CtrlK
BlogDocsLog inGet started
Tessl Logo

k8s-security-policies

Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use when securing Kubernetes clusters, implementing network isolation, or enforcing pod security standards.

83

1.21x
Quality

76%

Does it follow best practices?

Impact

95%

1.21x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./tests/ext_conformance/artifacts/agents-wshobson/kubernetes-operations/skills/k8s-security-policies/SKILL.md

The canonical home for this skill is k8s-security-policies in wshobson/agents

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body excels at actionability with complete, executable YAML and kubectl examples across all major Kubernetes security mechanisms. It is weakened by catalog-style organization with no implementation workflow, generic compliance/best-practice padding, and a broken bundle reference ('assets/pod-security-template.yaml').

Suggestions

Add an ordered implementation workflow with validation checkpoints (e.g., 1. apply Pod Security Standards labels, 2. apply default-deny NetworkPolicy, 3. add allow rules, 4. verify with 'kubectl auth can-i' and connectivity tests) so users get a sequenced rollout path rather than a topic catalog.

Fix the broken reference: either create 'assets/pod-security-template.yaml' or remove it from the Reference Files section, since the pod security content currently lives inline in the body.

Trim the 'Purpose', 'Compliance Frameworks', and 'Best Practices' sections (or move them to a reference file) — they restate generic security knowledge Claude already has, and consider moving the Gatekeeper/Istio sections to bundle files to reduce SKILL.md token load.

DimensionReasoningScore

Conciseness

The YAML examples are lean, but the 'Purpose', 'When to Use', 'Compliance Frameworks' (generic CIS/NIST bullets), and 'Best Practices' sections restate security knowledge Claude already has, which could be trimmed or moved to a reference file.

3 / 5

Actionability

Fully executable, copy-paste-ready YAML for NetworkPolicy, RBAC, securityContext, Gatekeeper ConstraintTemplate/Constraint, and Istio policies, plus concrete kubectl commands covering the common cases.

5 / 5

Workflow Clarity

Content is organized as a topic catalog with no implementation sequence or ordered checkpoints; the Troubleshooting commands serve as partial validation, but there is no explicit workflow (e.g., label namespaces → default-deny → allow rules → verify) for rolling out security.

3 / 5

Progressive Disclosure

References are one level deep and signaled inline, but 'assets/pod-security-template.yaml' is listed in the Reference Files section yet does not exist in the bundle, and the Gatekeeper and Istio sections are fully inlined content that arguably belongs in separate reference files.

3 / 5

Total

14

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it states concrete capabilities and pairs them with an explicit, naturally phrased 'Use when' clause. The only weaknesses are minor — a touch of buzzword ('production-grade security') and some missing trigger synonyms (e.g., 'RBAC', 'admission control') in the when-clause.

DimensionReasoningScore

Specificity

Names the domain and lists several concrete actions ('Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC'), but 'production-grade security' is mild fluff and the coverage stops at three policy types, so it falls just below the comprehensive anchor.

4 / 5

Completeness

Explicitly answers both what ('Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC') and when ('Use when securing Kubernetes clusters, implementing network isolation, or enforcing pod security standards') with concrete trigger phrases, matching the top anchor pattern.

5 / 5

Trigger Term Quality

'securing Kubernetes clusters', 'implementing network isolation', and 'enforcing pod security standards' are natural phrases users would say, but common variations like 'RBAC', 'network policies', or 'admission control' are absent from the when-clause.

4 / 5

Distinctiveness Conflict Risk

Clear Kubernetes security-policy niche with distinct triggers (cluster securing, network isolation, pod security standards); minimal risk of triggering for the wrong skill.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
Dicklesworthstone/pi_agent_rust
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.