CtrlK
BlogDocsLog inGet started
Tessl Logo

querying-aws-cloudwatch

Runs SQL queries on CloudWatch Logs data exported as Apache Iceberg tables in S3 Tables. Covers VPC Flow Logs, WAF logs, CloudFront access logs, Route 53 resolver logs, Network Firewall logs, EKS audit logs, Verified Access logs, SES logs, VPC Lattice logs, Step Functions logs, NLB access logs, and 20+ other AWS vended data sources. Applies when analyzing network traffic, investigating security incidents, querying exported logs with SQL, enabling S3 Tables integration, configuring log export, correlating logs with other data, or running Athena queries on the aws-cloudwatch table bucket. Trigger phrases: query logs with SQL, analyze logs in Athena, SQL on VPC flow logs, investigate network traffic, run SQL on exported logs, enable S3 Tables for CloudWatch, correlate logs, historical log analysis, set up log querying.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body with a clear task sequence, explicit pre-query validation, and a strong troubleshooting feedback table. The main improvements are moving the IAM/KMS policy JSON and the full data-source catalogue into reference files, and showing how an Athena query is actually executed rather than only written.

Suggestions

Move the three full IAM/KMS policy JSON documents (~100 lines) into a references/ file (e.g. references/iam-policies.md) and keep a one-line summary plus link in the Security Considerations section, reducing the inline body of the query-focused skill.

Add a concrete example of executing a query and retrieving results (e.g. the Athena start-query-execution / get-query-results CLI calls or the MCP server equivalent), since the skill mandates confirming a workgroup and output location before executing but never shows the execution step.

Trim the 24-row data source table to the most common sources plus the list-namespaces discovery command, moving the full catalogue to a reference file — the description already enumerates the headline sources.

DimensionReasoningScore

Conciseness

The body is dense and factual with no padding explaining concepts Claude already knows, but there is trimming potential: the 24-row data source table (whose headline sources are already listed in the description) and three complete inline IAM/KMS JSON policy documents run long even though accurate. This fits the score-4 anchor (efficient with minor instances that could be trimmed) rather than score 5, because roughly a third of the body is full policy JSON that not every invocation needs.

4 / 5

Actionability

Guidance is mostly copy-paste ready: concrete aws CLI commands (list-table-buckets, create-s3-table-integration, grant-permissions, get-tables) and executable SQL examples with justified placeholders. It falls short of the score-5 anchor because the actual Athena query-execution step is never shown — the skill mandates confirming a workgroup and output location "before executing" but provides no example command or procedure for running the query and retrieving results.

4 / 5

Workflow Clarity

Common Tasks are clearly sequenced (check configuration → enable → verify permissions → query) with explicit checkpoints: the mandatory pre-query get-tables step, interpretation of empty results ("Empty result → integration not enabled"), and a full troubleshooting table mapping each error to a cause and fix, which serves as the feedback loop for error recovery. This matches the score-5 anchor; query operations are read-only, so the destructive-operation validation cap does not apply.

5 / 5

Progressive Disclosure

The single-file body is well organized and easy to navigate (decision tree, task sections, internal anchor links, external resource links), which places it above the score-3 anchor whose example is a poorly-navigable wall of inlined reference content. It does not reach score 5 because there are no reference files at all: ~100 lines of security/IAM policy JSON and the full 24-source catalogue are inlined in SKILL.md where a references/ split would fit.

4 / 5

Total

17

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it clearly states what the skill does and when to use it, in third person, with concrete actions and a comprehensive list of natural trigger phrases. The only weakness is a couple of broad trigger terms (security-incident investigation, network-traffic analysis) that create minor overlap risk with adjacent skills.

DimensionReasoningScore

Specificity

Lists multiple concrete third-person actions — "Runs SQL queries", "enabling S3 Tables integration", "configuring log export", "correlating logs with other data", "running Athena queries" — covering the skill's full scope with no vague filler. This matches the anchor for comprehensive concrete actions rather than the score-4 anchor, since the action coverage (query, configure, correlate) has no meaningful gaps.

5 / 5

Completeness

Explicitly answers both questions: the opening sentence states what the skill does ("Runs SQL queries on CloudWatch Logs data exported as Apache Iceberg tables in S3 Tables"), and an explicit "Applies when..." clause plus a dedicated "Trigger phrases:" list states when to use it with concrete triggers. This is the score-5 pattern (clear what AND when with concrete trigger phrases), not score 4, because the when-clause is fully explicit rather than merely present.

5 / 5

Trigger Term Quality

The trigger list is comprehensive and natural: "query logs with SQL", "analyze logs in Athena", "SQL on VPC flow logs", "run SQL on exported logs", "enable S3 Tables for CloudWatch", "correlate logs", "historical log analysis", "set up log querying" — covering synonyms, service-specific phrasings, and both user-level and technical vocabulary. It matches the score-5 anchor for comprehensive natural-term coverage rather than the score-4 anchor, which expects a few missing terms.

5 / 5

Distinctiveness Conflict Risk

The core niche (SQL on CloudWatch Logs exported to the aws-cloudwatch S3 Tables bucket) is clear and distinct, but broader triggers like "investigating security incidents" and "analyzing network traffic" could overlap with general security-analysis or networking skills. This fits the score-4 anchor ("mostly distinct; minor overlap risk") rather than score 5, whose anchor requires minimal conflict risk from clearly distinct triggers alone.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.