CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-penetration-testing

This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.

73

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

80%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable and token-efficient, packed with executable commands and minimal fluff. Its main weaknesses are the absence of validation checkpoints in destructive/batch workflows and a large main file that could offload more detail to the bundled reference.

Suggestions

Add explicit validation/verification steps (e.g., confirm enumerated permissions before escalating, verify snapshot availability before attaching) to the Core Workflow and destructive sections to lift workflow clarity.

Move detailed per-technique sections such as Privilege Escalation, S3 Exploitation, and EC2 Exploitation into the references file, keeping SKILL.md a concise overview with clearly signaled links.

Add a short verification step after 'Covering Tracks' operations to confirm the intended state was achieved rather than only issuing destructive commands.

DimensionReasoningScore

Conciseness

The body is a dense, lean reference of copy-paste commands with minimal prose and no padding about concepts Claude already knows; nearly every line earns its place.

3 / 3

Actionability

It provides fully executable AWS CLI commands, a working Python snippet, and concrete curl examples that are copy-paste ready with specific values and flags.

3 / 3

Workflow Clarity

A labeled Core Workflow with Steps 1-3 and ordered sections exists, but validation/verification checkpoints between destructive and batch operations (e.g., enumeration results, EBS snapshot attacks, covering tracks) are missing or implicit, capping it at 2.

2 / 3

Progressive Disclosure

There is one well-signaled, one-level-deep reference to a real file (references/advanced-aws-pentesting.md) with no nesting, but the ~400-line SKILL.md keeps substantial detailed reference material inline that could be split out.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, and clearly answers both what the skill does and when to use it, with explicit trigger guidance and a distinct niche. It is one of the stronger skill descriptions.

DimensionReasoningScore

Specificity

The description enumerates concrete actions via trigger phrases such as 'enumerate IAM', 'AWS privilege escalation', 'S3 bucket testing', 'metadata SSRF', and 'Lambda exploitation', naming several specific capabilities rather than vague language.

3 / 3

Completeness

It answers both 'what' (guidance on Amazon Web Services security assessment, plus the enumerated actions) and 'when' via the explicit 'This skill should be used when the user asks to...' clause.

3 / 3

Trigger Term Quality

Phrases like 'pentest AWS', 'test AWS security', 'S3 bucket testing', and 'AWS privilege escalation' are natural terms a user would actually say, with broad coverage of common variations.

3 / 3

Distinctiveness Conflict Risk

The AWS-penetration-testing niche is clearly defined by distinct, specific triggers unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.