CtrlK
BlogDocsLog inGet started
Tessl Logo

setup-security-agent

Configure AWS Security Agent for the current workspace — provision or reuse an agent space, IAM service role, and S3 bucket. Use when the user asks to "set up security agent", "configure security scanner", "is security agent configured", or on first-time use before any scan or pentest.

75

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable, copy-paste-ready setup guidance with an unusually strong validation posture (ownership assertion, idempotent fallbacks, fail-closed aborts). The main costs are token redundancy — the bucket-squatting warning appears three times — and a 215-line monolith where a reference file or two would keep the SKILL.md body leaner.

Suggestions

State the bucket-squatting / --expected-bucket-owner rule once (e.g., in the step 5 blockquote) and have the Rules and Troubleshooting sections reference it in one line each, cutting ~10 lines of repeated rationale.

Move the trust/permissions/lifecycle policy JSON documents and the Troubleshooting section into a references/ file (e.g. references/policies.md, references/troubleshooting.md), keeping SKILL.md as a lean overview with one-level-deep, clearly signaled references.

Trim the "Why minimal config" paragraph to its actionable core ("only agent_space_id is stored; everything else is derived to avoid stale-path drift").

DimensionReasoningScore

Conciseness

The body is dense with executable commands and almost entirely plugin-specific (no explanation of concepts Claude already knows), but the bucket-squatting/--expected-bucket-owner rationale is repeated three times (step 5 blockquote, Rules, Troubleshooting) and the "Why minimal config" paragraph could be tightened. Not 5 because of that redundancy; not 3 because padding is minor and localized.

4 / 5

Actionability

Copy-paste-ready bash throughout: complete heredoc trust/permissions/lifecycle policy JSONs, region-aware create-bucket (us-east-1 special case), stderr capture with explicit 404/403/BucketAlreadyExists branching and exit codes, and idempotent read-then-merge registration. Specific examples cover the common cases, matching the 5 anchor.

5 / 5

Workflow Clarity

A 9-step sequence with explicit validation checkpoints (role probe with EntityAlreadyExists fallback, ownership-asserting head-bucket, post-create ownership re-assert, fail-closed 403 handling) and a troubleshooting section with error-recovery guidance — an exact match for the 5 anchor (clear sequence, validation, feedback loops).

5 / 5

Progressive Disclosure

No bundle files exist; the skill is a single well-sectioned 215-line file with clear headers (state convention, workflow, rules, troubleshooting) and inline policy JSONs that are directly consumed by the commands. Not 5: nothing is split out and the file runs long — troubleshooting and the policy documents could live in reference files; not 3: structure is clear and nothing is buried or nested.

4 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete actions covering the full setup scope, an explicit 'Use when' clause with verbatim user trigger phrases including a status-check question form, and third-person voice. The only weakness is minor overlap risk with sibling scan/pentest skills via the 'before any scan or pentest' trigger.

DimensionReasoningScore

Specificity

"provision or reuse an agent space, IAM service role, and S3 bucket" lists multiple concrete actions that comprehensively cover the skill's entire setup scope. Not 4: no coverage gaps remain for a setup skill; the actions named are exactly the resources the workflow creates.

5 / 5

Completeness

Explicitly answers both what ("Configure AWS Security Agent... provision or reuse an agent space, IAM service role, and S3 bucket") and when ("Use when the user asks to... or on first-time use before any scan or pentest") with concrete trigger phrases — an exact match for the 5 anchor.

5 / 5

Trigger Term Quality

Quotes exact user utterances — "set up security agent", "configure security scanner", "is security agent configured" — plus the proactive condition "on first-time use before any scan or pentest", covering synonyms and a natural question form. Not 4: the natural phrases a user would actually say are all present verbatim.

5 / 5

Distinctiveness Conflict Risk

"AWS Security Agent" is a clear niche with distinct triggers, but "before any scan or pentest" overlaps with closely related sibling scan/pentest skills. Not 5: scan/pentest mentions could route to this setup skill; not 3: the domain and triggers are specific enough that broad conflicts are unlikely.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.