CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-penetration-testing

This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with extensive copy-paste-ready AWS commands, but treats a destructive attack workflow without validation checkpoints, capping workflow clarity, and carries some redundancy (Quick Reference restate) and over-explanation that limit conciseness. Progressive disclosure is solid thanks to the well-signaled, confirmed reference file.

Suggestions

Add explicit validation/verification checkpoints to destructive and batch workflows (e.g., after 'aws ec2 create-snapshot' verify the snapshot is available before creating/attaching a volume; after CloudTrail changes verify state) to lift workflow clarity above the destructive-skill cap of 3.

Remove the Quick Reference table or move it into references/advanced-aws-pentesting.md, since every command it lists already appears verbatim in the body — this is pure redundancy consuming tokens.

Trim narrating prose like 'Identify the compromised identity and permissions:' and inline restatements of obvious JSON fields (AccessKeyId/SecretAccessKey) that Claude does not need, to improve conciseness.

DimensionReasoningScore

Conciseness

Mostly efficient with concrete commands, but includes some over-explanation Claude does not need (e.g., 'Identify the compromised identity and permissions:', repeated inline explanations of obvious output fields) and the Quick Reference table largely restates commands already shown in full above.

3 / 5

Actionability

Fully executable, copy-paste-ready AWS CLI commands and a runnable Python Lambda payload cover the common cases; concrete examples span enumeration, SSRF, privilege escalation, S3, and persistence. Placeholders (AKIA..., target_user) are standard and clearly marked.

5 / 5

Workflow Clarity

A rough Core Workflow sequence (Step 1 enumeration -> Step 2 IAM -> Step 3 SSRF) exists, but destructive/batch operations (snapshot & mount EBS, CloudTrail deletion, Lambda code injection) lack explicit validation checkpoints or feedback loops, which the rubric caps at 3.

3 / 5

Progressive Disclosure

Good structure with clearly signaled one-level-deep reference to the confirmed-present references/advanced-aws-pentesting.md for bulk advanced material, keeping the body an overview; minor gaps such as the inlined Quick Reference and several techniques that could be split out.

4 / 5

Total

15

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-structured description that clearly states the skill's purpose and provides an explicit trigger clause with a comprehensive list of natural phrases. Minor specificity gaps (no persistence/exfiltration terms) keep it just below the top of the specificity anchor.

DimensionReasoningScore

Specificity

Lists several concrete actions ('pentest AWS', 'enumerate IAM', 'exploit cloud infrastructure', 'AWS privilege escalation', 'S3 bucket testing', 'metadata SSRF', 'Lambda exploitation') with only minor coverage gaps (e.g., no mention of persistence/exfiltration).

4 / 5

Completeness

Explicitly answers both 'what' ('Provide comprehensive techniques for penetration testing AWS cloud environments') and 'when' via an explicit 'This skill should be used when the user asks to...' trigger clause with concrete phrases.

5 / 5

Trigger Term Quality

Comprehensive natural trigger phrases users would actually say ('pentest AWS', 'test AWS security', 'enumerate IAM', 'S3 bucket testing', 'Lambda exploitation') including synonyms and shorthand ('pentest').

5 / 5

Distinctiveness Conflict Risk

Clear niche (AWS security assessment) with distinct, AWS-specific triggers (IAM enumeration, S3, Lambda, metadata SSRF) that minimize overlap with other cloud or general pentest skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.