CtrlK
BlogDocsLog inGet started
Tessl Logo

resilience-hub-multi-account

Configures AWS Resilience Hub v2 for multi-account resilience management across an AWS Organization. Covers the per-service cross-account permission model, cross-account IAM roles, and centralized assessment from a single account. Applies when the user wants to set up org-wide resilience or assess workloads that span multiple AWS accounts.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/specialized-skills/resilience-skills/resilience-hub-multi-account/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and actionable, with an excellent decision rule, a concrete executable command, and a clean single-reference bundle that carries the detailed SOP. Its main weakness is redundancy: the delegated-administrator disclaimer is repeated about five times, and the inline create-service command overlaps the reference, inflating token cost without adding information.

Suggestions

Consolidate the 'no register-delegated-administrator CLI operation' caveat into a single authoritative statement (e.g., the decision rule or the Troubleshooting entry) and cut the repetitions in the Overview, the governance bullet, and the paragraph after the create-service command.

State the create-service command once — either inline as the canonical example or in the reference procedure — and cross-reference the other location instead of duplicating it.

Tighten the externalId callout to the essential guidance (generate a random secret, store in Secrets Manager/SSM SecureString, never commit) and move the CI/CD and CloudFormation NoEcho hardening detail into the reference or Security Considerations.

DimensionReasoningScore

Conciseness

The body is mostly efficient and assumes AWS/IAM knowledge (no beginner padding), but the 'no register-delegated-administrator CLI operation' warning is repeated almost verbatim in the Overview, the decision rule, the governance bullet, the paragraph after the create-service command, and the Troubleshooting section — several unnecessary repetitions that could be consolidated. It fits the 3 anchor ('mostly efficient but some unnecessary explanation or could be tightened') better than the 4 anchor, since the duplication is substantive rather than minor.

3 / 5

Actionability

Provides a fully executable copy-paste command (`aws resiliencehubv2 create-service --name {service} --regions {regions} --permission-model '{...}'`) with the complete JSON structure, plus concrete troubleshooting checks ('role ARN matches exactly', 'trust policy allows the central account's invoker role', 'externalId matches'). The bulk of executable steps are appropriately delegated to the real one-level-deep reference file (verified to exist with full CLI commands), leaving only minor gaps in the body itself — a 4, not 5, since the body's own setup guidance beyond the single command is thin.

4 / 5

Workflow Clarity

A clear decision rule up front ('To run cross-account resilience assessments... use the per-service cross-account permission model... Do NOT use register-delegated-administrator'), a directed handoff ('follow the procedure exactly. See references/multi-account-procedure.md'), and troubleshooting sections that function as error-recovery feedback loops for the two most likely failures (AccessDenied, no resources discovered). Not a 5 because the body's validation checkpoints are reactive (troubleshooting after failure) rather than explicit inline validation steps — those live in the reference's step constraints.

4 / 5

Progressive Disclosure

Good structure: the body is an overview (mechanism comparison, decision rule, one key command, troubleshooting, security notes) with a clearly signaled, verified one-level-deep reference (references/multi-account-procedure.md, 120-line SOP with parameters and steps) and no nested references. Not a 5 because some content duplicated between body and reference (the delegated-administrator caveat appears in both, and the create-service form also appears in the reference's step set) is inline rather than fully split.

4 / 5

Total

15

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states what the skill does in concrete terms, gives an explicit 'Applies when...' trigger clause in third person, and carves out a distinct niche. Keyword coverage is good but could add a couple of natural synonyms (member accounts, AWS Organizations) for full coverage.

DimensionReasoningScore

Specificity

Names the domain precisely ('AWS Resilience Hub v2', 'multi-account resilience management across an AWS Organization') and lists several specific capabilities ('per-service cross-account permission model, cross-account IAM roles, and centralized assessment from a single account'), but the verbs 'Configures'/'Covers' describe topic areas rather than fully enumerating concrete actions, leaving minor gaps versus the comprehensive 5 anchor.

4 / 5

Completeness

Explicitly answers both questions: what ('Configures AWS Resilience Hub v2... Covers the per-service cross-account permission model, cross-account IAM roles, and centralized assessment') and when ('Applies when the user wants to set up org-wide resilience or assess workloads that span multiple AWS accounts'). Both are concrete and use third-person voice, matching the 5 anchor; the 4 anchor applies only when the 'when' clause is less explicit.

5 / 5

Trigger Term Quality

Natural user phrasings are well covered — 'set up org-wide resilience', 'assess workloads that span multiple AWS accounts', 'centralized assessment', 'multi-account' — matching how users would actually ask. A few natural variants ('member accounts', 'central account', 'AWS Organizations setup') are missing, so it falls just short of the comprehensive-synonym 5 anchor.

4 / 5

Distinctiveness Conflict Risk

A clear niche — Resilience Hub v2 multi-account/cross-account configuration — with distinct trigger phrases (org-wide resilience, workloads spanning multiple AWS accounts) that are unlikely to fire for unrelated skills. It is far more specific than the 4 anchor's 'minor overlap risk with closely related skills'.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.