CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-secrets-rotation

Automate AWS secrets rotation for RDS, API keys, and credentials

52

Quality

59%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-aws-secrets-rotation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable — real commands and complete code for secret creation, rotation, monitoring, and compliance — but it is a monolithic 460-line document that inlines full scripts and redundant SDK boilerplate instead of splitting them into bundle files. Workflow ordering is implicit rather than sequenced, and validation checkpoints for production-impacting rotation operations are scattered rather than explicit.

Suggestions

Extract lambda_rotation.py, api_key_rotation.py, audit-rotations.sh, and compliance-report.py into a scripts/ directory and reference them from SKILL.md, keeping the body as a concise overview.

Replace the implicit section order with an explicit numbered workflow with validation checkpoints (e.g., verify rotation status with describe-secret and confirm app connectivity before and after each rotation).

Trim the "Application Integration" Python/Node SDK snippets and the Kiro CLI/Example Prompts sections — retrieving a secret with boto3 is knowledge Claude already has.

DimensionReasoningScore

Conciseness

The body is mostly commands and code rather than prose explanation, but at ~460 lines it inlines material Claude already knows (generic boto3 / aws-sdk get-secret snippets in "Application Integration") and duplicates overlap between the bash audit script and the Python compliance report. Mostly efficient with sections that could be tightened, matching anchor 3 rather than 4's "minor instances of over-explanation".

3 / 5

Actionability

Concrete, copy-paste-ready CLI commands (create-secret, rotate-secret, put-metric-alarm) and complete Python rotation functions cover the common cases. Not 5 because of minor executable gaps: the Lambda handler reads secret['dbInstanceIdentifier'] which the create-secret example never defines, and "--rotate-immediately" is not a real aws CLI parameter for rotate-secret.

4 / 5

Workflow Clarity

Sections imply an order (create secret → enable rotation → monitor) and include scattered verification commands (describe-secret checks, CloudWatch alarms), but there is no explicit sequenced workflow with validate-before-proceeding checkpoints for what is a batch operation on production credentials. This matches anchor 3 ("sequence present but checkpoints missing or implicit") and is capped there by the destructive/batch validation guideline.

3 / 5

Progressive Disclosure

The body has clear section headers, but no bundle files exist and everything is inlined in a single monolithic SKILL.md, including three full scripts (lambda_rotation.py, audit-rotations.sh, compliance-report.py) that clearly belong in a scripts/ directory. This matches anchor 3 ("some structure but content that should be separate is inline"); not 2 because headers do provide real navigational structure.

3 / 5

Total

13

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and domain-scoped with a clear statement of what the skill does, but it lacks any "when to use" trigger clause and misses natural synonyms like "Secrets Manager". It is serviceable but below the bar set by the good examples, which pair concrete capabilities with explicit trigger guidance.

Suggestions

Add an explicit trigger clause, e.g. "Use when rotating RDS/database credentials, API keys, or OAuth tokens in AWS Secrets Manager, or when compliance policies require scheduled key rotation."

Broaden natural keyword coverage with synonyms users actually say: "Secrets Manager", "key rotation", "rotate credentials", "rotate database password".

Reflect the skill's fuller capability set (rotation Lambda setup, monitoring, emergency rotation, compliance audits) so the description isn't limited to a single action.

DimensionReasoningScore

Specificity

"Automate AWS secrets rotation for RDS, API keys, and credentials" names the domain and a single concrete action (automate rotation) applied to a list of secret types, but does not mention setup, monitoring, compliance, or emergency rotation. It matches anchor 3 ("names domain and 1-2 concrete actions, but not comprehensive") rather than 4, which requires several specific distinct actions.

3 / 5

Completeness

The description clearly answers "what" (automate rotation of RDS, API keys, and credentials) but contains no "Use when..." clause or equivalent trigger guidance, which caps completeness at 3 per the judging guidelines. It is not 2 because the "what" is clear and specific rather than vague.

3 / 5

Trigger Term Quality

Terms like "AWS", "secrets", "rotation", "RDS", "API keys", and "credentials" are phrases users would naturally say. Not 5 because common variations such as "Secrets Manager", "key rotation", and "rotate credentials" are missing; not 3 because coverage goes beyond one or two generic keywords.

4 / 5

Distinctiveness Conflict Risk

"AWS secrets rotation" carves out a clear niche unlikely to collide with unrelated skills, though the generic word "credentials" leaves minor overlap risk with general credential-management skills. Not 5 because the trigger surface is not fully distinct (no explicit trigger phrases delimiting it).

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.