Content
68%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a dense, largely copy-paste-ready command reference with good file-level organization and a properly signaled reference file. Its weaknesses are the truncated core workflow — three steps then an unsequenced technique catalog — and the absence of validation checkpoints around destructive operations (CloudTrail deletion, policy attachment, EBS snapshotting), which caps workflow clarity at 3.
Suggestions
Add explicit validation checkpoints after destructive or high-impact operations (e.g., verify escalation succeeded with `aws sts get-caller-identity` / `aws iam get-user` before proceeding, and verify command results after `aws ssm send-command`), which would lift the workflow-clarity cap.
Extend the numbered Core Workflow past Step 3 so privilege escalation, S3, and persistence techniques follow a sequence rather than appearing as an unsequenced catalog.
Convert the bare metadata URLs in Step 3 into executable curl commands and replace the comment-only Shadow Copy Attack block with runnable commands, matching the executability of the rest of the body.
Move secondary sections (Console Access from API Keys, SSM Command Execution, Covering Tracks) into references/advanced-aws-pentesting.md to shorten the SKILL.md overview.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is mostly lean command tables and code blocks that assume competence, e.g. "aws sts get-caller-identity", "aws iam list-users", with no padding explaining AWS concepts. Minor trimmable redundancy: the Purpose section restates the description, "AWS CLI configured with credentials" and "Valid AWS credentials" duplicate each other, and the Quick Reference table repeats commands already shown. Not anchor 5 because of these redundancies; clearly above anchor 3's 'some unnecessary explanation'. | 4 / 5 |
Actionability | Mostly concrete, executable commands ("aws iam create-access-key --user-name target_user", "aws ssm send-command ...", a complete boto3 Lambda handler). Below anchor 5 because of minor gaps: the Step 3 metadata section lists bare URLs in bash blocks instead of curl commands, and the Shadow Copy Attack section is comment-only pseudocode ("# 1. Create snapshot of DC volume...") rather than executable steps. | 4 / 5 |
Workflow Clarity | A rough sequence exists (Step 1 Initial Enumeration → Step 2 IAM Enumeration → Step 3 Metadata SSRF), but the workflow stops at step 3 and the remaining sections (privilege escalation, S3, EBS, covering tracks) become an unsequenced technique catalog. Validation checkpoints are largely absent — the destructive workflows ("aws cloudtrail delete-trail", snapshot-and-attach EBS, "attach-user-policy") have no verify step, which caps this dimension at 3 per the destructive-operations rule. | 3 / 5 |
Progressive Disclosure | Good structure with clear section headers, a quick-reference table, and a well-signaled, verified, one-level-deep reference: the closing section explicitly enumerates the reference file's contents before linking [references/advanced-aws-pentesting.md](references/advanced-aws-pentesting.md), and the file exists in the bundle. Below anchor 5 because the ~400-line body still inlines several secondary topics (Console Access, SSM, EBS mounting, Covering Tracks) that would fit naturally in the reference file alongside the advanced material. | 4 / 5 |
Total | 15 / 20 Passed |