CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-penetration-testing

This skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.

58

Quality

67%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/cloud-penetration-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exceptionally actionable command reference with a coherent phase-based workflow, but it is a near-monolithic 500-line SKILL.md: duplicated quick-reference tables, no validation checkpoints in a workflow full of destructive operations, and only a single reference file. Splitting per-platform content out and adding verification steps would address the main gaps.

Suggestions

Split each platform's phases into reference files (e.g. references/azure.md, references/aws.md, references/gcp.md) with a short SKILL.md overview and workflow, turning the single end-of-file reference into well-signaled navigation — this also removes the need for the duplicate Quick Reference tables.

Add validation checkpoints after each destructive or batch step, e.g. confirm a backdoor key works with 'aws sts get-caller-identity' before moving on, and verify service-principal role grants with 'Get-AzRoleAssignment' before relying on persistence.

Delete or merge the Quick Reference tables (they restate commands already shown verbatim in the phases) and keep the tool list and troubleshooting table, which carry genuinely new information.

DimensionReasoningScore

Conciseness

The body is command-dense with almost no explanatory padding, but the 'Quick Reference' tables (Azure/AWS/GCP Key Commands, Metadata Service URLs) largely restate commands already shown in the phases, adding roughly 60 lines of redundant tokens. Mostly efficient but with a clear tightenable duplication, matching anchor 3.

3 / 5

Actionability

Nearly every section is copy-paste-ready CLI/PowerShell/bash with concrete flags, queries, and three fully worked examples (Azure password spray, S3 enumeration, GCP service-account pivot). Specific and executable throughout, matching the fully-executable anchor.

5 / 5

Workflow Clarity

The 11 phases give a clear, coherent sequence from reconnaissance through persistence, but there are no validation checkpoints anywhere (e.g. verifying role assignments after privilege escalation, confirming key validity after backdoor creation). Per the rubric's explicit cap, a workflow involving destructive/batch operations (backdoor service principals, access-key creation, password spraying) without validation cannot score above 3.

3 / 5

Progressive Disclosure

Section structure is clear and the single reference (references/advanced-cloud-scripts.md) is real, one level deep, and well-signaled — but it appears only at the very end, and ~490 lines are inlined where per-platform content (e.g. the per-cloud phases or quick-reference tables) clearly belongs in separate reference files. This matches anchor 3: structure present but content that should be separate is inline.

3 / 5

Total

14

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an excellent, explicit trigger clause with natural multi-platform phrasing, but the capability statement is padded and vague ('comprehensive techniques'). Tightening the 'what' into concrete capabilities would make it fully strong.

Suggestions

Replace 'It provides comprehensive techniques for security assessment across major cloud platforms' with the concrete capabilities the body actually covers, e.g. 'Reconnaissance, authentication testing, resource enumeration, privilege escalation, secret extraction, and persistence across Azure, AWS, and GCP.'

Add a few natural trigger variations users actually say, such as 'pentest our cloud', 'cloud security review', or platform-only requests like 'assess our AWS account', to broaden keyword coverage.

Trim the filler phrase 'This skill should be used' and the hedge 'comprehensive' — a leaner form like 'Use when the user asks to perform cloud penetration testing, audit cloud infrastructure, ...' preserves all triggers in fewer tokens.

DimensionReasoningScore

Specificity

The 'what' statement is generic ('It provides comprehensive techniques for security assessment across major cloud platforms'), naming the domain but describing capabilities only abstractly; the concrete actions (enumerate cloud resources, exploit cloud misconfigurations, extract secrets from cloud environments) appear solely inside trigger quotes rather than as a capability description. This sits between anchor 2 (domain named, minimal actions) and anchor 3, but the enumerated action phrases in the triggers lift it to 3.

3 / 5

Completeness

Both parts are present: an explicit 'when' ('This skill should be used when the user asks to...') with concrete trigger phrases, and a 'what' ('provides comprehensive techniques for security assessment'). Not anchor 5 because the 'what' is vague ('comprehensive techniques') rather than listing concrete capabilities; clearly above anchor 3 because the 'when' is explicit and trigger-rich.

4 / 5

Trigger Term Quality

Quotes natural user phrases such as 'perform cloud penetration testing', 'enumerate cloud resources', 'test O365 security', and 'audit cloud infrastructure' with good synonym coverage across platforms. It misses a few common variations (e.g. 'pentest the cloud', 'cloud security review', platform-name-only requests like 'check our AWS'), so it does not reach comprehensive anchor 5.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear niche — multi-cloud penetration testing across Azure, AWS, GCP, and O365 — with triggers unlikely to fire for unrelated skills. Minor overlap risk remains with a generic 'penetration-testing' skill or single-platform security-audit skills, which keeps it below the minimal-conflict anchor 5.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (502 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.