CtrlK
BlogDocsLog inGet started
Tessl Logo

dt-sec-contextualization

Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Covers identity-to-Smartscape mapping (incl. container-image digest/ID to workload), cross-level topology (K8s pod detection vs. node CVE via pod-to-node), per-entity risk summarization, and coverage match recipes shared by dt-sec-insights. Trigger: "map these findings to workloads/hosts", "which workload does this container image run as", "do these findings relate through the same runtime entity", "enrich this IoC match with entity context", "which threat report mentions this IoC". Queries security.events ONLY for THREAT_REPORT IoC enrichment (matched IoC to attributing reports); Do NOT use for broad security.events posture/overview (use dt-sec-insights), general DQL (use dt-dql-essentials), IoC hunting in logs/spans (use dt-sec-ioc-hunting), or K8s observability outside the security cross-level context (use dt-obs-kubernetes).

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured routing skill that points precisely to four reference files with intent-based navigation and concrete guardrails, suffering only minor verbosity and the absence of inline executable examples and an explicit recovery loop.

Suggestions

Trim the opening paragraph and the redundant 'What This Skill Covers' bullets that restate the frontmatter description, keeping the body focused on routing and guardrails.

Add a short numbered end-to-end workflow (select reference → pre-flight check → enrichment → dedup → verify) with an explicit validate→fix→retry feedback loop for the 3-way append chain.

Include one minimal copy-paste DQL snippet per covered pattern (e.g. the digest→CONTAINER→workload bridge) in the body or ensure each reference's lead example is linked inline so the skill is executable without opening a file.

DimensionReasoningScore

Conciseness

Dense and free of basic-concept padding, but the opening paragraph partly restates the frontmatter description and a few 'What This Skill Covers' bullets run long; efficient overall with minor trim opportunities, so above the midpoint but not fully lean.

4 / 5

Actionability

Names specific fields, entity types, and patterns (container_image.digest → CONTAINER → workload, 3-way match, k8s.node.name) and routes intents to concrete file+section pointers, but the body itself holds no executable query examples — acceptable for a routing skill yet just short of fully copy-paste ready.

4 / 5

Workflow Clarity

A clear implied sequence (load dt-dql-essentials → ground in template → pre-flight check → enrichment → dedup) with real checkpoints (pre-flight before append, dedup early and after append, check dt.smartscape_source.type before Path 1), but no single linear numbered workflow with an explicit validate→fix→retry recovery loop, leaving minor validation gaps.

4 / 5

Progressive Disclosure

SKILL.md is a clean overview routing to four real one-level-deep reference files, each clearly signaled with markdown links and described in 'How This Skill Is Organized', and the 'When to Use' table maps intents to specific files and sections — easy navigation with content appropriately split.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that concretely enumerates capabilities, supplies natural trigger phrases, answers both what and when, and sharply distinguishes the skill from siblings via explicit do-not-use routing.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities', cross-level topology via pod-to-node, per-entity risk summarization, and reverse IoC enrichment — matching the 'comprehensive coverage' anchor; not a 4 because no meaningful action is missing.

5 / 5

Completeness

Explicitly states both what ('Resolve security signals...connect findings on different entity levels') and when via a dedicated 'Trigger:' clause with concrete phrases, plus negative 'Do NOT use for' routing; clearly the 'answers both what AND when with concrete trigger phrases' anchor.

5 / 5

Trigger Term Quality

Quotes natural user phrases ('map these findings to workloads/hosts', 'which workload does this container image run as', 'enrich this IoC match with entity context', 'which threat report mentions this IoC') covering the main intents with synonyms; fits the comprehensive-coverage anchor.

5 / 5

Distinctiveness Conflict Risk

A clear Dynatrace security-contextualization niche with distinct triggers and an explicit 'Do NOT use for...' block routing to dt-sec-insights, dt-dql-essentials, dt-sec-ioc-hunting, and dt-obs-kubernetes, minimizing conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Dynatrace/dynatrace-for-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.