CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-penetration-testing

Provide comprehensive techniques for penetration testing AWS cloud environments. Covers IAM enumeration, privilege escalation, SSRF to metadata endpoint, S3 bucket exploitation, Lambda code extraction, and persistence techniques for red team operations.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/aws-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, command-dense reference that is mostly executable and well sectioned, with a real one-level-deep reference file for advanced material. Its weaknesses are redundancy (repeated warnings, duplicated quick-reference table, filler sections) and a workflow that lacks validation checkpoints despite covering destructive operations.

Suggestions

Add explicit validation checkpoints after each destructive step (e.g. verify snapshot creation before attaching a volume, confirm credential validity with 'aws sts get-caller-identity' before escalation attempts) to lift workflow clarity past the destructive-operation cap.

Trim redundancy: collapse the three AUTHORIZED USE ONLY blockquotes into one, drop the Quick Reference table that duplicates earlier commands, and replace the filler 'When to Use' sentence with genuine trigger guidance.

Make the inlined examples fully executable: provide the admin-policy.json document used by 'aws iam put-user-policy', show bucket_finder installation, and turn the bare metadata URLs in Step 3 into curl commands.

DimensionReasoningScore

Conciseness

The body is command-dense with minimal conceptual padding — tables and code blocks dominate, e.g. the Shadow Admin permissions table and the IMDSv2 token snippet. Minor trimmable redundancy remains: the Purpose section repeats the description verbatim, the Quick Reference table re-lists commands already shown, and there are three separate AUTHORIZED USE ONLY blockquotes plus a filler 'When to Use' sentence. It fits the 4 anchor ('efficient; minor instances that could be trimmed') rather than 5, where every token would earn its place.

4 / 5

Actionability

Most guidance is copy-paste ready — concrete aws CLI invocations ('aws iam create-access-key --user-name target_user'), a working IMDSv2 curl token flow, and a complete boto3 Lambda handler. It falls short of the 5 anchor because of small gaps: the Step 3 metadata URLs are bare URLs with no curl command, the referenced admin-policy.json content is never provided, and bucket_finder installation is omitted. It is well above the 3 anchor since almost everything shown is executable rather than pseudocode.

4 / 5

Workflow Clarity

A rough sequence exists (Core Workflow Steps 1-3, then technique catalogs) with an upfront confirmation gate and a Troubleshooting table for error recovery, but the workflow dissolves into an unsequenced technique catalog after Step 3. Because the operations are destructive (deleting CloudTrail trails, snapshotting volumes, persistence) and there are no validate-after-step checkpoints or fix-and-retry loops, workflow clarity is capped at 3 per the rubric guideline.

3 / 5

Progressive Disclosure

The single bundle file references/advanced-aws-pentesting.md exists, is one level deep (own TOC, no nested references), and is clearly signaled under 'Additional Resources' with an accurate summary of its contents. Structure is good with consistent section headers, matching the 4 anchor. It is not a 5 because the ~420-line main file inlines several catalogs (SSM, EC2, console access) that could be split out, and only one reference file exists.

4 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description that names six concrete AWS attack technique areas with strong domain keywords and near-zero conflict risk. Its main weakness is the complete absence of a 'when to use' trigger clause, which caps completeness and leaves triggering to inference.

Suggestions

Append an explicit trigger clause such as 'Use when the user asks about AWS penetration testing, cloud security assessment, pentesting AWS environments, or red team operations in AWS.'

Add natural synonyms users would say, e.g. 'pentest', 'ethical hacking', or 'cloud security audit', to broaden trigger coverage beyond the technical jargon.

State the defensive/audit applicability (e.g. 'also useful for validating AWS IAM misconfigurations during security audits') to distinguish it from generic offense-only tooling.

DimensionReasoningScore

Specificity

The description lists multiple concrete technique areas — 'IAM enumeration, privilege escalation, SSRF to metadata endpoint, S3 bucket exploitation, Lambda code extraction, and persistence techniques' — giving comprehensive coverage of the domain. It fits the anchor 'lists multiple specific concrete actions; comprehensive coverage' rather than the level-4 anchor, which expects minor gaps in coverage.

5 / 5

Completeness

It clearly answers 'what' (the enumerated AWS attack techniques) but contains no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. It is not a 2 because the 'what' is specific and detailed, and not a 4 because the 'when' is entirely missing rather than weakly implied.

3 / 5

Trigger Term Quality

Terms like 'penetration testing AWS', 'privilege escalation', 'SSRF', 'S3', and 'red team' are phrases practitioners would naturally say, giving good keyword coverage. It falls between the 3 anchor (missing common variations) and 5 anchor (comprehensive synonyms/extensions) because natural variants like 'pentest', 'cloud security assessment', or 'ethical hacking' are absent — noticeably above the midpoint but short of full coverage.

4 / 5

Distinctiveness Conflict Risk

The AWS-specific penetration-testing niche ('IAM enumeration', 'SSRF to metadata endpoint', 'Lambda code extraction') is clearly distinct with minimal overlap risk against generic cloud or security skills. It matches the anchor 'clear niche with distinct triggers; minimal conflict risk' and not the 4 anchor, which expects some overlap with closely related skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.