CtrlK
BlogDocsLog inGet started
Tessl Logo

dt-sec-insights

Query and analyze Dynatrace security data in security.events with DQL: vulnerabilities, threat detections, compliance posture, and scan coverage. Covers Dynatrace-native Runtime Vulnerability Analytics (RVA — CVEs, reachability, exposure, exploit), Runtime Application Protection (RAP), Automated Detections, and Security Posture Management (KSPM/CSPM), plus external security products and tools. Trigger: "open critical vulnerabilities", "vulnerable functions in use and publicly exposed", "top vulnerable libraries / K8s workloads", "CIS/DORA compliance pass rate", "SQL injection detections", "map external findings to workloads", "hosts not covered by scanning". Do NOT use for explaining existing DQL (use dt-dql-essentials), Davis problems (dt-obs-problems), logs (dt-obs-logs), distributed tracing (dt-obs-tracing), service RED metrics (dt-obs-services), or platform usage/audit telemetry (dt-platform).

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured routing skill: clear intent-to-reference tables, explicit best-practice rules with specific fields and recovery guidance, and clean progressive disclosure to verified references. The main gaps are body-level conciseness (dense inline annotations) and the absence of any executable DQL example in the body itself.

Suggestions

Trim the dense parenthetical annotations in the routing tables and best-practice rules; move repeated caveats (e.g. the 30m/1h/2h/24h window rationale) to common-patterns.md and reference them once to reduce body length.

Include one or two short canonical DQL snippets inline (e.g. a minimal RVA snapshot count and a cross-provider summarize skeleton) so the body is executable on its own before delegating to references.

Frame the empty-result and widen-on-empty guidance as an explicit validate -> recover -> retry checklist to lift workflow clarity from 4 to 5.

DimensionReasoningScore

Conciseness

Mostly efficient and free of concept-explanation fluff (no 'what is a CVE/K8s' padding), but the dense routing tables and best-practice rules carry long parenthetical annotations and repeated caveats that could be tightened.

3 / 5

Actionability

Provides concrete field names, windows, and patterns, but the body deliberately contains no executable DQL query — it routes to references for canonical templates, so guidance is specific but not copy-paste executable here.

3 / 5

Workflow Clarity

Clear sequenced workflow (identify intent -> load reference -> build from canonical template -> apply best practices) with explicit recovery checkpoints (empty-result handling, widen-on-empty, anti-join rules), though not framed as a strict validate-fix-retry checklist.

4 / 5

Progressive Disclosure

Clean overview SKILL.md pointing to one-level-deep references, all of which exist and are clearly signaled via markdown links plus a dedicated 'How This Skill Is Organized' map; content is well-split by domain.

5 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is excellent: third-person, specific, with concrete trigger phrases and an explicit negative-boundary clause that de-conflicts sibling skills. It fully answers both what the skill does and when to use it.

DimensionReasoningScore

Specificity

Names the concrete data source (security.events, DQL) and enumerates specific analysis actions across many capability families (RVA CVEs/reachability/exposure/exploit, RAP, Automated Detections, KSPM/CSPM, scan coverage), with comprehensive itemized coverage rather than minor gaps.

5 / 5

Completeness

Clearly answers both 'what' (query/analyze Dynatrace security data in security.events with DQL across listed families) and 'when' via an explicit Trigger block with concrete trigger phrases.

5 / 5

Trigger Term Quality

An explicit 'Trigger:' block lists natural user phrases ('open critical vulnerabilities', 'top vulnerable libraries / K8s workloads', 'CIS/DORA compliance pass rate', 'SQL injection detections', 'hosts not covered by scanning') with synonyms across sub-domains.

5 / 5

Distinctiveness Conflict Risk

Highly specific Dynatrace-security.events/DQL niche, with an explicit 'Do NOT use for ...' clause disambiguating against named sibling skills (dt-dql-essentials, dt-obs-problems, etc.), minimizing conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Dynatrace/dynatrace-for-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.