CtrlK
BlogDocsLog inGet started
Tessl Logo

diff-scanning-with-aws-security-agent

Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, highly executable runbook: nearly every step is copy-paste bash with a clear placeholder-resolution table, fail-fast checks, and error recovery. Its main weakness is reliance on an external "full scan" skill for pre-scan logic, exclusions, and findings presentation without pointers, which keeps it from being fully self-contained.

Suggestions

Inline or link the findings-fetch/presentation steps: replace "same presentation as full scan" with the actual batch-get findings command and severity-grouping format, or point to a concrete reference file in the companion skill.

Make the "same as full scan" cross-references navigable by naming the sibling skill's file or workflow explicitly (e.g., "see full-scan skill, step 4") instead of relying on unstated context.

Consolidate the duplicated "no prior full scan needed" statement (intro line and Rules section) into one location to save tokens.

DimensionReasoningScore

Conciseness

The body is lean throughout: a placeholder-resolution table instead of prose, bare executable commands, and terse rules — it assumes Claude's competence and never explains known concepts. The only trimmable bit is that "No prior full scan needed" (intro) is restated as "Diff scans are standalone — no prior full scan needed" (Rules), which is too minor to drop it from anchor 5.

5 / 5

Actionability

Steps 3–7 and 10 give fully executable bash with placeholders resolved via the table and a ResourceNotFoundException retry path. Not a 5 because key details are delegated rather than written: "Findings: same presentation as full scan" and step 6's "same logic as full scan" leave the reader without in-file instructions for fetching/presenting findings.

4 / 5

Workflow Clarity

An 11-step numbered sequence with real validation checkpoints (fail-fast on empty diff, retry on ResourceNotFoundException, poll-only-on-status-change) and error feedback loops. It falls short of anchor 5 because the findings step — the payoff of the whole workflow — is a cross-reference to an unwritten "same as full scan" presentation, leaving the completion path implicit.

4 / 5

Progressive Disclosure

A single, well-organized SKILL.md with no bundle files and cleanly sectioned content (Local state, Workflow, Rules), which suits a single-purpose workflow. Not a 5: it depends on sibling-skill content via three unpointed "same as full scan" references (pre-scan checks, exclusions, findings presentation), so navigation to that material is assumed rather than signaled.

4 / 5

Total

17

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An excellent description: third-person, concise, states a precise capability with explicit scope, and pairs it with a comprehensive "Use when" trigger clause covering natural user phrasings. The only minor limitation is that it describes the scan launch without hinting at findings/reporting output.

DimensionReasoningScore

Specificity

"Run a fast AWS Security Agent diff scan on only the changed code since a git ref" names concrete, precisely-scoped actions (diff scan, changed code, git ref), but coverage is limited to launching the scan without touching findings or reporting. It lists specific actions with only minor gaps rather than comprehensive coverage, so it sits above anchor 3 and below anchor 5.

4 / 5

Completeness

It explicitly answers both questions: the "what" ("Run a fast AWS Security Agent diff scan on only the changed code since a git ref") and the "when" ("Use when the user asks to scan changes... or any pre-commit/pre-push security check") with concrete trigger phrases. This matches the anchor-5 example structure exactly.

5 / 5

Trigger Term Quality

The trigger list — "scan changes", "run a diff scan", "check what changed for security issues", "scan before committing", "scan before PR", "pre-commit/pre-push security check" — covers the natural phrasings users would say, including synonyms and hyphenated variants. Anchor 4 would require missing natural terms, and none of the common ways to request this are absent.

5 / 5

Distinctiveness Conflict Risk

"AWS Security Agent diff scan" carves out a clear niche, and the triggers (diff scan, pre-commit/pre-push check) are distinct from a general or full security scan. Minimal conflict risk since the trigger terms are specific to changed-code scanning.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.