CtrlK
BlogDocsLog inGet started
Tessl Logo

scanning-with-aws-security-agent

Run an AWS Security Agent scan on the workspace — uploads the source to AWS, scans it with the managed Security Agent service, and returns ranked, verified findings with code locations and remediations. Use when the user asks to scan code, find vulnerabilities, run a security scan or review, check security issues, check scan status, show findings, list recent scans, or stop a scan.

75

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a strong operational skill: copy-paste-ready CLI commands, explicit placeholder resolution, and workflows with real validation and error-recovery loops. The main costs are mild redundancy between the Rules/Troubleshooting sections and inline guidance, and a monolithic single-file layout that could offload the report template and troubleshooting detail to a reference file.

Suggestions

Deduplicate the Rules and Troubleshooting sections against inline guidance (e.g., the polling cadence, title-hyphen rule, and ResourceNotFoundException recovery each appear twice).

Move the detailed findings-report markdown template and the troubleshooting table into a reference file (e.g., references/reporting.md), keeping SKILL.md as a lean workflow overview.

Collapse the four near-identical severity blocks in the chat-summary template into a single parameterized pattern like "{emoji} {SEVERITY}: {name} — {filePath}:{lineStart}".

DimensionReasoningScore

Conciseness

The body is command-first and dense (placeholder-resolution table, exact CLI invocations, exclusion lists), but the Rules section and Troubleshooting repeat constraints already stated inline ("poll every 5 minutes", title-hyphen rule, ResourceNotFoundException handling), and the severity summary template repeats four nearly identical blocks. Anchor 4 fits; not 5 because of this redundancy, not 3 because padding is minor and localized.

4 / 5

Actionability

Fully executable guidance throughout: complete `aws securityagent` commands with flags, a copy-paste zip command with size guard, S3 upload with `--expected-bucket-owner`, JSON schema for scans.json entries, and a markdown report template — with every placeholder explicitly resolved in a table. Anchor 5 matches; not 4 because the commands are copy-paste ready and cover all common cases.

5 / 5

Workflow Clarity

Multi-step workflows are clearly sequenced with explicit validation checkpoints and feedback loops: pre-scan agent-space verification, zip size bail-out, ResourceNotFoundException → recreate → retry, a polling loop with status-change detection and terminal states, and a troubleshooting table. Anchor 5 matches; not 4 because error-recovery loops are explicit rather than implied.

5 / 5

Progressive Disclosure

Well-organized sections with clear headers and well-signaled cross-skill references (setup-security-agent, diff-scanning, threat-modeling), but everything lives inline in a single ~310-line file — the findings-report template and troubleshooting content are plausible candidates for a separate reference file. Anchor 4 fits; not 5 because content is not split across files and the under-50-line exception doesn't apply, not 3 because structure and navigation are genuinely good with nothing buried.

4 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: concrete actions, an explicit and richly varied "Use when" clause, and a clearly framed AWS-specific niche. Its only weakness is that broad scan triggers could collide with the sibling diff-scanning skill, which the description alone doesn't distinguish.

Suggestions

Add a disambiguating trigger such as "full-repository scans (for changed-code-only scans, use the diff-scanning skill)" to reduce overlap with sibling scanning skills.

DimensionReasoningScore

Specificity

"uploads the source to AWS, scans it with the managed Security Agent service, and returns ranked, verified findings with code locations and remediations" lists multiple concrete actions covering the full scan lifecycle. Anchor 5 matches; not 4 because coverage is comprehensive rather than having minor gaps.

5 / 5

Completeness

Explicitly answers "what" (upload, scan, return ranked verified findings with locations and remediations) and "when" via a concrete "Use when the user asks to..." clause with many trigger phrases. Anchor 5 matches; not 4 because the when-clause is already explicit and specific.

5 / 5

Trigger Term Quality

"scan code, find vulnerabilities, run a security scan or review, check security issues, check scan status, show findings, list recent scans, or stop a scan" covers natural phrasings and synonyms across all the skill's workflows. Anchor 5 matches; not 4 because no common variation is obviously missing.

5 / 5

Distinctiveness Conflict Risk

The AWS Security Agent framing gives a clear niche, but generic triggers like "scan code" and "find vulnerabilities" overlap with the sibling diff-scanning skill referenced in the body, which the description does not disambiguate. Anchor 4 (mostly distinct, minor overlap with closely related skills) fits; not 5 because of that sibling-skill overlap, not 3 because the managed-service framing is far more specific than "Works with document files".

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.