CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-security-audit

Comprehensive AWS security posture assessment using AWS CLI and security best practices

66

1.12x
Quality

55%

Does it follow best practices?

Impact

82%

1.12x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-aws-security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is strong on executable AWS CLI guidance and covers a broad, sensible set of audit categories, but it is a monolithic checklist with no defined audit workflow or validation checkpoints. Splitting per-category checks, the audit script, and compliance mappings into reference files and adding a sequenced procedure would substantially improve it.

Suggestions

Add a sequenced audit workflow with validation checkpoints (e.g. 1. verify credentials and region with 'aws sts get-caller-identity', 2. run category checks, 3. validate findings, 4. compile report with remediation priorities), since the current batch audit script has no error handling.

Move the per-category check listings, the audit script, and the compliance mapping into separate reference files (e.g. references/iam-checks.md, references/audit-script.sh) and keep SKILL.md as a concise overview with clearly signaled one-level-deep links.

Fix or complete the Python score calculator (the MFA check never parses the credential report and the bare 'except: pass' silently swallows errors) or remove the duplicated inlined audit script to reduce redundancy.

DimensionReasoningScore

Conciseness

The per-category check sections are lean command listings, but the 'Automated Security Audit Script' and 'Security Score Calculator' re-inline commands already shown, and the 'Best Practices'/'Example Prompts' sections add padding; it is mostly efficient but could be tightened rather than noticeably verbose.

3 / 5

Actionability

Dozens of concrete, executable aws CLI commands with specific --query filters cover the common cases; minor gaps (hardcoded 'my-trail' name, and the Python score calculator contains a stub MFA check with a bare 'except: pass' and no credential parsing) keep it below fully copy-paste-ready.

4 / 5

Workflow Clarity

The content is a catalog of checks rather than a sequenced audit procedure — there is no ordering such as 'verify credentials, run IAM checks, validate output, compile report', and the batch audit script includes no validation checkpoints, matching 'steps listed but validation gaps'.

3 / 5

Progressive Disclosure

Section headers give reasonable structure, but all ~365 lines live in SKILL.md with no bundle files — the per-category check commands, compliance mapping, audit script, and score calculator clearly belong in separate reference files, matching 'content that should be separate is inline'.

3 / 5

Total

13

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a clear domain and a single concrete capability but relies on buzzwords ('Comprehensive', 'best practices') and omits any 'when to use' trigger guidance. Adding an explicit 'Use when…' clause with natural trigger terms like 'audit', 'compliance', or 'misconfigurations' would lift completeness and trigger-term quality.

Suggestions

Add an explicit trigger clause, e.g. 'Use when the user asks to audit their AWS account, review security posture, check for misconfigurations, or prepare for compliance assessments (CIS, PCI-DSS, HIPAA).'

Replace 'Comprehensive' and 'security best practices' with 2-3 concrete actions such as 'identifies IAM, network, encryption, and logging misconfigurations and generates remediation priorities'.

Include natural user phrasings ('security audit', 'check my AWS security', 'compliance report') as trigger terms since those are the words users would actually say.

DimensionReasoningScore

Specificity

Names the domain ('AWS security posture assessment') and one concrete action (assessment), but 'Comprehensive' and 'security best practices' are generic padding rather than additional specific actions, matching the 1-2-concrete-actions anchor rather than the several-actions anchors above.

3 / 5

Completeness

The 'what' is clearly stated ('Comprehensive AWS security posture assessment using AWS CLI'), but there is no 'Use when…' or equivalent trigger clause, which per the judging guidelines caps completeness at 3.

3 / 5

Trigger Term Quality

Keywords 'AWS', 'security', and 'AWS CLI' are relevant, but the natural phrases users would say — 'audit my AWS account', 'compliance', 'vulnerabilities', 'misconfigurations' — are absent, fitting 'some relevant keywords but missing common variations' rather than the good coverage of 4.

3 / 5

Distinctiveness Conflict Risk

'AWS security posture assessment' carves a mostly distinct niche with minor overlap risk against closely related AWS or general-security skills; it lacks the explicitly distinct trigger phrases that would justify a 5.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.