CtrlK
BlogDocsLog inGet started
Tessl Logo

diff-scanning-with-aws-security-agent

Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when the user asks to scan changes, run a diff scan, check what changed for security issues, scan before committing, scan before PR, or any pre-commit/pre-push security check.

76

Quality

95%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, highly actionable skill body with a clear sequenced workflow and explicit validation checkpoints. It is self-contained with good internal structure, though it does not exercise progressive disclosure across separate reference files.

DimensionReasoningScore

Conciseness

The body is lean and command-driven, assuming Claude's knowledge of git and the AWS CLI; nearly every token earns its place with no padded concept explanations.

5 / 5

Actionability

It provides copy-paste-ready bash and aws CLI commands plus a placeholder-resolution table, covering the common scan workflow with concrete executable steps.

5 / 5

Workflow Clarity

An 11-step numbered sequence includes explicit checkpoints (fail-fast on empty diff, ResourceNotFoundException recreate-and-retry, fixed 2-minute polling cadence) and clear error-recovery feedback loops.

5 / 5

Progressive Disclosure

The content is well-organized into clearly signaled sections (Local state, Workflow, Rules) with no nested references, but as a self-contained ~100-line skill it does not demonstrate the well-signaled one-level-deep external references that anchor 5 requires.

4 / 5

Total

19

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-targeted description that clearly states the capability and gives rich, natural trigger guidance. The only minor gap is that it names one core action rather than a comprehensive list of distinct actions.

DimensionReasoningScore

Specificity

The description names the domain and a concrete, well-scoped action ('Run a fast AWS Security Agent diff scan on only the changed code since a git ref'), but it describes one primary action rather than a list of several distinct actions, so it sits just below the comprehensive 5-anchor.

4 / 5

Completeness

It explicitly answers both 'what' (run a diff scan on changed code since a git ref) and 'when' (an explicit 'Use when...' clause enumerating concrete trigger scenarios).

5 / 5

Trigger Term Quality

It includes a comprehensive set of natural trigger phrases users would actually say ('scan changes', 'run a diff scan', 'check what changed for security issues', 'scan before committing', 'scan before PR', 'pre-commit/pre-push security check').

5 / 5

Distinctiveness Conflict Risk

It carves a clear niche — AWS Security Agent diff scanning — with distinct triggers that are unlikely to fire for unrelated skills, keeping conflict risk minimal.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.