CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-penetration-testing

Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).

48

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/cloud-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-scaffolded for safety and offers concrete, mostly executable examples, but it stops short of a complete working document: the core workflow lives off-page with no validation checkpoints, the second reference file is undiscoverable from the root, and duplicate warnings and filler sections spend tokens without adding guidance.

Suggestions

Surface references/advanced-cloud-scripts.md directly in SKILL.md (e.g., alongside the detailed-guide link) so both bundle files are one level deep and clearly signaled.

Add a brief phase overview in the body (recon → auth testing → enumeration → escalation → reporting) with explicit validation/verification checkpoints — e.g., confirming scope before each phase and verifying findings before reporting — since the current destructive/batch operations lack any validation steps.

Trim the duplicate AUTHORIZED USE ONLY banner, replace the circular "When to Use" sentence with concrete trigger conditions, and drop the Required Knowledge list of concepts Claude already knows.

DimensionReasoningScore

Conciseness

The body is mostly lean command lists, but it carries avoidable padding: the "AUTHORIZED USE ONLY" warning is stated twice (the opening block and again at line 24), the "When to Use" section is circular filler ("This skill is applicable to execute the workflow or actions described in the overview"), and the "Required Knowledge" list ("Cloud architecture fundamentals", "Identity and Access Management (IAM)") tells Claude what it already knows. This fits 'mostly efficient but includes some unnecessary explanation or could be tightened' rather than the trimmer anchor 4.

3 / 5

Actionability

The three examples give concrete, largely executable commands (MSOLSpray invocation, `aws s3 ls`/`sync` loops, `gcloud` enumeration and SSH), and the prerequisites include real install commands. Minor gaps keep it below 5: the FireProx setup is partial, `<key>`/`<secret>`/`<api-gateway>` placeholders are left unresolved, and `pip install scoutsuite pacu` glosses over Pacu's venv-based setup.

4 / 5

Workflow Clarity

The operational assessment sequence (recon, authentication testing, enumeration, escalation, extraction) is delegated entirely to detailed-guide.md rather than summarized in the body, and the body contains no validation or verification steps for operations that are destructive and batch-oriented (e.g., `aws s3 sync s3://... ./loot/`), which caps workflow clarity at 3 per the rubric. It is above anchor 2 because the prerequisites → constraints → examples progression and the pre-execution confirmation gate do provide a defined, if partial, structure.

3 / 5

Progressive Disclosure

Scored against the actual bundle: references/detailed-guide.md is clearly signaled one level deep from the body, but the second bundle file, references/advanced-cloud-scripts.md, is never mentioned in SKILL.md — it is reachable only through a link inside detailed-guide.md, making it a buried second-level reference. Combined with the fully inlined examples section, this matches 'references present but not clearly signaled; content that should be separate is inline' better than anchor 4's 'minor organization gaps'.

3 / 5

Total

13

/

20

Passed

Description

45%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly identifies the domain (offensive/assessment testing across the three major cloud providers) but offers only one generic action verb and no trigger guidance. It would benefit most from an explicit 'Use when...' clause naming natural trigger phrases like penetration testing, pentest, or cloud security audit.

Suggestions

Add an explicit trigger clause, e.g., "Use when the user asks for cloud penetration testing, a cloud security assessment, pentesting of Azure/AWS/GCP environments, or auditing cloud misconfigurations."

Replace the single generic verb with 2-3 concrete actions drawn from the skill's actual coverage, e.g., "enumerate cloud resources, test authentication and IAM policies, identify misconfigured storage, and escalate privileges".

Include natural synonyms users would say ("pentest", "red team", "cloud security audit") so the skill triggers on phrasing beyond the formal "security assessments".

DimensionReasoningScore

Specificity

The description names the domain and all three providers ("cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP)"), but the only action offered is the generic "Conduct comprehensive security assessments" — matching the 'names the domain but actions are minimal or generic' anchor. It is not a 3 because no second concrete action (e.g., enumeration, privilege escalation, misconfiguration auditing) is stated, and not a 1 because the domain is explicitly and concretely named.

2 / 5

Completeness

The 'what' is stated (comprehensive security assessments of cloud infrastructure across three named providers), but there is no 'Use when...' clause or equivalent trigger guidance, which caps completeness at 3 per the rubric guidelines. It is not a 4 because the 'when' is entirely missing rather than merely imprecise.

3 / 5

Trigger Term Quality

"Security assessments" and the three provider names are natural terms a user might say, but common variations users actually use — "penetration testing", "pentest", "red team", "cloud security audit" — are absent. This matches 'some relevant keywords but missing common variations or synonyms' rather than the good-coverage anchor 4.

3 / 5

Distinctiveness Conflict Risk

Naming Azure, AWS, and GCP gives the skill a recognizable niche, but "comprehensive security assessments" is broad enough to overlap with general penetration testing, security audit, and defensive cloud-hardening skills. It sits at 'somewhat specific but could still overlap with similar skills' rather than the 'mostly distinct' anchor 4.

3 / 5

Total

11

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.