CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-security-audit

Comprehensive AWS security posture assessment using AWS CLI and security best practices

43

1.12x
Quality

18%

Does it follow best practices?

Impact

82%

1.12x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/security/aws-security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

14%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill reads more like a comprehensive reference document or blog post than an actionable skill for Claude. While it contains useful AWS CLI commands, it suffers from excessive verbosity, lack of workflow structure, incomplete code (the Python script), and a monolithic format that dumps everything into one file. The compliance mapping, example prompts, and best practices sections add little value for Claude and consume significant token budget.

Suggestions

Add a clear sequential workflow (e.g., 1. Generate credential report, 2. Run IAM checks, 3. Run network checks, 4. Compile findings, 5. Prioritize remediation) with explicit validation checkpoints between steps.

Remove or drastically condense the audit categories list, compliance mapping, example prompts, and best practices sections — these are things Claude already knows and they consume tokens without adding actionable value.

Split the content: keep a concise overview with the workflow in SKILL.md, and move the command reference catalog and scripts into separate bundle files (e.g., COMMANDS.md, scripts/audit.sh, scripts/security-score.py).

Fix the Python security score calculator to be fully executable — complete the credential report parsing logic and replace the bare `except: pass` with proper error handling.

DimensionReasoningScore

Conciseness

The skill is extremely verbose at ~300+ lines. It includes extensive lists of audit categories that merely describe what to check (which Claude already knows), a compliance mapping section that's just a list of standards, generic best practices, example prompts, and a Python security score calculator with incomplete logic (bare except, placeholder comment). Much of this could be cut or condensed significantly.

1 / 3

Actionability

The bash commands are mostly executable and copy-paste ready, which is good. However, the Python security score calculator is incomplete (the credential report parsing is stubbed out with a comment), the automated audit script hardcodes a trail name ('my-trail'), and the overly permissive policies check only looks for a policy literally named 'AdministratorAccess' which misses the actual concern of overly broad inline policies. Several commands would need modification to work in practice.

2 / 3

Workflow Clarity

There is no clear workflow sequence for conducting an audit. The content is organized as a reference catalog of individual commands grouped by category, but there's no step-by-step process, no validation checkpoints, no guidance on what to do when issues are found (beyond a static priority list), and no feedback loops. For a security audit involving potentially destructive remediation actions, this lack of workflow structure is a significant gap.

1 / 3

Progressive Disclosure

The content is a monolithic wall of text with everything inline — individual commands, a full audit script, a full Python script, compliance mappings, remediation priorities, best practices, and example prompts all in one file. There are no bundle files to reference, and the content would benefit enormously from splitting the command reference, scripts, and compliance mappings into separate files with clear navigation from a concise overview.

1 / 3

Total

5

/

12

Passed

Description

22%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is too vague and high-level, reading more like a tagline than a functional skill description. It lacks concrete actions, specific trigger terms, and any 'Use when...' guidance, making it difficult for Claude to reliably select this skill from a pool of alternatives.

Suggestions

List specific concrete actions the skill performs, e.g., 'Audits IAM policies, checks S3 bucket permissions, reviews security group rules, evaluates CloudTrail logging configuration, and assesses encryption settings.'

Add an explicit 'Use when...' clause with natural trigger terms, e.g., 'Use when the user asks about AWS security audits, cloud security review, IAM permissions check, compliance assessment, or hardening AWS infrastructure.'

Include specific AWS service names and file/resource types to improve distinctiveness, e.g., 'IAM, S3, EC2 security groups, CloudTrail, KMS, VPC configurations.'

DimensionReasoningScore

Specificity

The description uses vague language like 'comprehensive assessment' and 'security best practices' without listing any concrete actions. It doesn't specify what the skill actually does (e.g., check IAM policies, audit S3 bucket permissions, review security groups).

1 / 3

Completeness

The 'what' is vaguely stated as 'security posture assessment' without specifics, and there is no 'when' clause or explicit trigger guidance at all. The missing 'Use when...' clause caps this at 2 per the rubric, but the weak 'what' brings it to 1.

1 / 3

Trigger Term Quality

It includes some relevant keywords like 'AWS', 'security', and 'AWS CLI' that users might naturally mention, but misses common variations and specific terms like 'IAM', 'S3 permissions', 'security groups', 'compliance', 'audit', or 'vulnerability'.

2 / 3

Distinctiveness Conflict Risk

The mention of 'AWS' and 'AWS CLI' provides some specificity, but 'security posture assessment' is broad enough to overlap with other AWS-related skills or general security auditing skills.

2 / 3

Total

6

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.