CtrlK
BlogDocsLog inGet started
Tessl Logo

rds-oracle

Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting. Applicable to any RDS-for-Oracle question including connecting a Python Lambda to RDS Oracle in a VPC with pooling and cold-start optimization, EKS pods to RDS Oracle via the Secrets Manager CSI driver with IRSA and SecretProviderClass, ORA-12170 cross-VPC timeouts from EC2, DPI-1047 cannot-locate-64-bit-Oracle-Client errors, and Oracle Connection Manager (CMAN) on EC2 as a proxy with HA across two AZs. Covers python-oracledb thin vs thick mode, init_oracle_client, RDS Proxy does NOT support RDS Oracle, port 1521, VPC peering, Transit Gateway, Kerberos with AWS Managed Microsoft AD, SSL/TLS/NNE, SSM port forwarding, EC2/ECS Fargate/EKS/Lambda, SQL Developer/DBeaver/Toad/SQLcl, and Secrets Manager.

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/specialized-skills/database-skills/rds-oracle/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, genuinely actionable skill body with strong safety gating, real executable commands, and a clean routing layer over a verified reference bundle. Its main cost is token efficiency: a large duplicated fact section (written explicitly to satisfy a grading rubric) and time-pinned version examples inflate the body at the expense of the otherwise excellent progressive-disclosure design.

Suggestions

Delete the "Rubric-Critical Facts to Always Surface" section from the body and move the five scenario checklists into their matching reference files (troubleshooting.md, compute-runtime.md, cman-proxy.md), keeping only one-line routing pointers — the facts currently appear twice in the bundle.

Remove rubric-gaming meta-commentary ("the rubric greps for these", "a common misdiagnosis that the rubric catches", "Agents without this skill get this wrong") and replace the version-pinned examples (claude-sonnet-4-20250514, 19.0.0.0.ru-2024-01) with placeholders or move them to a versioned reference so they don't age.

Close the remaining workflow gap by adding an explicit failure branch after the connectivity diagnostics (e.g. "if test_connectivity.sh fails DNS → check VPC DNS resolution; if TCP fails → check SG/NACL/routes") and a re-prompt loop for parameter validation instead of only listing formats.

DimensionReasoningScore

Conciseness

Mostly efficient — the routing table, safety tiers, and troubleshooting table are dense with non-obvious RDS-specific facts Claude would not reliably know ("RDS Oracle is VPC-only", "no SYS/SYSTEM logins", NAE/return-path NACL rules) — but the ~60-line "Rubric-Critical Facts to Always Surface" section duplicates content already in troubleshooting.md, compute-runtime.md, and cman-proxy.md (e.g. the DPI-1047 thin-mode fix and the ORA-12170 checklist appear in both places), and meta-commentary like "the rubric greps for these" and "a common misdiagnosis that the rubric catches" earns no tokens for the reader. Version-pinned examples ("claude-sonnet-4-20250514", "19.0.0.0.ru-2024-01") are time-sensitive and not placed in a deprecated/old-patterns section. Not 4: the duplication and rubric-gaming filler are more than "minor instances of over-explanation"; not 2 because nothing explains concepts Claude already knows and the core reference-routing content is tight.

3 / 5

Actionability

Concrete, executable commands appear throughout: `aws ec2 authorize-security-group-ingress --group-id sg-123 --protocol tcp --port 1521 --source-group sg-456`, `nc -zv <rds-endpoint> 1521`, `aws rds describe-db-instances --query 'DBInstances[0].Endpoint'`, `SELECT value FROM v$parameter WHERE name = 'service_names'`, plus five bundled diagnostic scripts. Not 5: the body itself contains no complete copy-paste connection-code example (deferred to the language references, which is acceptable per the code-vs-instruction note but leaves minor gaps), and some directives like "Name 'eksctl', 'OIDC', 'iamserviceaccount' explicitly" tell the agent what to mention rather than giving the runnable command.

4 / 5

Workflow Clarity

A clear three-stage sequence (Verify Dependencies → Classify and Route → Execute Workflow) with genuine validation checkpoints for the destructive operations the skill guards: explicit user-confirmation gates before any create/modify, downtime warnings before instance-class/engine changes, a refuse-and-offer-assessment path for deletes/reboots, and a dependency check that must precede code generation. The troubleshooting table gives error→fix feedback loops. Not 5: some checkpoints are implicit rather than looped — e.g. after running test_connectivity.sh there is no explicit "if this fails, go here" branch in the body, and parameter validation states formats but no re-prompt loop.

4 / 5

Progressive Disclosure

Good structure: the body routes to twelve real one-level-deep reference files via a symptom→file table (all verified to exist and be substantive), instructs "Load only the matching reference", and lists the five scripts with links. Not 5: the inlined "Rubric-Critical Facts" section is exactly the detailed per-scenario content that belongs in troubleshooting.md/compute-runtime.md/cman-proxy.md (anchor-3 symptom present), and the handoff section reaches two levels deep into another skill's tree (`aws-database-selection/references/handoff-contract.md` → `workload-primary-artifact.schema.json`). These are minor organization gaps rather than structural ones, so it sits at 4.

4 / 5

Total

15

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, trigger-rich description that clearly answers both what the skill does and when to use it, with excellent natural-keyword coverage and near-zero conflict risk. Its only weakness is verbosity — the scenario enumeration and keyword list make it roughly three times longer than the anchor examples, costing it the top completeness mark.

DimensionReasoningScore

Specificity

Opens with concrete actions ("Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting") and then enumerates specific concrete scenarios and tools ("connecting a Python Lambda to RDS Oracle in a VPC with pooling and cold-start optimization", "EKS pods... via the Secrets Manager CSI driver with IRSA", "ORA-12170 cross-VPC timeouts", "DPI-1047", "CMAN on EC2 as a proxy with HA across two AZs"). Coverage is comprehensive and nothing is vague. Not 4 because the minor gaps (no mention of e.g. ORA-12541/ORA-12514 in the description itself) are negligible against the breadth of concrete capability named.

5 / 5

Completeness

Both "what" ("Diagnoses and resolves...") and "when" ("Applicable to any RDS-for-Oracle question including...") are explicitly present, so it clears the anchor-4 bar, but the when-clause is padded into a very long enumeration rather than concise explicit trigger guidance, and the trailing "Covers..." sentence adds keyword laundry-list material that dilutes rather than sharpens the when. Not 5: the guideline "do not reward verbosity; concise and clear beats long and padded" — the when guidance is explicit but buried at the end of ~180 words, so it does not read as the crisp dual what+when statement of the anchor-5 example.

4 / 5

Trigger Term Quality

Natural user vocabulary is comprehensively covered with synonyms and product-specific tokens users would actually type: error codes ("ORA-12170", "DPI-1047"), tool names ("SQL Developer/DBeaver/Toad/SQLcl"), APIs ("port 1521", "VPC peering", "Transit Gateway", "SSM port forwarding"), and driver keywords ("python-oracledb thin vs thick mode", "init_oracle_client"). Not 4: no common natural term or synonym is observably missing for this domain.

5 / 5

Distinctiveness Conflict Risk

Clear niche with distinct triggers: every phrase is scoped to "Amazon RDS for Oracle" specifically, and it even disambiguates the nearest neighbor products ("RDS Proxy does NOT support RDS Oracle"). Minimal conflict risk with general Oracle, EC2, or other database skills. Not 4: there is no meaningful overlap risk — the trigger terms (ORA-12170 from EC2, CMAN on EC2, RDS Oracle endpoints) are unambiguous for this one skill.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.