CtrlK
BlogDocsLog inGet started
Tessl Logo

cloudfront

Configures Amazon CloudFront content delivery across six workflows: when to use CloudFront and how it fits with AWS WAF, Shield, CloudFront Functions, Lambda@Edge, Route 53, and origins (creating a distribution, caching, and Flat Rate Pricing (FRP) versus pay-as-you-go pricing); managing custom-domain TLS certificates (ACM in us-east-1); configuring multi-tenant distributions; protecting origins with origin access control (OAC), VPC origins, and origin mutual TLS (mTLS); securing content with signed URLs and cookies, geographic restrictions, viewer mutual TLS, and edge token validation; and observing traffic with standard and real-time logs. Applicable when the customer wants to put CloudFront in front of content, choose pricing, lock an origin, restrict who can view content, or analyze logs. Not applicable for the Route 53 DNS side of a CloudFront custom domain or failover between distributions (see the route53-cloudfront skill), or for pure-Route 53 DNS work (see the route53 skill).

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exemplary router: lean, well-structured, with a clear decision table routing to six self-contained reference files and helpful disambiguation notes. The only mild gap is that validation/feedback loops and detailed executable steps live in the references rather than the body, which is appropriate for a router but leaves workflow clarity and actionability just short of full marks.

DimensionReasoningScore

Conciseness

A lean router body that assumes Claude's competence ("This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting"), with no padding or explanation of concepts Claude already knows; the routing notes add genuine disambiguation value rather than fluff.

5 / 5

Actionability

Concrete, actionable routing via a decision table mapping goals to specific linked reference files plus a clear execution instruction ("Execute commands using the AWS MCP server when connected ... Fall back to the AWS CLI otherwise"), but the detailed executable steps themselves are delegated to the reference files, leaving minor gaps in the body.

4 / 5

Workflow Clarity

The routing sequence is clear and unambiguous (identify goal -> match reference -> read in full -> follow its constraints and steps), but the body itself carries no validation checkpoints or feedback loops since those live in the per-task reference files.

4 / 5

Progressive Disclosure

A clean overview body points to six well-signaled, one-level-deep reference files via a goal-to-reference table; references are real, self-contained, and only cross-reference sibling files rather than nesting, matching the anchor for clear overview with easy navigation.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is comprehensive and well-structured, clearly stating capabilities across six workflows with explicit when-to-use and when-not-to-use boundary guidance. Trigger phrasing is strong but slightly service-flavored rather than mirroring the full range of natural user synonyms.

DimensionReasoningScore

Specificity

Lists multiple concrete actions per workflow ("creating a distribution, caching", "protecting origins with origin access control (OAC), VPC origins, and origin mutual TLS", "securing content with signed URLs and cookies, geographic restrictions, viewer mutual TLS, and edge token validation", "observing traffic with standard and real-time logs") with comprehensive coverage across six workflows.

5 / 5

Completeness

Explicitly answers both what ("Configures Amazon CloudFront content delivery across six workflows: ...") and when ("Applicable when the customer wants to ..."), plus negative boundary guidance, matching the anchor for concrete trigger phrases on both.

5 / 5

Trigger Term Quality

Strong natural keywords (CloudFront, custom domain, TLS certificates, signed URLs, pricing, logs) and a concrete trigger clause ("Applicable when the customer wants to put CloudFront in front of content, choose pricing, lock an origin, restrict who can view content, or analyze logs"), but phrasing leans service-oriented rather than mirroring varied user synonyms, so it falls short of comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

Clear CloudFront niche with explicit de-scoping ("Not applicable for the Route 53 DNS side of a CloudFront custom domain ... see the route53-cloudfront skill, or for pure-Route 53 DNS work (see the route53 skill)") minimizing conflict with sibling skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.