CtrlK
BlogDocsLog inGet started
Tessl Logo

rds-sqlserver

Provides connectivity, authentication, and troubleshooting guidance for Amazon RDS for SQL Server. Applicable when users ask about SSMS times out connecting from EC2, Cannot generate SSPI context with Windows auth, connect RDS SQL Server from Lambda with pymssql, auth_scheme shows NTLM instead of KERBEROS on ECS Fargate, SSM tunnel to RDS SQL Server from laptop, port 1433 security group, TrustServerCertificate=True for localhost tunnels, SPN MSSQLSvc, AWS Managed Microsoft AD, CNAME not RDS endpoint for Kerberos, tds_version='7.4', encryption='require', port-as-string for pymssql, Secrets Manager credential caching in Lambda, error 18456 login failed. Covers Python (pymssql, pyodbc), .NET (Microsoft.Data.SqlClient), Java (JDBC mssql-jdbc), Node.js (tedious), IAM auth via RDS Proxy, and VPC/ECS/EKS/Lambda deployment.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable — specific commands, parameters, and a complete code sample — with a clear task sequence, strong destructive-operation gating, and a well-wired reference structure. Its main defect is token efficiency: a large scenario-checklist section padded with rubric-referencing meta-commentary duplicates the Troubleshooting section and does not earn its context-window cost.

Suggestions

Delete the meta-commentary about the grading rubric ('the rubric explicitly greps for klist', 'what the rubric grades as failure', 'Each checklist below is what the rubric grades for') and keep only the underlying technical facts — this alone removes dozens of wasted tokens.

Merge the 'Rubric-Critical Facts to Always Surface' scenario checklists into the matching reference files (troubleshooting.md, ad-kerberos.md, lambda-vpc.md) or into the existing Troubleshooting section, since SSPI, NTLM-fallback, and 18456 guidance currently appears twice in the body.

Concretize the terminal 'verify' stage of the workflow (e.g., an actual connectivity/auth verification query or command per driver) so the execute step's final checkpoint is actionable in the body rather than deferred entirely to references.

DimensionReasoningScore

Conciseness

The ~90-line 'Rubric-Critical Facts to Always Surface' section is padded with meta-commentary about an external grading rubric ('the rubric explicitly greps for klist in the first-message output', 'what the rubric grades as failure') that earns no tokens for the executing agent, and it duplicates the Troubleshooting section (SSPI, NTLM fallback, and 18456 each appear twice in the body). This is 'several unnecessary explanations or padded sections' (anchor 2) rather than the 'some unnecessary explanation' of anchor 3, though the safety and routing sections themselves are tight.

2 / 5

Actionability

Fully executable throughout: exact CLI commands with flags (create-db-instance, modify-db-instance --domain, setspn -L, nltest /dsgetdc), concrete tag syntax with a worked example, the specific SSM document name AWS-StartPortForwardingSessionToRemoteHost with parameter values, diagnostic commands (Test-NetConnection -Port 1433, klist), and a complete copy-paste-ready Python handler with both required exception handlers. Matches the anchor-5 'copy-paste ready, common cases covered' example.

5 / 5

Workflow Clarity

The three-task sequence (Verify Dependencies → Classify and Route with required parameters and a routing table → Execute 'driver setup → networking → auth → secrets → verify') is clearly ordered, and the safety section adds strong checkpoints (explicit user confirmation before any modify, downtime warnings, refusal of destructive ops with an assessment fallback). It falls short of anchor 5 because the terminal 'verify' stage is named but never concretized in the body — the actual verification steps are deferred to reference files, and the troubleshooting checklists interleave two different orderings (systematic vs. klist-first narrowing) without reconciling them.

4 / 5

Progressive Disclosure

The sub-skill routing table cleanly signals 14 one-level-deep references, and every referenced file (python.md, ad-kerberos.md, ssm-tunneling.md, troubleshooting.md, etc.) exists in references/. Good overview structure (Overview, Common Tasks, Troubleshooting, Additional Resources, Handoff). Not anchor 5 because the inlined 'Rubric-Critical Facts' scenario checklists largely restate content that belongs in troubleshooting.md and the per-scenario references, and the handoff section points at another skill's internal files (aws-database-selection/references/...) that are not part of this bundle.

4 / 5

Total

15

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it pairs a clear capability statement with an unusually rich set of natural-language triggers (verbatim error messages, tool names, and connection parameters) that would reliably fire this skill for the right requests. Its only weakness is that the top-level verbs are broad categories, with specificity carried by the trigger list rather than by the action descriptions.

DimensionReasoningScore

Specificity

The verb set is generic ('Provides connectivity, authentication, and troubleshooting guidance') but is backed by concrete enumerated capabilities — SSPI/Windows auth, SPN registration, SSM tunneling, IAM auth via RDS Proxy, per-language driver coverage (pymssql, Microsoft.Data.SqlClient, mssql-jdbc, tedious). Fits anchor 4 ('several specific actions; minor gaps') rather than 5 because the actions themselves remain broad categories rather than the fully concrete verb list of the 5 anchor.

4 / 5

Completeness

Explicitly answers both questions: the 'what' ('Provides connectivity, authentication, and troubleshooting guidance for Amazon RDS for SQL Server' with scope detail) and the 'when' ('Applicable when users ask about...' followed by concrete trigger phrases). Matches the anchor-5 example structure of what + 'Use when...' with concrete triggers.

5 / 5

Trigger Term Quality

Contains verbatim natural user phrasings and error strings: 'SSMS times out connecting from EC2', 'Cannot generate SSPI context', 'auth_scheme shows NTLM instead of KERBEROS', 'error 18456 login failed', 'port 1433 security group', 'connect RDS SQL Server from Lambda with pymssql'. Coverage spans symptoms, error codes, tool names, and connection-string parameters — matches the comprehensive synonym-plus-specifics anchor.

5 / 5

Distinctiveness Conflict Risk

Clearly niched to Amazon RDS for SQL Server with engine-specific triggers (MSSQLSvc SPN, tds_version='7.4', AWS Managed Microsoft AD, RDS Proxy for IAM auth) that sibling database skills (rds-oracle, aurora) would not match. Minor overlap with generic SQL Server skills exists but the RDS/AWS framing keeps conflict risk minimal.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.