CtrlK
BlogDocsLog inGet started
Tessl Logo

securing-s3-buckets

Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an existing bucket, fix a security finding, configure encryption, or enable logging and monitoring. Do NOT use for general S3 data operations, S3 Tables setup, or discovering existing data assets.

74

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An excellent instruction-style skill body: executable commands, hard ordering and safety constraints for the destructive policy operation, explicit validation/feedback loops, and a clean split between the overview and five existing one-level-deep reference files. The only weakness is mild token redundancy from duplicated reference listings and repeated emphasis phrasing.

DimensionReasoningScore

Conciseness

The body is dense, constraint-driven, and assumes Claude's competence (no explaining of S3 or encryption concepts), but the reference links are duplicated — once inline per workflow and again in "Additional Resources" — and emphatic filler like "this is REQUIRED, not optional" (used twice) could be trimmed, matching the level-4 'minor instances that could be trimmed' anchor rather than the every-token-earns-its-place level 5.

4 / 5

Actionability

Copy-paste-ready commands appear exactly where needed: a complete create-bucket invocation with the required namespace flag, a full put-bucket-policy JSON document, `python3 -m json.tool` validation, and troubleshooting one-liners with `--query` filters — matching the level-5 'fully executable, copy-paste ready' anchor.

5 / 5

Workflow Clarity

Workflow A is explicitly ordered ("execute in order, do not skip") with six numbered steps; the destructive put-bucket-policy operation has full safety rules (retrieve existing, back up, merge, validate, confirm); and feedback loops are explicit ("re-run the relevant audit check after applying the fix", "Verify with get-bucket-encryption after applying"), satisfying the level-5 anchor with validation checkpoints well above the destructive-operation cap of 3.

5 / 5

Progressive Disclosure

SKILL.md is a genuine overview (classification table, constraints, troubleshooting) with all CLI detail pushed to five real, one-level-deep reference files, each clearly signaled with its content both inline and in a resources section — matching the level-5 'clear overview with well-signaled one-level-deep references' anchor.

5 / 5

Total

19

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capability list, explicit "Use when…" triggers covering all five workflows, and a Do-NOT-Use boundary clause that sharply reduces mis-trigger risk. The only gap is modest synonym coverage in the trigger terms.

DimensionReasoningScore

Specificity

"access control, encryption, monitoring, and remediation of misconfigurations" plus "Create and secure S3 buckets" names multiple concrete actions that comprehensively cover the skill's five workflows, matching the level-5 anchor rather than the 'minor gaps' of level 4.

5 / 5

Completeness

It clearly answers both "what" (create and secure S3 buckets across access control, encryption, monitoring, remediation) and "when" via an explicit "Use when the user wants to…" clause with five concrete trigger scenarios, exactly matching the level-5 anchor.

5 / 5

Trigger Term Quality

Natural phrases like "secure a new bucket", "audit an existing bucket", "fix a security finding", "configure encryption", and "enable logging and monitoring" give good keyword coverage, but common synonyms such as "harden", "review bucket security", or "bucket policy" are absent, placing it just below the comprehensive-synonym level 5 anchor.

4 / 5

Distinctiveness Conflict Risk

A clear S3-security niche with an explicit negative boundary ("Do NOT use for general S3 data operations, S3 Tables setup, or discovering existing data assets") minimizes conflict risk with adjacent S3 skills, matching the level-5 anchor.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.