'creating a distribution, caching, and Flat Rate Pricing (FRP) versus pay-as-you-go pricing', 'origin access control (OAC), VPC origins, and origin mutual TLS (mTLS)', 'signed URLs and cookies, geographic restrictions, viewer mutual TLS, and edge token validation' — with comprehensive coverage and no vague filler. It exceeds the 4 anchor because there are no minor gaps in capability coverage.

5 / 5

Completeness

Both questions are answered explicitly: the 'what' is the six enumerated workflows, and the 'when' is the concrete trigger clause 'Applicable when the customer wants to put CloudFront in front of content, choose pricing, lock an origin, restrict who can view content, or analyze logs'. It also adds explicit 'Not applicable' boundaries, which exceeds the 4 anchor's 'when could be more explicit'.

5 / 5

Trigger Term Quality

Natural user phrases are present — 'put CloudFront in front of content', 'choose pricing', 'lock an origin', 'restrict who can view content', 'analyze logs' — giving good keyword coverage. It falls short of 5 because common synonyms a user might say, such as 'CDN', 'cache', 'accelerate content', or 'edge', are absent.

4 / 5

Distinctiveness Conflict Risk

The skill occupies a clear CloudFront-configuration niche and actively fences off adjacent skills ('see the route53-cloudfront skill', 'see the route53 skill'), minimizing conflict risk. It is not a 4 because overlap with the closely related Route 53 skills is not merely minor — it is explicitly disambiguated with named alternatives.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.