CtrlK
BlogDocsLog inGet started
Tessl Logo

enabling-lambda-vpc-internet-access

Enables internet access for AWS Lambda functions deployed in VPC subnets by creating NAT Gateway infrastructure, configuring public/private subnet routing, and updating security groups. Use when a VPC-attached Lambda function cannot reach the internet.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/specialized-skills/networking-and-content-delivery-skills/enabling-lambda-vpc-internet-access/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body correctly positions itself as a thin index over a single well-built reference, but it under-delivers on efficiency: the overview repeats known concepts and the troubleshooting section is copied almost verbatim into both files. Consolidating troubleshooting into the reference and trimming the overview would raise conciseness without losing anything.

Suggestions

Remove the Troubleshooting section from SKILL.md and keep it only in references/lambda-vpc-internet-access.md, replacing it with a single line pointing there — the two copies are nearly identical.

Trim the overview to one sentence; the explanation of why Lambda-in-VPC needs a NAT Gateway is background Claude already knows and is repeated in the reference's own overview.

Add one or two concrete inline commands (e.g., the describe-route-tables check for the 0.0.0.0/0 NAT route) so the most common troubleshooting path is actionable without opening the reference.

DimensionReasoningScore

Conciseness

Mostly lean, but the overview re-explains VPC/NAT basics Claude already knows ('Lambda functions in a VPC cannot receive public IP addresses...'), and the entire Troubleshooting section duplicates near-identical content in references/lambda-vpc-internet-access.md, so it could be tightened considerably.

3 / 5

Actionability

The body offers directional checks ('Verify the route table... has a `0.0.0.0/0` route pointing to the NAT Gateway') but no executable commands itself — all concrete CLI guidance is deferred to the reference, and the main procedure section is essentially just a pointer.

3 / 5

Workflow Clarity

The body contains no step sequence or validation checkpoints of its own; it delegates wholly to the reference with 'follow the procedure exactly', and while the referenced SOP is well-sequenced with user-confirmation gates, the body-level view has gaps.

3 / 5

Progressive Disclosure

Good structure: a short overview, a clearly signaled one-level-deep reference (references/lambda-vpc-internet-access.md, verified to exist), and organized sections. The duplication of troubleshooting guidance between body and reference is a minor organization gap.

4 / 5

Total

13

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete actions, third-person voice, explicit use-when trigger, and a distinct niche. The only room for improvement is broader coverage of the supporting infrastructure pieces (Internet Gateway, Elastic IPs, route tables) and a few more natural trigger synonyms.

DimensionReasoningScore

Specificity

Lists three concrete actions ('creating NAT Gateway infrastructure, configuring public/private subnet routing, and updating security groups'), but omits supporting pieces like Internet Gateway creation, Elastic IP allocation, and route table updates, leaving minor coverage gaps.

4 / 5

Completeness

Explicitly answers both what (the three infrastructure actions) and when ('Use when a VPC-attached Lambda function cannot reach the internet') with a concrete, naturally phrased trigger.

5 / 5

Trigger Term Quality

Includes natural terms users would say ('internet access', 'AWS Lambda', 'VPC', 'NAT Gateway', 'cannot reach the internet'), but misses common variations like 'no internet', 'outbound access', 'timeout', or 'NAT'.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (Lambda-in-VPC internet access via NAT Gateway) with distinctive trigger phrasing that is unlikely to fire for unrelated networking or Lambda skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.