CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-secrets-rotation

Automate AWS secrets rotation for RDS, API keys, and credentials

41

Quality

41%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-awesome-skills-claude/skills/security/aws-secrets-rotation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

42%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill provides highly actionable, executable code examples covering a broad range of AWS Secrets Manager operations, which is its primary strength. However, it is excessively verbose — much of the content (SDK usage patterns, basic secret CRUD operations, best practices checklists) is standard AWS knowledge that Claude already possesses. The monolithic structure with no bundle files or progressive disclosure makes it a poor fit for the SKILL.md format.

Suggestions

Reduce content by 60-70% by removing standard AWS SDK usage examples, basic CRUD operations, and generic best practices checklists that Claude already knows — focus only on the rotation-specific Lambda patterns and workflow.

Split the Lambda rotation functions, audit scripts, and compliance report into separate bundle files (e.g., `lambda_rotation.py`, `audit-rotations.sh`, `compliance-report.py`) and reference them from the main SKILL.md.

Add a clear end-to-end numbered workflow for setting up rotation from scratch, including IAM permission setup, Lambda deployment, enabling rotation, and verification steps with explicit checkpoints.

Remove the 'Example Prompts' and 'Kiro CLI Integration' sections which add no actionable value to the skill content.

DimensionReasoningScore

Conciseness

The skill is extremely verbose at ~350+ lines, covering secret creation, retrieval, rotation Lambda functions, monitoring, application integration in two languages, compliance tracking, best practices checklists, and more. Much of this is standard AWS documentation that Claude already knows. The Node.js and Python SDK retrieval examples, best practices checklists, and compliance report script add significant bulk without being specific to a unique workflow.

1 / 3

Actionability

The skill provides fully executable CLI commands, complete Python Lambda functions, bash audit scripts, and SDK integration code. All examples are copy-paste ready with specific AWS CLI flags, proper JSON structures, and real service endpoints.

3 / 3

Workflow Clarity

The Lambda rotation function follows the four-step AWS rotation protocol (createSecret, setSecret, testSecret, finishSecret) which provides implicit validation via the testSecret step. However, the overall workflow for setting up rotation end-to-end lacks explicit sequencing with validation checkpoints — steps like creating the Lambda, setting IAM permissions, enabling rotation, and verifying it works are scattered rather than presented as a clear sequential workflow with feedback loops.

2 / 3

Progressive Disclosure

All content is inlined in a single monolithic file with no references to supporting files. The application integration examples, compliance report script, audit script, and rotation Lambda functions could all be separate referenced files. The document is a wall of code blocks that would benefit significantly from being split into focused sub-documents.

1 / 3

Total

7

/

12

Passed

Description

40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a clear and distinct domain (AWS secrets rotation) with some specific targets, giving it good distinctiveness. However, it lacks a 'Use when...' clause, which significantly hurts completeness, and the actions described are limited to the single verb 'automate' without detailing specific sub-tasks or workflows.

Suggestions

Add an explicit 'Use when...' clause, e.g., 'Use when the user asks about rotating secrets in AWS Secrets Manager, setting up rotation schedules, or managing RDS passwords and API key lifecycles.'

Expand the concrete actions listed, e.g., 'Creates rotation Lambda functions, configures rotation schedules in AWS Secrets Manager, updates RDS database credentials, and manages API key rotation policies.'

Include additional natural trigger terms such as 'Secrets Manager', 'rotate password', 'Lambda rotation', and 'secret lifecycle management'.

DimensionReasoningScore

Specificity

Names the domain (AWS secrets rotation) and lists some specific targets (RDS, API keys, credentials), but doesn't describe concrete actions beyond 'automate rotation' — e.g., it doesn't mention creating rotation lambdas, configuring schedules, updating Secrets Manager policies, etc.

2 / 3

Completeness

Describes what the skill does (automate AWS secrets rotation) but completely lacks a 'Use when...' clause or any explicit trigger guidance for when Claude should select this skill. Per the rubric, a missing 'Use when...' clause caps completeness at 2, and since the 'what' is also only moderately detailed, this scores a 1.

1 / 3

Trigger Term Quality

Includes relevant keywords like 'AWS', 'secrets rotation', 'RDS', 'API keys', and 'credentials', which are natural terms users might use. However, it misses common variations like 'Secrets Manager', 'rotate password', 'secret lifecycle', 'Lambda rotation function', or 'IAM credentials'.

2 / 3

Distinctiveness Conflict Risk

The combination of 'AWS secrets rotation' with 'RDS, API keys, and credentials' is a clear, narrow niche that is unlikely to conflict with other skills. It targets a very specific operational domain.

3 / 3

Total

8

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.