CtrlK
BlogDocsLog inGet started
Tessl Logo

shieldadvanced

Configures AWS Shield Advanced for enhanced Distributed Denial of Service (DDoS) protection: subscribing accounts and adding resource protections, enabling automatic application layer (layer 7) mitigation through AWS WAF, configuring health-based detection with Route 53 health checks, setting up Shield Response Team (SRT) access and proactive engagement, reviewing DDoS events and requesting cost protection credits, and aggregating resources into protection groups. Applicable when the user wants stronger DDoS protection for internet-facing resources (CloudFront, Application or Network Load Balancers, Elastic IP addresses, Global Accelerator, or Route 53 hosted zones), wants expert help during an attack, or wants to recover attack-driven scaling charges. Routes to the right per-task procedure in references. Not applicable for authoring AWS WAF rules (waf skill), creating Route 53 health checks (route53 skill), or org-wide Shield Advanced rollout with Firewall Manager (firewallmanager skill).

79

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-architected router skill: concise, decision-rich overview; concrete cross-cutting constraints; clear routing precedence; and verified one-level-deep references. The body adds judgment Claude could not infer and delegates execution detail appropriately.

DimensionReasoningScore

Conciseness

Lean router body that assumes Claude's competence — no padding explaining what DDoS or Shield is; every section (routing table, routing notes, logging, security) carries decision guidance Claude could not derive, with concrete identifiers earning their tokens. Not the 2 anchor because there is no unnecessary explanation to tighten.

3 / 3

Actionability

Concrete and executable guidance throughout: 'pass --region us-east-1 on every aws shield command', the AWSManagedRulesAntiDDoSRuleSet managed rule group, 'disassociate-drt-role', and an 'aws:SourceAccount' trust-policy condition, plus an explicit goal→reference routing table; instruction-only but specific, so it meets the 3 anchor rather than the pseudocode/incomplete 2 anchor.

3 / 3

Workflow Clarity

The routing workflow is unambiguous with explicit precedence ('Decide before you subscribe', 'Subscribe and protect comes first', 'Run the subscribing reference before any of the others if the customer is starting from scratch') and a clear single action (pick the matching reference, read it in full before acting); validation for risky operations correctly lives in the references, so it clears the 3 anchor for a router skill rather than capping at 2.

3 / 3

Progressive Disclosure

Textbook one-level-deep structure: a concise overview plus a routing table linking to seven real, verified reference files (all confirmed present in references/), with details split out rather than inlined; matches the 'clear overview with well-signaled one-level-deep references' anchor and is not the 2 anchor because nothing that should be separate is inline.

3 / 3

Total

12

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: third-person voice, comprehensive concrete capabilities, explicit when-to-use triggers, explicit non-applicability boundaries, and clear de-confliction against sibling skills. No changes needed.

DimensionReasoningScore

Specificity

Lists many concrete actions — 'subscribing accounts and adding resource protections', 'enabling automatic application layer (layer 7) mitigation through AWS WAF', 'configuring health-based detection with Route 53 health checks', 'setting up SRT access and proactive engagement', 'reviewing DDoS events and requesting cost protection credits', 'aggregating resources into protection groups' — matching the multi-action anchor; not the 2 anchor because it is comprehensive, not partial.

3 / 3

Completeness

Explicitly answers both what (the enumerated capabilities) and when via the 'Applicable when the user wants...' clause, and adds an explicit 'Not applicable for...' boundary; clearly above the 2 anchor where the when clause is missing or only implied.

3 / 3

Trigger Term Quality

Natural trigger phrases users would say ('wants stronger DDoS protection', 'wants expert help during an attack', 'wants to recover attack-driven scaling charges') plus concrete resource keywords (CloudFront, Load Balancers, Elastic IP addresses, Global Accelerator, Route 53 hosted zones); broader and more natural than the 2 anchor's single 'Works with PDF files'.

3 / 3

Distinctiveness Conflict Risk

Narrow Shield Advanced niche with explicit de-confliction against the waf, route53, and firewallmanager skills; unlikely to trigger for the wrong skill, matching the 'clear niche with distinct triggers' anchor.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.