CtrlK
BlogDocsLog inGet started
Tessl Logo

configuring-vpc-endpoints-for-private-aws-service-access

Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink. Use when setting up secure private connectivity to S3, DynamoDB, and other AWS services without internet gateway, NAT device, or public IP addresses. Covers endpoint creation, security groups, route tables, and DNS configuration.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, token-efficient overview with excellent progressive disclosure — one real, one-level-deep reference and concise inline troubleshooting. Its weakness is that the main procedure is entirely delegated and the troubleshooting guidance never becomes executable (no commands or verification steps), leaving actionability and workflow clarity at the mid-level.

Suggestions

Add a minimal inline quick-start (e.g., one aws ec2 create-vpc-endpoint command for a gateway and an interface endpoint) so the body's core section is actionable without opening the reference.

Include a short verification step after configuration (e.g., confirm the endpoint is "Available" and test private connectivity) to give the workflow a validation checkpoint.

Make troubleshooting entries executable by naming the specific check or command (e.g., describe-security-group-rules, checking route table propagation entries) instead of only naming the area to inspect.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence — it never explains what a VPC or endpoint is — but the Overview paragraph largely repeats the frontmatter description and "follow the procedure exactly" is filler preamble. This matches anchor 4 (efficient with minor instances that could be trimmed) better than anchor 5's "every token earns its place".

4 / 5

Actionability

The core task is a pure pointer ("follow the procedure exactly. See [VPC endpoints configuration procedure](references/...)") with no inline steps or commands, and the troubleshooting section names what to check ("port 443", "DNS hostnames and DNS resolution", "DHCP options set", "endpoint policies") without any executable commands. This is concrete-but-incomplete guidance (anchor 3), not the mostly-executable guidance of anchor 4.

3 / 5

Workflow Clarity

The multi-step process (creation, security groups, route tables, DNS) is entirely delegated to the reference file, so the body itself shows no step sequence and no validation checkpoints — the symptom-organized troubleshooting headings provide structure but not a workflow. It sits above anchor 2 ("steps poorly defined") because the delegation is explicit and unambiguous, but below anchor 4 which requires a clear visible sequence.

3 / 5

Progressive Disclosure

The body is a concise overview with one clearly signaled, one-level-deep reference (verified to exist at references/configure-vpc-endpoints-for-private-aws-service-access.md with no nested references), and the brief inline troubleshooting is appropriately placed in the overview. This matches anchor 5's clear overview with well-signaled single-level references.

5 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: concrete actions, an explicit "Use when" clause with concrete triggers, comprehensive natural keywords including service names and AWS-specific terminology, and a clearly distinct niche. It closely follows the pattern of the rubric's good examples.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — "Configures VPC endpoints (interface and gateway)", "endpoint creation, security groups, route tables, and DNS configuration" — with comprehensive coverage of the domain. It matches the anchor for multiple specific concrete actions; the anchor-4 example ("minor gaps in coverage") doesn't apply since creation, security, routing, and DNS are all named.

5 / 5

Completeness

It explicitly answers both what ("Configures VPC endpoints (interface and gateway) for private AWS service access using AWS PrivateLink") and when ("Use when setting up secure private connectivity to S3, DynamoDB, and other AWS services without internet gateway, NAT device, or public IP addresses") with concrete trigger phrases, matching the anchor-5 good example pattern.

5 / 5

Trigger Term Quality

It includes the natural terms a user would say for this task: "VPC endpoints", "interface and gateway", "AWS PrivateLink", "S3", "DynamoDB", "internet gateway", "NAT", "public IP addresses", "security groups", "route tables", and "DNS". Coverage is comprehensive with synonyms, matching anchor 5 rather than anchor 4's "a few natural terms missing".

5 / 5

Distinctiveness Conflict Risk

"VPC endpoints", "AWS PrivateLink", and the named services (S3, DynamoDB) form a clear niche with distinct triggers, so the risk of firing for an unrelated skill is minimal. Anchor 4 ("minor overlap risk with closely related skills") is a worse fit since no closely related AWS networking skill would claim these exact triggers.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.