CtrlK
BlogDocsLog inGet started
Tessl Logo

setting-up-ec2-instance-profiles

Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials. Use when an EC2 instance needs permissions to access AWS services like S3, DynamoDB, SQS, or CloudWatch through temporary credentials.

68

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, lean skill body that appropriately delegates the detailed procedure to a single verified reference file and keeps concise, actionable troubleshooting inline. The main workflow in the bundle has explicit validation and recovery steps, leaving only minor tightening opportunities in the Overview and a couple of additional inline verification commands.

DimensionReasoningScore

Conciseness

The ~40-line body is lean with no explanation of concepts Claude already knows, but the Overview section partially duplicates the frontmatter description and the reference file's own overview, so a few tokens could be trimmed.

4 / 5

Actionability

Troubleshooting entries give concrete, executable guidance ('aws ec2 describe-instances --region <region>', 'AWS_ACCESS_KEY_ID', '~/.aws/credentials', CloudTrail review), and the main procedure delegates to a fully executable reference SOP — minor gaps remain, e.g., no inline credential-verification command like 'aws sts get-caller-identity'.

4 / 5

Workflow Clarity

The body directs the reader unambiguously to the procedure ('follow the procedure exactly'), and the referenced SOP is a 10-step sequence with explicit validation checkpoints (Step 2 instance verification, Step 9 'Verify Configuration and Test Access'), error-recovery guidance, and a prompt before disassociating an existing profile.

5 / 5

Progressive Disclosure

The body is a clean overview with one clearly signaled, one-level-deep reference (references/ec2-instance-profile-setup.md — verified to exist, with no nested references), and troubleshooting content that belongs inline is kept inline.

5 / 5

Total

18

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly and explicitly states both capability and trigger conditions with concrete service names, in proper third-person voice. Keyword coverage is good but could add a few natural synonyms (e.g., 'access keys', 'instance role') and mention verification to round out capability coverage.

DimensionReasoningScore

Specificity

The description lists several concrete third-person actions — 'creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials' — but omits parts of the skill's actual coverage such as verifying credential availability and reusing existing roles, so it is not fully comprehensive.

4 / 5

Completeness

It explicitly answers both what ('Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles') and when ('Use when an EC2 instance needs permissions to access AWS services like S3, DynamoDB, SQS, or CloudWatch through temporary credentials') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural terms like 'EC2 instance', 'IAM roles', 'instance profiles', 'S3, DynamoDB, SQS, CloudWatch', 'temporary credentials', and 'hardcoded credentials' give good coverage of phrases users would say, though common variations such as 'access keys' or 'AWS credentials on the instance' are missing.

4 / 5

Distinctiveness Conflict Risk

The EC2 instance-profile niche with service-specific triggers is well distinguished, but there is minor overlap risk with closely related general IAM-role or AWS-credentials skills.

4 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.