CtrlK
BlogDocsLog inGet started
Tessl Logo

shieldadvanced

Configures AWS Shield Advanced for enhanced Distributed Denial of Service (DDoS) protection: subscribing accounts and adding resource protections, enabling automatic application layer (layer 7) mitigation through AWS WAF, configuring health-based detection with Route 53 health checks, setting up Shield Response Team (SRT) access and proactive engagement, reviewing DDoS events and requesting cost protection credits, and aggregating resources into protection groups. Applicable when the user wants stronger DDoS protection for internet-facing resources (CloudFront, Application or Network Load Balancers, Elastic IP addresses, Global Accelerator, or Route 53 hosted zones), wants expert help during an attack, or wants to recover attack-driven scaling charges. Routes to the right per-task procedure in references. Not applicable for authoring AWS WAF rules (waf skill), creating Route 53 health checks (route53 skill), or org-wide Shield Advanced rollout with Firewall Manager (firewallmanager skill).

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured router: an overview, a goal-to-reference table, decision-oriented routing notes, and security/logging callouts, all pointing to one level of self-contained reference files. It is efficient and actionable with only minor over-explanation in the overview.

Suggestions

Trim the Overview's capability list since it duplicates the frontmatter description; keep only the 'this skill is a router' framing and the global/MCP execution notes.

Surface one explicit validation checkpoint per destructive/commitment step in the routing notes (e.g., 'confirm the one-year commitment cost before create-protection') rather than relying solely on the references.

DimensionReasoningScore

Conciseness

The body is lean for a router skill and assumes Claude's knowledge, but the Overview paragraph partly re-lists the capabilities already in the description, and a few routing-note sentences could be tightened without losing decision value.

4 / 5

Actionability

Concrete tokens are present — 'pass --region us-east-1 on every aws shield command', 'scope its trust policy with an aws:SourceAccount condition', 'revoke it with disassociate-drt-role' — plus a goal→reference routing table; it stops short of copy-paste code blocks, but as an instruction/router skill the guidance is actionable.

4 / 5

Workflow Clarity

Sequencing is explicit ('Decide before you subscribe', 'Subscribe and protect comes first... Run the subscribing reference before any of the others'), with prerequisites stated, though detailed validation checkpoints are deferred to the per-task references rather than surfaced here.

4 / 5

Progressive Disclosure

A clear overview routes via a goal→reference table to seven real, one-level-deep reference files (all verified present), each described as self-contained; navigation is easy and nothing is deeply nested.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it enumerates concrete capabilities, provides explicit 'Applicable when' trigger conditions with natural user phrasing, and cleanly disambiguates from sibling skills via a negative-boundary clause. No verbosity or fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'subscribing accounts and adding resource protections', 'enabling automatic application layer (layer 7) mitigation', 'configuring health-based detection', 'setting up SRT access and proactive engagement', 'reviewing DDoS events and requesting cost protection credits', 'aggregating resources into protection groups' — giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both what (the enumerated configuration tasks) and when ('Applicable when the user wants stronger DDoS protection...'), with concrete trigger phrases and an explicit non-applicability boundary.

5 / 5

Trigger Term Quality

Natural trigger phrases abound — 'wants stronger DDoS protection for internet-facing resources', 'wants expert help during an attack', 'wants to recover attack-driven scaling charges' — alongside concrete resource names (CloudFront, ALB/NLB, Elastic IP, Global Accelerator, Route 53 hosted zones).

5 / 5

Distinctiveness Conflict Risk

The 'Not applicable for authoring AWS WAF rules (waf skill), creating Route 53 health checks (route53 skill), or org-wide Shield Advanced rollout with Firewall Manager (firewallmanager skill)' clause carves out a clear, distinct niche with minimal conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.