CtrlK
BlogDocsLog inGet started
Tessl Logo

pentesting-with-aws-security-agent

Run an AWS Security Agent penetration test against a live web application — registers and verifies the target domain, exercises the supplied endpoints with the managed Security Agent service, and returns verified runtime findings. Use when the user asks to pentest, run a penetration test, test their app's attack surface, find runtime vulnerabilities, register or verify a target domain, or check pentest status / findings.

74

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content: complete CLI commands, resolved placeholders, validation checkpoints, and error-recovery guidance make the pentest workflow straightforward to execute. The only trimmable fat is the triple-stated authorization reminder, and the all-inline structure forgoes any progressive-disclosure layering.

Suggestions

State the authorization requirement once (e.g., in the Rules section) and reference it from the pre-pentest checklist instead of repeating it three times across the intro, checks, and rules.

Move the findings-report format and field list to a short reference file (e.g., references/findings-report.md) so SKILL.md stays a lean workflow overview.

DimensionReasoningScore

Conciseness

The body is lean and command-driven with no explanations of concepts Claude already knows, but the authorization reminder is stated three times (intro line, pre-pentest check 4, and the Rules section) and could be consolidated.

4 / 5

Actionability

Every workflow step ships a copy-paste-ready `aws securityagent` command with concrete flags, a placeholder-resolution table, an exact `--assets endpoints=[...]` example, a precise JSON record schema for pentests.json, and verbatim user-facing messages.

5 / 5

Workflow Clarity

The six-step workflow has explicit validation checkpoints (agent-space existence check, domain verification before create-pentest, authorization confirmation), terminal-state handling in the polling loop, pagination of findings, and a troubleshooting section with recovery paths — so the destructive-operation cap does not apply.

5 / 5

Progressive Disclosure

No bundle files exist and the ~150-line body is well-sectioned with a clearly signaled one-level reference to the `setup-security-agent` skill, but everything lives inline with no content split across reference files, leaving minor organization headroom (e.g., the findings-report format could be a reference).

4 / 5

Total

18

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete third-person capabilities, explicit 'Use when...' triggers with good synonym coverage, and a distinct AWS Security Agent niche. The only gap is that it undersells a couple of lifecycle actions the body supports (stopping a pentest, setup handoff).

DimensionReasoningScore

Specificity

"registers and verifies the target domain, exercises the supplied endpoints... and returns verified runtime findings" names several concrete actions covering the core lifecycle, but omits capabilities the skill body handles (stopping a pentest, delegating setup), leaving minor gaps in coverage.

4 / 5

Completeness

The description explicitly answers both what it does ("registers and verifies the target domain, exercises the supplied endpoints... returns verified runtime findings") and when to use it ("Use when the user asks to pentest... or check pentest status / findings") with concrete trigger phrases.

5 / 5

Trigger Term Quality

"pentest, run a penetration test, test their app's attack surface, find runtime vulnerabilities, register or verify a target domain, or check pentest status / findings" covers natural synonyms and varied user phrasings comprehensively.

5 / 5

Distinctiveness Conflict Risk

"Run an AWS Security Agent penetration test against a live web application" carves out a clear niche with service-specific triggers (target-domain registration, pentest status) that are unlikely to fire for unrelated skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.