CtrlK
BlogDocsLog inGet started
Tessl Logo

remediating-with-aws-security-agent

Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. Use this whenever the user mentions Security Agent, security findings, pentest or penetration test results, code review findings, vulnerabilities found in their AWS account, "what did the security scan find", remediating or triaging security risks, or wants to start fixing reported vulnerabilities — even if they don't name the service explicitly. Trigger it for phrases like "get my security findings", "what vulnerabilities do we have", "let's fix the pentest results", or "triage the security report". The skill discovers scans, exports findings to a gitignored local directory (so sensitive exploit detail is never committed), produces a prioritized triage summary, and offers to start fixing the highest-risk issues.

76

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong operational skill: every stage is backed by copy-paste AWS CLI commands, explicit validation gates, and deterministic triage rules, with sensitive-data handling enforced by a gitignore-before-write rule. The only weaknesses are mild — a few justifying sentences that could be cut, and a ~245-line monolith whose reference-worthy detail (summary template, matching heuristics) could be split into reference files.

Suggestions

Trim the motivational rationale sentences (e.g. 'the user is working in a codebase for a reason...' in Stage 1 and 'a CRITICAL unauthenticated RCE outranks a LOW informational finding every time' in Stage 3) to pure instructions, saving tokens without losing operational content.

Move the Stage 3 summary template and the Stage 1 codebase-matching heuristics into a references/ file (e.g. references/triage-format.md, references/app-matching.md) and link to them from the body, keeping SKILL.md as a leaner overview.

DimensionReasoningScore

Conciseness

Largely lean — exact CLI commands, parameter names, and batch limits with no tutorials on concepts Claude already knows — but a few rationale passages could be trimmed, e.g. 'the user is working in a codebase for a reason, and the relevant findings are almost always for the app in front of them' and 'a CRITICAL unauthenticated RCE outranks a LOW informational finding every time'. Fits the 4 anchor (efficient, minor over-explanation) rather than 5 because a handful of justifying sentences don't add operational information.

4 / 5

Actionability

Fully executable throughout: exact 'aws securityagent' commands with all parameters, pagination via '--next-token until absent', 'batch-get-findings ... at most 25 ids per call', mkdir/gitignore commands, deterministic composite sort keys, and a concrete output file pattern '.security-agent/findings_<jobId>.md'. Covers the common cases (pentest and code-review paths both given); not 4 because there are no gaps in executable detail.

5 / 5

Workflow Clarity

The four stages are explicitly ordered ('they matter in order') with validation checkpoints throughout: confirm the scan match before exporting ('Never export from a guessed scan without the user's confirmation'), filter jobs to 'status == "COMPLETED"' and stop if none, verify credentials via 'aws sts get-caller-identity' with Region check, and confirm with the user before remediating ('don't silently begin editing code'). Error-recovery loops are present; not 4 because checkpoints are explicit at every risky transition, satisfying the batch/destructive-operation bar.

5 / 5

Progressive Disclosure

No bundle files exist (no references/, scripts/, or assets/), and the body is well-sectioned with clear headers matching the four-stage flow — but at roughly 245 lines, self-contained content like the triage summary template, the codebase-matching heuristics, and the ranking rules could live in one-level-deep reference files. Fits the 4 anchor (good structure, most content appropriately placed, minor organization gaps) rather than 5 because some detail-heavy sections would be better split out.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it states concrete capabilities in third person, gives an explicit 'Use this whenever...' trigger clause with quoted natural phrases users would actually say, and anchors itself to a distinct AWS service niche. It also surface-justifies the gitignore behavior, which differentiates it from generic security skills.

DimensionReasoningScore

Specificity

Lists multiple concrete, specific actions — 'discovers scans, exports findings to a gitignored local directory (so sensitive exploit detail is never committed), produces a prioritized triage summary, and offers to start fixing the highest-risk issues' — with comprehensive coverage of the skill's behavior. Not the 4 anchor because there are no meaningful gaps in capability coverage; every stage of the workflow is named concretely.

5 / 5

Completeness

Explicitly answers both what ('Pull AWS Security Agent findings... and drive remediation', plus the four-stage summary) and when ('Use this whenever the user mentions...', plus explicit trigger phrases). Matches the 5 anchor's pattern of concrete trigger phrases attached to a clear capability statement; not 4 because the 'when' is maximally explicit.

5 / 5

Trigger Term Quality

Comprehensive natural-language coverage including synonyms and quoted user phrases: 'pentest or penetration test results', 'what did the security scan find', 'get my security findings', 'what vulnerabilities do we have', 'let's fix the pentest results', 'triage the security report'. These are exactly the phrases a user would naturally say; not the 4 anchor because no common variation is missing.

5 / 5

Distinctiveness Conflict Risk

Clear niche anchored to a named AWS service ('AWS Security Agent findings (penetration tests and code reviews)') with triggers specific to that service's artifacts (Security Agent, pentest results, security scan findings in 'their AWS account'). Minor overlap with generic code-review vocabulary ('code review findings'), but the AWS/Security Agent anchoring keeps conflict risk minimal — fits the 5 anchor better than 4.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.