CtrlK
BlogDocsLog inGet started
Tessl Logo

sitetositevpn

Configures AWS Site-to-Site VPN: creating an IPsec VPN connection between an on-premises network and a VPC, choosing the target gateway (virtual private gateway, transit gateway, or AWS Cloud WAN), choosing static or dynamic (BGP) routing, sizing tunnel bandwidth (Standard 1.25 Gbps or Large 5 Gbps), connecting many sites through a VPN Concentrator, applying the customer gateway device configuration, making a connection highly available, and monitoring tunnels with CloudWatch. Applicable when the user wants to connect a data center or branch office to AWS over an encrypted tunnel, choose how routes are exchanged, scale throughput, consolidate sites, or diagnose a down tunnel. Routes to the right per-task procedure in references. Not for AWS Direct Connect (its own service), Client VPN for individual remote users, the transit gateway side of a VPN attachment (transitgateway skill), or Route 53 DNS work.

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured router skill: the body stays lean, routes each task to a verified, one-level-deep reference file, and contributes genuine cross-cutting AWS decision knowledge in the routing notes. The only minor gaps are slight redundancy with the frontmatter description and the absence of any example commands in the body itself.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence — routing notes carry non-obvious AWS specifics ("the only target that supports Large (5 Gbps) tunnels, equal-cost multi-path (ECMP) bandwidth aggregation, IPv6 customer gateways, and the VPN Concentrator") rather than generic IPsec education. Not a 5 because the Overview paragraph largely restates the frontmatter description and the "AWS side vs device side" bullet is mildly explanatory.

4 / 5

Actionability

Concrete, executable routing: a goal-to-reference table ("Decide between static and dynamic (BGP) routing → choosing-static-or-dynamic-routing.md"), a tool directive ("Execute commands using the AWS MCP server when connected... Fall back to the AWS CLI otherwise"), and a specific flag rule ("pass --region {region} matching the VPC or transit gateway"). Not a 5 because the body contains no example commands — all executable detail is delegated to the reference files.

4 / 5

Workflow Clarity

The workflow is unambiguous for a router skill — "Read the matching reference in full before acting, then follow its constraints and steps" — with explicit ordering guidance ("Run the choosing-static-or-dynamic-routing reference before creating the connection so the customer does not have to recreate it"). Not a 5 because validation/checkpoint behavior lives entirely in the references rather than being signaled here.

4 / 5

Progressive Disclosure

Textbook router structure: a concise overview, a routing table mapping each goal to one of seven reference files (all seven paths verified to exist in references/), one level deep, and a statement that "The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting." Navigation is easy and nothing that belongs in a reference is inlined.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: comprehensive concrete capabilities with specific numbers, an explicit applicability clause with natural trigger phrasing, and explicit exclusions that disambiguate it from neighboring AWS skills. Third-person voice throughout with no padding or over-claims.

DimensionReasoningScore

Specificity

Lists eight concrete actions ("creating an IPsec VPN connection", "choosing the target gateway (virtual private gateway, transit gateway, or AWS Cloud WAN)", "sizing tunnel bandwidth (Standard 1.25 Gbps or Large 5 Gbps)", "monitoring tunnels with CloudWatch") with exact numbers and named options, fully covering the service's task surface. Not a 4 because there are no coverage gaps — every per-task procedure in the bundle is named.

5 / 5

Completeness

Explicitly answers both questions: "what" is the eight-action capability list, and "when" is the concrete "Applicable when the user wants to connect a data center or branch office to AWS over an encrypted tunnel, choose how routes are exchanged, scale throughput, consolidate sites, or diagnose a down tunnel" clause. This matches the anchor-5 example's structure of what + explicit trigger phrases.

5 / 5

Trigger Term Quality

Covers the natural phrases users would say: "connect a data center or branch office to AWS over an encrypted tunnel", "diagnose a down tunnel", "choose how routes are exchanged", plus synonyms (Site-to-Site VPN, IPsec VPN, BGP, tunnel). Not a 4 because both the service names and the colloquial phrasings are present with no common variation missing.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (AWS Site-to-Site VPN) and explicitly fences off adjacent skills: "Not for AWS Direct Connect (its own service), Client VPN for individual remote users, the transit gateway side of a VPN attachment (transitgateway skill), or Route 53 DNS work." Conflict risk is minimal because the disambiguation is stated rather than implied.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.