CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-penetration-testing

Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).

38

Quality

37%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

—

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-bundle-security-engineer/skills/cloud-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

42%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is highly actionable with concrete, executable commands across all three major cloud platforms, but it is severely bloated—most commands are standard CLI usage that Claude already knows. The workflow lacks validation checkpoints critical for security testing operations, and the monolithic structure with duplicated quick-reference tables makes poor use of progressive disclosure. The content would benefit enormously from splitting platform-specific details into separate files and adding explicit scope-verification and validation steps between phases.

Suggestions

Split Azure, AWS, and GCP sections into separate referenced files (e.g., azure-testing.md, aws-testing.md, gcp-testing.md) and keep SKILL.md as a concise overview with phase descriptions and cross-references.

Remove the quick reference tables that duplicate commands already shown in the workflow, or move them to a separate cheat-sheet file.

Add explicit validation checkpoints between phases (e.g., 'Verify current scope matches authorization before proceeding to exploitation', 'Confirm enumeration results before attempting privilege escalation').

Cut standard CLI commands Claude already knows (e.g., 'aws configure', 'gcloud auth login') and focus on non-obvious techniques, gotchas, and cloud-specific attack patterns.

DimensionReasoningScore

Conciseness

Extremely verbose at ~400+ lines. Massive amounts of enumeration commands that Claude already knows (standard AWS CLI, gcloud, Az PowerShell commands). The quick reference tables duplicate commands already shown in the workflow sections. The 'Required Knowledge' section lists concepts Claude already understands.

1 / 3

Actionability

Nearly all guidance is concrete, executable commands across all three cloud platforms. Code blocks are copy-paste ready with real CLI commands, PowerShell scripts, and bash one-liners. Specific tools, flags, and output formats are provided.

3 / 3

Workflow Clarity

The 11 phases provide a clear sequence from reconnaissance through persistence, but there are no validation checkpoints between phases. For destructive/risky operations like creating backdoor service principals or extracting secrets, there are no verification steps, error recovery loops, or safety checks to confirm scope boundaries before proceeding.

2 / 3

Progressive Disclosure

Monolithic wall of content with everything inline. The single reference to 'references/advanced-cloud-scripts.md' is not provided in the bundle. The Azure, AWS, and GCP sections could each be separate files with SKILL.md serving as an overview. The quick reference tables at the end duplicate inline content rather than being split into a cheat sheet file.

1 / 3

Total

7

/

12

Passed

Description

32%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies its domain (cloud security) and names the three major cloud providers, which provides some useful specificity. However, it lacks concrete actions beyond the vague 'comprehensive security assessments,' omits a 'Use when...' clause entirely, and misses many natural trigger terms users would employ when requesting cloud security help.

Suggestions

Add a 'Use when...' clause with explicit triggers, e.g., 'Use when the user asks for cloud security audits, infrastructure reviews, compliance checks, or mentions AWS/Azure/GCP security concerns.'

Replace 'comprehensive security assessments' with specific concrete actions, e.g., 'Review IAM policies, audit network configurations, check encryption settings, identify misconfigurations, and evaluate compliance posture.'

Include additional natural trigger terms users might say, such as 'cloud audit', 'security review', 'misconfiguration', 'compliance', 'vulnerability assessment', or 'hardening'.

DimensionReasoningScore

Specificity

Names the domain (cloud infrastructure security) and the three major cloud providers, but 'comprehensive security assessments' is a broad action rather than listing specific concrete actions like 'review IAM policies, audit network configurations, check encryption settings'.

2 / 3

Completeness

Describes what it does (security assessments of cloud infrastructure) but completely lacks a 'Use when...' clause or any explicit trigger guidance for when Claude should select this skill. Per rubric guidelines, a missing 'Use when...' clause caps completeness at 2, and the 'what' is also somewhat vague, warranting a score of 1.

1 / 3

Trigger Term Quality

Includes good cloud provider keywords (Azure, AWS, GCP) and 'security assessments' and 'cloud infrastructure', but misses common user variations like 'cloud security audit', 'vulnerability scan', 'compliance check', 'misconfiguration', 'IAM review', or 'pentest'.

2 / 3

Distinctiveness Conflict Risk

The focus on cloud security across Azure/AWS/GCP provides some distinctiveness, but 'comprehensive security assessments' is broad enough to potentially overlap with general security review skills, compliance skills, or individual cloud-provider-specific skills.

2 / 3

Total

7

/

12

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 9 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (510 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

9

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.