Content
14%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This skill reads more like a comprehensive reference document or blog post than an actionable skill for Claude. While it contains useful AWS CLI commands, it suffers from excessive verbosity, lack of workflow structure, incomplete code (the Python script), and a monolithic format that dumps everything into one file. The compliance mapping, example prompts, and best practices sections add little value for Claude and consume significant token budget.
Suggestions
Add a clear sequential workflow (e.g., 1. Generate credential report, 2. Run IAM checks, 3. Run network checks, 4. Compile findings, 5. Prioritize remediation) with explicit validation checkpoints between steps.
Remove or drastically condense the audit categories list, compliance mapping, example prompts, and best practices sections — these are things Claude already knows and they consume tokens without adding actionable value.
Split the content: keep a concise overview with the workflow in SKILL.md, and move the command reference catalog and scripts into separate bundle files (e.g., COMMANDS.md, scripts/audit.sh, scripts/security-score.py).
Fix the Python security score calculator to be fully executable — complete the credential report parsing logic and replace the bare `except: pass` with proper error handling.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The skill is extremely verbose at ~300+ lines. It includes extensive lists of audit categories that merely describe what to check (which Claude already knows), a compliance mapping section that's just a list of standards, generic best practices, example prompts, and a Python security score calculator with incomplete logic (bare except, placeholder comment). Much of this could be cut or condensed significantly. | 1 / 3 |
Actionability | The bash commands are mostly executable and copy-paste ready, which is good. However, the Python security score calculator is incomplete (the credential report parsing is stubbed out with a comment), the automated audit script hardcodes a trail name ('my-trail'), and the overly permissive policies check only looks for a policy literally named 'AdministratorAccess' which misses the actual concern of overly broad inline policies. Several commands would need modification to work in practice. | 2 / 3 |
Workflow Clarity | There is no clear workflow sequence for conducting an audit. The content is organized as a reference catalog of individual commands grouped by category, but there's no step-by-step process, no validation checkpoints, no guidance on what to do when issues are found (beyond a static priority list), and no feedback loops. For a security audit involving potentially destructive remediation actions, this lack of workflow structure is a significant gap. | 1 / 3 |
Progressive Disclosure | The content is a monolithic wall of text with everything inline — individual commands, a full audit script, a full Python script, compliance mappings, remediation priorities, best practices, and example prompts all in one file. There are no bundle files to reference, and the content would benefit enormously from splitting the command reference, scripts, and compliance mappings into separate files with clear navigation from a concise overview. | 1 / 3 |
Total | 5 / 12 Passed |