CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-iam-best-practices

IAM policy review, hardening, and least privilege implementation

50

Quality

55%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-aws-iam-best-practices/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is strong on executable content — real CLI commands, complete policy templates, and a working script — but it functions as a reference catalog rather than a guided workflow, with weak validation around destructive operations. Redundancy between the bash checks, the Python script, and the repeated principles/best-practices sections, plus everything inlined in one long file, hurt token efficiency and structure.

Suggestions

Deduplicate: the Python iam-hardening.py repeats the MFA, old-key, and wildcard-policy bash checks, and "Best Practices" restates "Core Principles" — keep one canonical version of each check and one principles section.

Extract the four policy templates and the hardening script into reference files (e.g., references/templates.md, scripts/iam-hardening.py) linked from a lean SKILL.md overview.

Add a sequenced hardening workflow with explicit validation checkpoints (run checks → review findings → apply changes in non-production → verify with aws iam simulate-principal-policy) and remove the hardcoded 2026 dates from the Time-Based Access template.

DimensionReasoningScore

Conciseness

The bulk is dense executable content, but there is real padding: "Core Principles" teaches textbook concepts ("Grant minimum permissions needed"), the iam-hardening.py script duplicates three of the bash checks, and the closing "Best Practices" section repeats "Core Principles"; the Time-Based Access template also hardcodes dates ("2026-01-01" to "2026-12-31") outside any deprecated section. This matches 'mostly efficient but includes some unnecessary explanation', not a 2 since nearly every section carries executable commands rather than prose filler.

3 / 5

Actionability

Concrete, mostly copy-paste-ready guidance throughout: complete aws iam CLI pipelines, four full policy JSON templates, and a runnable boto3 script. Minor gaps keep it below 5: the rotation example uses a placeholder (OLD_KEY="<AWS_ACCESS_KEY_ID>"), and grepping for '"Action": "*"' misses URL-encoded policy documents.

4 / 5

Workflow Clarity

Content is organized as a catalog of checks, templates, and checklists rather than a sequenced hardening workflow, and destructive/batch operations (deleting access keys, replacing policies) have only weak, implicit validation ("test first", "Test policies in non-production first") with no validate-then-fix feedback loop — capping this at 3 per the guidelines. Not a 2 because sections are coherently grouped and small validation hints do exist.

3 / 5

Progressive Disclosure

Section headers and checklists provide real structure, but the ~390-line body inlines content that belongs in reference files (four policy templates and a ~60-line Python script), and no bundle files exist to offload them. Matches 'some structure but could be better organized; content that should be separate is inline' — not a 2 given the genuinely clear organization, not a 4 because no content is split out.

3 / 5

Total

13

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description names a specific domain and a few actions but reads as a terse label rather than a trigger-rich description. It completely lacks a 'when to use' clause, which both caps completeness and weakens trigger-term quality. Adding explicit usage triggers and natural user phrasings would materially improve it.

Suggestions

Add an explicit trigger clause, e.g., "Use when reviewing or auditing IAM policies, tightening permissions to least privilege, finding unused access keys or wildcard permissions, or hardening AWS account security."

Include natural phrases users would actually say, such as "audit my IAM setup", "find users without MFA", or "generate a hardening report", to improve trigger-term coverage.

Name concrete deliverables (e.g., "produces an IAM hardening report and least-privilege policy JSON") to sharpen the 'what' beyond generic verbs like review and harden.

DimensionReasoningScore

Specificity

Names the domain ("IAM policy") and 2-3 actions ("review", "hardening", "least privilege implementation"), but the actions are generic verbs with no concrete deliverables (e.g., hardening reports, least-privilege policy JSON), matching the 'names domain and 1-2 concrete actions, but not comprehensive' anchor. Not a 4 because it does not enumerate several specific actions or outputs.

3 / 5

Completeness

The 'what' is clear ("IAM policy review, hardening, and least privilege implementation") but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. Not a 2 because the 'what' is concrete rather than vague.

3 / 5

Trigger Term Quality

Relevant keywords are present ("IAM", "policy", "least privilege") but common natural phrasings users would actually say are missing ("audit IAM", "find users without MFA", "unused access keys", "wildcard permissions"), matching 'some relevant keywords but missing common variations or synonyms'. Not a 4 because keyword coverage lacks synonym variation.

3 / 5

Distinctiveness Conflict Risk

"IAM policy" and "least privilege" carve a clear AWS-specific niche with only minor overlap risk against generic AWS-security or security-audit skills, matching 'mostly distinct; minor overlap risk with closely related skills'. Not a 5 because the absence of explicit trigger phrases leaves some ambiguity versus adjacent AWS security skills.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.