CtrlK
BlogDocsLog inGet started
Tessl Logo

transitgateway

Configures AWS Transit Gateway: creating a hub and attaching VPCs, segmenting traffic with route tables, centralizing egress and inspection through a hub (appliances or a Gateway Load Balancer endpoint), forcing east-west traffic between VPCs through AWS Network Firewall, connecting on-premises networks over the transit-gateway side of a Site-to-Site VPN or Direct Connect attachment (including ECMP to aggregate bandwidth across multiple VPN tunnels), peering transit gateways across Regions, migrating from a VPC peering mesh, and routing IP multicast. Applicable when connecting many VPCs through one router, isolating environments, forcing VPC-to-VPC traffic through a central Network Firewall, reaching on-premises over the hub, linking Regions, or moving off a peering mesh. Not applicable for single-VPC routing, VPC peering between two VPCs (vpcpeering skill), Direct Connect gateway or virtual interface setup (directconnect skill), or Route 53 DNS work.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-executed router skill: lean decision guidance in the body, a clean dispatch table to eight real, self-contained references, and sharp routing notes that guide reference selection. The minor deductions come from slight overlap between the Overview and the description and from validation being delegated to the references rather than stated in the body.

DimensionReasoningScore

Conciseness

The body is efficient — the Routing notes carry genuinely non-obvious decision content (default route table propagation wiring an open mesh, appliance-mode disabling cross-AZ failover) and no space is spent on concepts Claude already knows. The Overview paragraph slightly restates the frontmatter description and a few sentences run long.

4 / 5

Actionability

As an instruction-only router skill it gives concrete directives: a goal→reference dispatch table, 'Read the matching reference in full before acting', MCP-first with CLI fallback, ephemeral STS/SSO credentials only, and 'run each aws ec2 transit gateway command in the Region that holds the hub'. Bulk executable detail is deliberately and appropriately delegated to the references.

4 / 5

Workflow Clarity

The workflow (match goal → read reference in full → follow its constraints and steps) is unambiguous, and the references verified to carry Workflow, Procedure, verification, and Troubleshooting sections. Validation checkpoints are present but live in the delegated files rather than the body itself, so it does not fully meet the anchor-5 bar.

4 / 5

Progressive Disclosure

Textbook router structure: a concise overview, an eight-row table mapping customer goals to one-level-deep reference files, and all eight referenced files verified present under references/ and self-contained. Navigation is exactly the anchor-5 pattern.

5 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: comprehensive concrete capabilities, explicit positive and negative applicability triggers, and explicit disambiguation against neighboring skills. The only gap is a few missing natural synonyms such as 'hub-and-spoke' and 'TGW'.

DimensionReasoningScore

Specificity

The description enumerates eight concrete, distinct actions — 'creating a hub and attaching VPCs, segmenting traffic with route tables, centralizing egress and inspection', 'forcing east-west traffic... through AWS Network Firewall', 'peering transit gateways across Regions, migrating from a VPC peering mesh, and routing IP multicast' — giving comprehensive coverage of the skill's task space.

5 / 5

Completeness

Both what and when are answered explicitly and concretely: the opening clause lists what the skill does, 'Applicable when' lists concrete triggers, and 'Not applicable for' adds negative triggers with skill referrals.

5 / 5

Trigger Term Quality

Natural trigger phrases are present ('connecting many VPCs through one router', 'isolating environments', 'reaching on-premises over the hub', 'linking Regions', 'moving off a peering mesh') plus product names users actually say (Site-to-Site VPN, Direct Connect, Network Firewall), but common synonyms like 'hub-and-spoke' and the 'TGW' abbreviation are missing.

4 / 5

Distinctiveness Conflict Risk

The description carves out a clear niche and actively disambiguates against adjacent skills — 'Not applicable for... VPC peering between two VPCs (vpcpeering skill), Direct Connect gateway or virtual interface setup (directconnect skill)' — minimizing wrong-skill triggering.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
aws/agent-toolkit-for-aws
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.