CtrlK
BlogDocsLog inGet started
Tessl Logo

creating-secrets-using-best-practices

Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exemplary pointer-skill body: concise overview, verified one-level reference, and concrete troubleshooting detail. The main creation workflow is fully delegated to the reference, which slightly limits standalone actionability and workflow visibility within the body itself.

Suggestions

Add a brief inline quick-start (e.g., a single AWS CLI create-secret command or a one-line summary of the 8 steps) so the body is minimally actionable without opening the reference.

Include a short numbered outline of the procedure's steps in the body so the workflow sequence and the presence of the final validation step are visible at a glance.

Consider mentioning the troubleshooting anchors (KMS, rotation, access denied) already covered in the reference to avoid the body and reference drifting apart.

DimensionReasoningScore

Conciseness

The body is a lean overview ("Domain expertise for creating and managing secrets... KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management") with zero concept re-explanation and every section earning its tokens. Not 4 because there is no over-explanation to trim.

5 / 5

Actionability

Troubleshooting gives concrete, specific guidance ("kms:CreateKey", "kms:PutKeyPolicy", "kms:ViaService" scoped to "secretsmanager.<region>.amazonaws.com"), and the creation workflow delegates to a real, complete procedure; however the body itself contains no executable commands. Not 5 because there is no copy-paste-ready code or command inline; not 3 because the guidance given is specific and executable in nature, not vague hints.

4 / 5

Workflow Clarity

"To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly" delegates to a verified reference containing an 8-step sequence with per-step MUST-verify constraints and a dedicated "Validate Configuration" step, so the workflow has clear sequencing and checkpoints. Not 5 because the body itself shows no sequence or validation checkpoint — the reader must open the reference to see the steps; not 3 because the delegated procedure demonstrably contains explicit validation and feedback loops rather than implicit ones.

4 / 5

Progressive Disclosure

The body is a clear overview pointing to a single well-signaled, one-level-deep reference ("See [secret creation procedure](references/create-secrets-using-best-practices.md)"), verified to exist with no nested references. Not 4 because structure and reference signaling are clean with no organization gaps.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete, and comprehensive, with an explicit "Always use this skill when creating secrets" trigger clause. The only gap is modest synonym coverage in trigger terms.

DimensionReasoningScore

Specificity

"Creates and manages secrets in AWS Secrets Manager" plus "sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management" lists multiple concrete actions with comprehensive coverage of the domain. Not 4 because coverage of the skill's capabilities is complete rather than having minor gaps.

5 / 5

Completeness

Explicitly answers what ("Creates and manages secrets in AWS Secrets Manager... sets up dedicated KMS encryption keys, automatic rotation...") and when ("Always use this skill when creating secrets") with a concrete trigger phrase. Not 4 because the when-clause is explicit and directive rather than vague.

5 / 5

Trigger Term Quality

"creating secrets", "AWS Secrets Manager", "KMS", "rotation", "IAM" are natural terms users would say, giving good keyword coverage. Not 5 because common synonyms such as "password", "credentials", or "store a secret" are missing.

4 / 5

Distinctiveness Conflict Risk

"AWS Secrets Manager" secret creation with KMS/rotation/IAM/CloudTrail controls is a clear niche with distinct triggers, unlikely to fire for unrelated skills. Not 4 because no meaningful overlap with closely related skills is apparent.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.