CtrlK
BlogDocsLog inGet started
Tessl Logo

generate-sandbox-policy

Generate sandbox security policies from plain-language requirements and optional REST API documentation. Produces L4 or fine-grained L7 network policies and ordered network middleware configuration. Use for API access rules, middleware host selection, failure behavior, or built-in and operator-run middleware attachment. Trigger keywords - generate policy, create policy, update policy, change policy, sandbox policy, network policy, API policy, security policy, allow API, restrict API, network middleware, supervisor middleware.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with a strong, well-validated multi-step workflow and excellent concrete examples. Its main weakness is conciseness: it runs long with some inlined reference material and un-bundled external references that slightly undercut progressive disclosure.

Suggestions

Tighten verbose prose — collapse repeated WebSocket-binding caveats and long breadth-warning sentences into terser checklist entries to respect the token budget.

Move inlined reference-style detail (validation rules, glob semantics, full middleware behavior) into bundled reference files and keep the SKILL.md body as an overview pointing to them, so the referenced paths actually exist in the bundle.

Verify that the 'Additional Resources' links resolve to files shipped with the skill, or convert them into bundled assets, to make the one-level-deep references reliable.

DimensionReasoningScore

Conciseness

Mostly efficient use of tables, decision trees, and checklists, but ~650 lines include padded prose (repeated WebSocket-binding caveats, lengthy breadth-warning sentences) and some conceptual explanation Claude could be assumed to know.

3 / 5

Actionability

Provides fully executable, copy-paste-ready YAML templates, decision trees, glob-mapping tables, and concrete Quick Reference patterns covering the common L4/L7/private-IP cases.

5 / 5

Workflow Clarity

Eight clearly sequenced steps culminate in a 'Validate and Warn' step with explicit Hard Error / Schema Warning / Structural / Breadth checklists and feedback loops, including which errors would block sandbox startup.

5 / 5

Progressive Disclosure

Section structure is clear and references are signaled one-level-deep via Read commands and links, but the referenced files are repo-relative paths absent from the bundle, and substantial reference-style detail (validation rules, glob semantics, middleware behavior) is inlined rather than split into separate files.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is comprehensive and well-structured, explicitly stating both capabilities and use-conditions with an explicit trigger-keyword list. Third-person voice is consistent and the niche is clearly delineated.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('Generate sandbox security policies', 'Produces L4 or fine-grained L7 network policies', 'ordered network middleware configuration') covering the capability space comprehensively.

5 / 5

Completeness

Clearly answers both 'what' (generates L4/L7 policies and ordered middleware config) and 'when' ('Use for API access rules, middleware host selection, failure behavior...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

An explicit 'Trigger keywords' list provides comprehensive natural phrasings and synonyms ('generate policy', 'allow API', 'restrict API', 'network middleware', 'supervisor middleware') users would actually say.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (sandbox network policy generation) with distinctive triggers ('sandbox policy', 'supervisor middleware') and minimal overlap risk with other skills; uses correct third-person voice.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (652 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 1 missing, 3 suspicious

Warning

Total

14

/

16

Passed

Repository
NVIDIA/OpenShell
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.