CtrlK
BlogDocsLog inGet started
Tessl Logo

querying-aws-s3

Queries S3 object metadata, tracks bucket activity, audits object changes, searches annotations, and analyzes storage metrics using S3 Metadata system tables (journal, inventory, annotation) and S3 Storage Lens tables via Athena SQL. Applies when counting objects, finding recent uploads or deletions, identifying who wrote to a prefix, breaking down storage classes, finding objects by tag, searching annotation content, analyzing storage lens metrics, or enabling S3 Metadata tracking. Prefers system tables over raw S3 APIs (list-objects-v2, head-object) at scale. Trigger phrases: bucket activity, object count, who uploaded, track deletions, storage class breakdown, find by tag, search annotations, storage lens metrics, audit bucket changes.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content with fully executable CLI commands and SQL, a clearly sequenced workflow with validation checkpoints, and a useful troubleshooting/error-recovery table. The main weakness is structure across files: everything, including ~60 lines of security policy details, is inlined in a single long SKILL.md with no reference files. Secondary trimming (the security JSON blocks) would also improve token efficiency.

Suggestions

Move the Security Considerations detail (least-privilege IAM policy JSON, Athena workgroup encryption configuration, audit-trail guidance) into a references/security.md and keep a 3-4 line summary with a clearly signaled link in SKILL.md.

Extract the enable/configuration command blocks (S3 Metadata create-bucket-metadata-configuration variants, Storage Lens export, Glue federated catalog registration) into a references/setup.md, leaving the check-configured step and a pointer inline since setup is only needed when the feature is not enabled.

Consider moving the full table descriptions and Additional Resources link list into a references/tables.md so the main file reads as an overview + core queries, reducing the main-file token footprint.

DimensionReasoningScore

Conciseness

The body is dense and operational (tables, copy-paste commands, no explanation of what S3 or Athena is), but the full IAM policy JSON, workgroup encryption JSON, and multi-block enable configurations are reference material that inflates the token budget of the main file. This fits anchor 4 ("efficient; minor instances ... that could be trimmed") rather than anchor 5, since the ~60-line Security Considerations section could be extracted.

4 / 5

Actionability

Every section is executable: complete aws s3api/s3control/glue commands with real JSON payloads, and eight full SQL queries (audit deletes with requester/source_ip, tag filtering via object_tags map access, annotation LIKE and json_extract_scalar searches, Storage Lens selects). Copy-paste ready with only intentional <BUCKET>/<REGION> placeholders, covering all common cases from the decision tree.

5 / 5

Workflow Clarity

The Common Tasks are clearly sequenced (check configured → enable if not → verify permissions → identify table → query) with a validation-first checkpoint (TableStatus ACTIVE/BACKFILLING/FAILED interpretation and MetadataConfigurationNotFound routing to the Enable section) and a troubleshooting table providing error→cause→fix feedback loops (empty journal results, AccessDenied, CATALOG_NOT_FOUND, wrong namespace). Queries are read-only, so the destructive/batch cap does not apply.

5 / 5

Progressive Disclosure

There are no bundle files at all — the entire ~330-line skill is inlined in SKILL.md, and content that clearly belongs in separate files (the least-privilege IAM policy, encryption configuration, audit-trail guidance, and enable-configuration JSON blocks) sits inline. Sections are well-organized with headers and tables, which keeps this above anchor 2's "minimal structure", but the absence of any one-level-deep reference files for a skill this size matches anchor 3 ("content that should be separate is inline") better than anchor 4.

3 / 5

Total

17

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly states concrete capabilities, the underlying mechanism, and explicit "use when" guidance with a dedicated trigger-phrase list. The only weakness is slight breadth in audit/storage-metrics phrasing that could overlap with adjacent AWS analytics skills. It uses third person and stays concrete without padding.

DimensionReasoningScore

Specificity

The description lists five concrete actions ("Queries S3 object metadata, tracks bucket activity, audits object changes, searches annotations, and analyzes storage metrics") and names the exact mechanism (S3 Metadata system tables journal/inventory/annotation and Storage Lens tables via Athena SQL), matching the comprehensive-coverage anchor rather than anchor 4, which expects minor gaps.

5 / 5

Completeness

It clearly answers "what" (queries S3 metadata via Athena SQL over named system tables) and "when" ("Applies when counting objects, finding recent uploads or deletions, ... or enabling S3 Metadata tracking" followed by explicit trigger phrases), exactly matching the anchor-5 example pattern of concrete what + explicit when.

5 / 5

Trigger Term Quality

It explicitly enumerates nine natural trigger phrases ("bucket activity, object count, who uploaded, track deletions, storage class breakdown, find by tag, search annotations, storage lens metrics, audit bucket changes") plus an "Applies when" clause with additional variants ("counting objects, finding recent uploads or deletions"), giving comprehensive natural-term coverage; anchor 4 would require natural terms to be missing, and none of the capability areas lack a user-sayable phrase.

5 / 5

Distinctiveness Conflict Risk

The niche is distinct (S3 Metadata system tables via Athena, with specific API names like list-objects-v2 and head-object), but broad phrases like "analyzes storage metrics" and "audits object changes" carry minor overlap risk with a general CloudTrail or S3 analytics skill, fitting anchor 4 ("mostly distinct; minor overlap risk") rather than anchor 5's minimal-conflict bar.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.