CtrlK
BlogDocsLog inGet started
Tessl Logo

deploying-custom-domain-rest-api

Deploys a Regional REST API with a custom domain name, a Lambda backend function, and a request-based Lambda authorizer using AWS CLI. Covers ACM certificate provisioning, API Gateway REST API creation, Lambda function deployment, request authorizer setup, custom domain configuration, base path mapping, and Route 53 DNS record creation. Trigger keywords: custom domain, REST API, Lambda, Route 53, API Gateway, regional endpoint, request authorizer, base path mapping.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable SOP: fully sequenced steps with explicit validation checkpoints, troubleshooting feedback loops, and real supporting scripts. The main weaknesses are minor — some redundant warning text, one step (request validation) stated as a MUST without a concrete command, and a monolithic inline command list that could live in a reference file.

Suggestions

Add the concrete commands for the request-validation constraint in Step 5 (e.g., apigateway create-request-validator / put-method-response with actual schema/patterns), since it is currently a MUST with no executable implementation.

Remove the duplicated hardcoded-credentials warning — state it once in Security Considerations (or Parameters) instead of both — and tighten the repeated 'You MUST' framing to cut tokens without losing clarity.

Move the long inline CLI invocations and the access-log format string into the existing scripts/ bundle (or a reference file) so SKILL.md reads as an overview with well-signaled, one-level-deep references.

DimensionReasoningScore

Conciseness

The body is dense with executable commands and assumes AWS knowledge rather than explaining concepts, but contains minor trimmable redundancy: the Overview restates the description, the hardcoded-credentials warning appears in both Parameters ("hardcoded demo authorization values... NOT suitable for production") and Security Considerations, and the repeated "You MUST" constraint framing pads each step. It matches the score-4 anchor (efficient, minor over-explanation) rather than score 5 (every token earns its place).

4 / 5

Actionability

Nearly every step gives copy-paste-ready AWS CLI commands (create-role, create-function, create-domain-name, the curl test, validate.sh), matching the score-5 anchor's executability. It drops to 4 because a few MUST constraints lack any command — "MUST support multiple input methods (direct input, file path, URL)" and "MUST configure request validation to reject malformed query parameters... by validating that QueryString1 and HeaderAuth1 match expected patterns" give no concrete implementation — the minor-gaps case of score 4.

4 / 5

Workflow Clarity

Ten explicitly ordered steps with sequencing guards ("This step MUST be performed before all other steps", "MUST NOT create the deployment until all resources, methods, and integrations are configured"), validation checkpoints at each stage (wait certificate-validated, 10-second IAM propagation wait, get-function/get-stage/get-domain-name verification, final validate.sh), and feedback loops in Troubleshooting (e.g., retry the ACM wait when PENDING_VALIDATION, diagnose 401/403 causes). This matches the score-5 anchor with explicit validation and error-recovery guidance.

5 / 5

Progressive Disclosure

All five bundle files referenced in the body (scripts/lambda-trust-policy.json, authorizer.mjs, example_function.mjs, dns-record.json, validate.sh) exist exactly one level deep and are clearly signaled with their purpose, and sections (Parameters, Steps, Examples, Troubleshooting, Security) are well organized. It falls short of score 5 because the entire command-heavy procedure — including the very long inline CLI invocations and log-format strings — is inlined in SKILL.md rather than split out, a minor organization gap consistent with the score-4 anchor.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states what the skill does with a comprehensive, concrete action list, provides explicit trigger keywords, and occupies a distinct niche. The only minor gap is a few missing natural synonyms in the trigger list.

DimensionReasoningScore

Specificity

The description enumerates seven concrete actions — "ACM certificate provisioning, API Gateway REST API creation, Lambda function deployment, request authorizer setup, custom domain configuration, base path mapping, and Route 53 DNS record creation" — which comprehensively covers the deployment pipeline. It clearly matches the score-5 anchor (multiple specific concrete actions, comprehensive) and exceeds the score-4 anchor, which allows coverage gaps.

5 / 5

Completeness

It explicitly answers "what" (the enumerated deployment actions) and "when" via the explicit trigger clause "Trigger keywords: custom domain, REST API, Lambda, Route 53...". This is equivalent explicit trigger guidance per the judging guidelines, matching the score-5 anchor with concrete trigger phrases; it is not score 4, which requires the 'when' to be less explicit.

5 / 5

Trigger Term Quality

The trigger list includes natural terms users would say: "custom domain, REST API, Lambda, Route 53, API Gateway, regional endpoint, request authorizer, base path mapping" — good coverage. It falls short of the score-5 anchor because a few natural variations are missing (e.g., "DNS record", "domain name", "API endpoint"), but it is well above score 3, which requires missing common terms.

4 / 5

Distinctiveness Conflict Risk

The combination of "Regional REST API", "request-based Lambda authorizer", and "base path mapping" carves out a clear AWS API Gateway niche with distinct triggers and minimal conflict risk. It matches the score-5 anchor; score 4 would imply meaningful overlap with closely related skills, which is not the case.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.