CtrlK
BlogDocsLog inGet started
Tessl Logo

setting-up-cloudtrail-multi-region

Enables a multi-region AWS CloudTrail trail with S3 log storage, CloudWatch Logs integration, and CloudWatch Logs Insights queries for security monitoring and compliance auditing. Use when setting up centralized API activity logging across all AWS regions.

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/specialized-skills/operations-skills/setting-up-cloudtrail-multi-region/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, appropriately brief hub that delegates the heavy procedure to a real, well-organized one-level-deep reference and keeps quick troubleshooting inline. Main weaknesses are mild redundancy between the body and the reference (overview restating the description, duplicated troubleshooting topics) and the body not surfacing the procedure's validation checkpoints.

Suggestions

Trim or remove the Overview paragraph, which restates the frontmatter description almost verbatim.

Consolidate troubleshooting: either point to the reference's Knowledge Base Troubleshooting section from the body instead of duplicating it, or keep only the quick fixes in the body and drop the duplicated detail from the reference.

Surface the procedure's key validation checkpoint in the body (e.g. 'Step 8 verifies trail status and cross-region log delivery before reporting success') so users know verification is part of the flow.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence ("follow the procedure exactly"), but the Overview paragraph ("Domain expertise for enabling AWS CloudTrail across all regions to capture comprehensive API activity logs...") largely restates the frontmatter description, and the Troubleshooting section duplicates topics already covered in the reference's Knowledge Base Troubleshooting — minor trimmable redundancy fitting the 4 anchor.

4 / 5

Actionability

Concrete commands appear where needed ("aws sts get-caller-identity", "start-logging") alongside specific guidance ("log group exists in the same region as the trail", "Wait up to 24 hours"), and the full executable procedure is delegated to a real reference file; however the main section is a pointer and some items like "check S3 bucket policy allows CloudTrail access" lack the specific command, matching 'mostly executable with minor gaps'.

4 / 5

Workflow Clarity

The referenced procedure provides a clear 9-step sequence with a dedicated Verify Configuration step and per-step verification constraints, and the body's troubleshooting acts as error recovery; however the body itself only says "follow the procedure exactly" without surfacing any sequencing or validation checkpoints, so it sits just below the explicit-validation 5 anchor.

4 / 5

Progressive Disclosure

Good hub structure: a single clearly signaled, verified, one-level-deep reference (references/cloudtrail-multi-region-setup.md, 332 lines, no nested .md references) with well-organized body sections; the minor gap is troubleshooting content maintained in both the body and the reference's Knowledge Base, keeping it below the 'content appropriately split' 5 anchor.

4 / 5

Total

16

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: specific, third-person, with concrete capabilities and an explicit Use-when clause occupying a well-differentiated niche. The only weakness is that the trigger clause is narrower than the skill's stated capabilities, covering setup but not monitoring or compliance analysis.

Suggestions

Broaden the 'Use when' clause to cover the analysis side of the skill, e.g. 'Use when setting up centralized API activity logging across all AWS regions or when auditing AWS API activity with CloudWatch Logs Insights'.

Add one or two natural synonyms users might say, such as 'audit logging' or 'CloudTrail trail', to strengthen trigger matching.

DimensionReasoningScore

Specificity

"Enables a multi-region AWS CloudTrail trail with S3 log storage, CloudWatch Logs integration, and CloudWatch Logs Insights queries" names four concrete capability areas in third person, matching the comprehensive-coverage anchor rather than the 'minor gaps' level of 4.

5 / 5

Completeness

Both what and when are present with an explicit "Use when setting up centralized API activity logging across all AWS regions", but the when-clause covers only setup and omits triggers for the monitoring and compliance-analysis use cases stated in the what, so it falls just below the fully-explicit 5 anchor.

4 / 5

Trigger Term Quality

Good natural keyword coverage ("CloudTrail", "AWS", "security monitoring", "compliance auditing", "API activity logging") that users would actually say, but common variations like "audit logging", "audit trail", or "trail setup" are missing, fitting the 'a few natural terms missing' anchor.

4 / 5

Distinctiveness Conflict Risk

"multi-region AWS CloudTrail trail with S3 log storage, CloudWatch Logs integration" carves out a clear niche with distinct triggers; minimal realistic overlap with other skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.