CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-penetration-testing

This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.

61

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/aws-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a dense, largely copy-paste-ready command reference with good file-level organization and a properly signaled reference file. Its weaknesses are the truncated core workflow — three steps then an unsequenced technique catalog — and the absence of validation checkpoints around destructive operations (CloudTrail deletion, policy attachment, EBS snapshotting), which caps workflow clarity at 3.

Suggestions

Add explicit validation checkpoints after destructive or high-impact operations (e.g., verify escalation succeeded with `aws sts get-caller-identity` / `aws iam get-user` before proceeding, and verify command results after `aws ssm send-command`), which would lift the workflow-clarity cap.

Extend the numbered Core Workflow past Step 3 so privilege escalation, S3, and persistence techniques follow a sequence rather than appearing as an unsequenced catalog.

Convert the bare metadata URLs in Step 3 into executable curl commands and replace the comment-only Shadow Copy Attack block with runnable commands, matching the executability of the rest of the body.

Move secondary sections (Console Access from API Keys, SSM Command Execution, Covering Tracks) into references/advanced-aws-pentesting.md to shorten the SKILL.md overview.

DimensionReasoningScore

Conciseness

The body is mostly lean command tables and code blocks that assume competence, e.g. "aws sts get-caller-identity", "aws iam list-users", with no padding explaining AWS concepts. Minor trimmable redundancy: the Purpose section restates the description, "AWS CLI configured with credentials" and "Valid AWS credentials" duplicate each other, and the Quick Reference table repeats commands already shown. Not anchor 5 because of these redundancies; clearly above anchor 3's 'some unnecessary explanation'.

4 / 5

Actionability

Mostly concrete, executable commands ("aws iam create-access-key --user-name target_user", "aws ssm send-command ...", a complete boto3 Lambda handler). Below anchor 5 because of minor gaps: the Step 3 metadata section lists bare URLs in bash blocks instead of curl commands, and the Shadow Copy Attack section is comment-only pseudocode ("# 1. Create snapshot of DC volume...") rather than executable steps.

4 / 5

Workflow Clarity

A rough sequence exists (Step 1 Initial Enumeration → Step 2 IAM Enumeration → Step 3 Metadata SSRF), but the workflow stops at step 3 and the remaining sections (privilege escalation, S3, EBS, covering tracks) become an unsequenced technique catalog. Validation checkpoints are largely absent — the destructive workflows ("aws cloudtrail delete-trail", snapshot-and-attach EBS, "attach-user-policy") have no verify step, which caps this dimension at 3 per the destructive-operations rule.

3 / 5

Progressive Disclosure

Good structure with clear section headers, a quick-reference table, and a well-signaled, verified, one-level-deep reference: the closing section explicitly enumerates the reference file's contents before linking [references/advanced-aws-pentesting.md](references/advanced-aws-pentesting.md), and the file exists in the bundle. Below anchor 5 because the ~400-line body still inlines several secondary topics (Console Access, SSM, EBS mounting, Covering Tracks) that would fit naturally in the reference file alongside the advanced material.

4 / 5

Total

15

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has excellent trigger-term coverage and a clear niche, with an explicit 'use when' clause. Its main weakness is that the 'what' is left vague ("guidance on... security assessment") — capabilities are only implied through the quoted user phrases rather than stated in third person as skill functions.

Suggestions

State the skill's capabilities directly in third person (e.g., "Provides techniques for IAM enumeration, privilege escalation, S3 bucket exploitation, metadata SSRF, and Lambda code extraction") rather than relying on the vague "needs guidance on Amazon Web Services security assessment".

Add a few missing natural synonyms such as "AWS security audit", "red team AWS", or "cloud pentest" to broaden trigger coverage.

Drop or tighten the generic "exploit cloud infrastructure" phrase, which is the only term with meaningful overlap risk against non-AWS cloud skills.

DimensionReasoningScore

Specificity

The description names concrete domain actions only as quoted user phrases ("enumerate IAM", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation"), while the actual 'what' is the vague "needs guidance on Amazon Web Services security assessment". It is above anchor 2 (domain named, minimal actions) because several specific techniques are enumerated, but below anchor 4 because the skill's own capabilities are never stated — only what the user might say.

3 / 5

Completeness

The 'when' is explicit and strong ("This skill should be used when the user asks to...") and a 'what' is present ("needs guidance on Amazon Web Services security assessment"), satisfying anchor 4. Not anchor 5 because the 'what' clause is generic — the concrete capabilities are only implied via the quoted trigger list rather than stated directly.

4 / 5

Trigger Term Quality

Strong natural trigger phrases users would actually say: "pentest AWS", "test AWS security", "enumerate IAM", "S3 bucket testing", "Lambda exploitation". Below anchor 5 because common synonyms like "AWS security audit", "red team AWS", or "cloud pentest" are missing, and "exploit cloud infrastructure" is generic.

4 / 5

Distinctiveness Conflict Risk

Clear niche (AWS penetration testing) with distinct, domain-specific triggers ("pentest AWS", "metadata SSRF", "S3 bucket testing"). Minimal conflict risk with other skills; only "exploit cloud infrastructure" is mildly broad, but it is anchored in an AWS context.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.