CtrlK
BlogDocsLog inGet started
Tessl Logo

shieldadvanced

Configures AWS Shield Advanced for enhanced Distributed Denial of Service (DDoS) protection: subscribing accounts and adding resource protections, enabling automatic application layer (layer 7) mitigation through AWS WAF, configuring health-based detection with Route 53 health checks, setting up Shield Response Team (SRT) access and proactive engagement, reviewing DDoS events and requesting cost protection credits, and aggregating resources into protection groups. Applicable when the user wants stronger DDoS protection for internet-facing resources (CloudFront, Application or Network Load Balancers, Elastic IP addresses, Global Accelerator, or Route 53 hosted zones), wants expert help during an attack, or wants to recover attack-driven scaling charges. Routes to the right per-task procedure in references. Not applicable for authoring AWS WAF rules (waf skill), creating Route 53 health checks (route53 skill), or org-wide Shield Advanced rollout with Firewall Manager (firewallmanager skill).

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-architected router skill: the body stays lean, routes every task to a self-contained reference with clear ordering and disambiguation rules, and includes genuinely non-obvious operational detail (us-east-1 control plane, SRT trust-policy scoping). The only drag is mild redundancy between the description, Overview, and Logging sections, and the absence of any inline validation checkpoints at the router level.

Suggestions

Trim the Overview paragraph, which re-enumerates the task list already given in the description and the routing table — one sentence pointing at the table would reclaim tokens.

Consolidate the three separate SSE-KMS bullets in Logging and monitoring (CloudTrail bucket, CloudWatch Logs group, SNS topics) into a single encryption recommendation covering all Shield-related log/notification destinations.

Add one router-level verification cue (e.g., 'after any protection or subscription change, confirm with `aws shield list-protections --region us-east-1`') so each delegated procedure lands back at a shared checkpoint.

DimensionReasoningScore

Conciseness

The body is dense and mostly operational (routing notes, `--region us-east-1` detail, `AWSManagedRulesAntiDDoSRuleSet`, `disassociate-drt-role`), but the Overview paragraph re-lists the task taxonomy already stated in the description, and the Logging/monitoring section repeats the SSE-KMS recommendation across three bullets. This is 'efficient with minor instances that could be trimmed', not the fully lean score-5 anchor.

4 / 5

Actionability

Concrete, actionable routing: a Goal→Reference table, executable command-level details (AWS MCP server vs CLI fallback, `--region us-east-1` on every `aws shield` command), a specific managed rule group name, and named CloudWatch metrics (`DDoSDetected`, `DDoSAttackBitsPerSecond`). It stops short of fully copy-paste-ready commands in the body, which is defensible for a router but leaves minor gaps versus the score-5 anchor.

4 / 5

Workflow Clarity

Sequencing is explicit — "Decide before you subscribe", "Run the subscribing reference before any of the others if the customer is starting from scratch", "Read the matching reference in full before acting" — with disambiguation guidance (automatic mitigation vs health-based detection; health check as SRT prerequisite). Validation checkpoints are delegated to the per-task references rather than present at the router level, so it sits at 'clear sequence with most checkpoints' rather than the explicit validation-loop anchor.

4 / 5

Progressive Disclosure

Textbook progressive disclosure: a concise router body, seven well-signaled one-level-deep references presented in a Goal→Reference table, all referenced files verified to exist in references/, and no nested or buried pointers. Easy navigation with content appropriately split.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: third-person voice, comprehensive and specific action list, explicit applicable/not-applicable triggers, and explicit disambiguation from adjacent skills. It reads like the rubric's own good-example pattern applied to a complex domain without padding.

DimensionReasoningScore

Specificity

The description enumerates concrete actions — "subscribing accounts and adding resource protections", "enabling automatic application layer (layer 7) mitigation through AWS WAF", "configuring health-based detection with Route 53 health checks", "reviewing DDoS events and requesting cost protection credits", "aggregating resources into protection groups" — covering the full capability surface. This matches the 'comprehensive coverage' anchor exactly, not the score-4 anchor which expects minor gaps.

5 / 5

Completeness

Both what (enumerated action list) and when ("Applicable when the user wants stronger DDoS protection... wants expert help during an attack, or wants to recover attack-driven scaling charges") are explicit, with a bonus "Not applicable for..." clause. This is a textbook match for the score-5 anchor with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural user phrasings are present — "wants stronger DDoS protection", "wants expert help during an attack", "wants to recover attack-driven scaling charges" — plus resource-name synonyms (CloudFront, Application or Network Load Balancers, Elastic IP addresses, Global Accelerator, Route 53 hosted zones). This hits the comprehensive-coverage-with-synonyms anchor; nothing common is missing.

5 / 5

Distinctiveness Conflict Risk

It carves out an explicit niche and names the neighboring skills it must not trigger — "Not applicable for authoring AWS WAF rules (waf skill), creating Route 53 health checks (route53 skill), or org-wide Shield Advanced rollout with Firewall Manager (firewallmanager skill)". Clear distinct triggers with minimal conflict risk, matching the score-5 anchor.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.