CtrlK
BlogDocsLog inGet started
Tessl Logo

iam-audit

Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization (RBAC, ABAC, ReBAC), and federated identity. Use when the user mentions 'IAM,' 'identity,' 'access management,' 'least privilege,' 'role design,' 'SSO,' 'SAML,' 'OIDC,' 'OAuth,' 'JIT access,' 'just-in-time access,' 'break-glass,' 'service accounts,' 'RBAC,' 'ABAC,' 'privilege creep,' 'role explosion,' 'identity governance,' 'IAM strategy,' 'identity migration,' 'Okta,' 'Entra ID,' 'Azure AD,' 'Auth0,' 'Cognito,' or needs identity consultant-level guidance.

77

Quality

97%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, highly actionable consultant-grade IAM guide with concrete commands, clear multi-step workflows, and explicit validation/rollback for destructive migration steps. Its only weak spot is progressive disclosure: substantial inline per-provider checklists and external-only references would benefit from being split into one-level-deep bundle files.

Suggestions

Move the per-provider audit checklists (AWS/GCP/Azure) into separate reference files (e.g. references/aws-audit.md, references/gcp-audit.md, references/azure-audit.md) and link to them from the body so the main SKILL.md stays a concise overview.

Convert the 'References' list from external doc titles into actual bundle files under references/ (or clearly mark them as external URLs) so progressive disclosure is one level deep and navigable.

Consider extracting the Common audit findings / Design principles sections into a references/playbook.md to keep the three-mode overview scannable.

DimensionReasoningScore

Conciseness

Dense actionable bullets with no padding or basic-concept explanation; assumes Claude's competence (e.g., lists 'IMDSv2 enforced — MetadataOptions.HttpTokens: required' without explaining IMDS). Every line earns its place, matching the lean anchor-5 example.

5 / 5

Actionability

Provides copy-paste-ready commands per provider ('aws accessanalyzer list-findings', 'gcloud asset analyze-iam-policy', 'az role assignment list --all') and specific config/pattern guidance covering common cases, matching anchor 5.

5 / 5

Workflow Clarity

The 7-step migration playbook and ordered greenfield checklist are clearly sequenced with explicit validation/rollback checkpoints ('No cutover yet', 'each wave has a rollback procedure', 'Audit-trail the cutover'); destructive operations carry validation, so the >3 cap does not apply.

5 / 5

Progressive Disclosure

Well-organized sections (three modes, sub-sections, output format, boundaries), but the body is ~165 lines of inline provider checklists that could be split into one-level-deep reference files, and the References section points to external docs rather than bundle files — good structure with minor organization gaps, matching anchor 4 rather than 5.

4 / 5

Total

19

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it states concrete actions across a clearly scoped IAM domain and pairs them with an explicit, synonym-rich 'Use when' trigger clause. It fully answers both what the skill does and when to invoke it with minimal conflict risk.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('Audit, design, and migrate') plus named sub-domains (AWS/GCP/Azure IAM, Okta/Entra/Auth0 IdPs, RBAC/ABAC/ReBAC app auth, federation) — comprehensive coverage matching the anchor-5 example.

5 / 5

Completeness

Explicitly answers both 'what' (audit/design/migrate IAM across named domains) and 'when' (concrete 'Use when the user mentions...' clause with many trigger phrases), matching anchor 5.

5 / 5

Trigger Term Quality

Extensive natural trigger phrases with synonyms ('JIT access'/'just-in-time access', 'Entra ID'/'Azure AD') and provider names users would actually say, matching the comprehensive-coverage anchor 5.

5 / 5

Distinctiveness Conflict Risk

Clear IAM niche with distinct, specific triggers and minimal overlap risk; provider names and IAM-specific terms keep it from triggering for adjacent skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.