CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-penetration-testing

Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).

50

Quality

55%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/cloud-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is actionable and well-structured with a strong authorization gate and concrete per-cloud examples, but it leans on generic conceptual padding and its offensive workflows lack validation checkpoints. An unreferenced bundle file also leaves the progressive-disclosure structure partially unexposed.

Suggestions

Add explicit validation/verification steps to each offensive workflow (e.g., confirm scope per command, verify enumerated findings before acting, validate that an S3 bucket is in-scope before syncing), with fix-and-retry loops so workflow clarity can exceed 3.

Trim or relocate generic conceptual content ('Required Knowledge' items like IAM and API authentication fundamentals) that Claude already knows, and consolidate the duplicate AUTHORIZED USE banners into a single gate.

Reference advanced-cloud-scripts.md from the body (e.g., a '## Advanced scripts' section linking to it) so both bundle files are discoverable, completing the progressive-disclosure structure.

DimensionReasoningScore

Conciseness

Examples and prerequisites are reasonably tight, but the 'Required Knowledge' and 'Constraints/Limitations' sections restate concepts Claude already knows, and the AUTHORIZED USE banner is duplicated.

3 / 5

Actionability

All three worked examples provide concrete, mostly copy-paste-ready commands (MSOLSpray/FireProx, aws s3 enumeration, gcloud service-account pivot) with only minor placeholder gaps.

4 / 5

Workflow Clarity

Because this is an offensive skill with batch/destructive operations and the example workflows contain no validation or fix-retry checkpoints, workflow clarity is capped at 3 per the rubric's feedback-loop rule.

3 / 5

Progressive Disclosure

The detailed-guide.md reference is clearly signaled and one level deep, but the bundle file advanced-cloud-scripts.md exists yet is never referenced or navigated from the body, leaving the disclosure structure incomplete.

3 / 5

Total

13

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly identifies a distinct cloud-penetration-testing niche across Azure, AWS, and GCP, but it is light on concrete actions and entirely lacks an explicit 'when to use' trigger clause. Adding specific capabilities and a Use-when clause would lift it from adequate to strong.

Suggestions

Add a 'Use when...' clause naming concrete trigger phrases (e.g., 'Use when performing authorized cloud penetration tests, privilege escalation, or misconfiguration enumeration across Azure, AWS, or GCP').

Replace the single generic verb 'Conduct comprehensive security assessments' with several concrete actions (e.g., enumerate cloud resources, test IAM and credential hygiene, identify misconfigured storage).

Include common synonyms such as 'pentest' and 'penetration testing' alongside 'security assessments' to improve natural trigger-term coverage.

DimensionReasoningScore

Specificity

The description names the domain (cloud infrastructure security) and the three target providers (Azure, AWS, GCP), but offers only one generic action ('Conduct comprehensive security assessments') rather than several concrete actions.

3 / 5

Completeness

It gives a clear 'what' but no 'Use when...' clause or equivalent explicit trigger guidance, so completeness is capped at 3 per the rubric guidelines.

3 / 5

Trigger Term Quality

Relevant keywords like 'security assessments', 'cloud infrastructure', 'Azure', 'AWS', and 'GCP' are present, but common natural synonyms such as 'pentest', 'penetration testing', and 'cloud security' are missing.

3 / 5

Distinctiveness Conflict Risk

The cloud-penetration-testing niche across the three named providers is mostly distinct, with only minor overlap risk against generic cloud-security skills.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.