CtrlK
BlogDocsLog inGet started
Tessl Logo

generate-sandbox-policy

Generate sandbox security policies from plain-language requirements and optional REST API documentation. Produces L4 or fine-grained L7 network policies and ordered network middleware configuration. Use for API access rules, middleware host selection, failure behavior, or built-in and operator-run middleware attachment. Trigger keywords - generate policy, create policy, update policy, change policy, sandbox policy, network policy, API policy, security policy, allow API, restrict API, network middleware, supervisor middleware.

71

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with a clear, validated workflow, but it is verbose and bundles most material into a single long file. The broken examples.md reference and inline-heavy structure are the main progressive-disclosure weaknesses.

Suggestions

Create the referenced examples.md (or remove the link) so the 'see examples.md' pointer does not point to a missing file.

Move the Quick Reference patterns and the full policy-file scaffolding into a separate reference file, leaving SKILL.md as a lean overview with one-level-deep links.

Tighten the breadth-warning and scoping-down tables to short condition->action rows instead of full quoted warning sentences to reduce token cost while keeping them actionable.

DimensionReasoningScore

Conciseness

The ~610-line body is mostly domain-specific and actionable rather than padded with concepts Claude already knows, so it avoids level 1; however it is not lean — repeated full-text breadth-warning messages and long clarification tables could be tightened, keeping it at level 2 rather than 3.

2 / 3

Actionability

Provides copy-paste-ready YAML templates, a decision tree, a glob-mapping table, concrete commands ('openshell sandbox create --policy <path>'), and explicit validation checklists — fully executable, specific guidance matching the level-3 anchor.

3 / 3

Workflow Clarity

A clear 8-step sequence is present, and Step 6 supplies explicit validation checklists (Hard Errors, Schema Warnings, Structural, Breadth) forming a validate-then-fix loop, while Step 2 defines an iterative clarification loop with explicit stop criteria.

3 / 3

Progressive Disclosure

Heavy schema detail is deferred to well-signaled external docs ('Read docs/reference/policy-schema.mdx'), but the body itself is monolithic with substantial inline content (Quick Reference patterns, full scaffolding) and the referenced [examples.md](examples.md) bundle file does not exist, so it does not reach the level-3 'appropriately split' anchor.

2 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, uses third person, supplies a strong set of natural trigger keywords, and explicitly covers both capability and use-when guidance. It is a strong, well-distinguished description with no notable weaknesses.

DimensionReasoningScore

Specificity

Names multiple concrete actions in third person ('Generate sandbox security policies', 'Produces L4 or fine-grained L7 network policies and ordered network middleware configuration', 'middleware host selection, failure behavior'), matching the level-3 anchor of listing several specific concrete actions.

3 / 3

Completeness

Clearly answers both what ('Generate sandbox security policies... Produces L4 or fine-grained L7 network policies and ordered network middleware configuration') and when ('Use for API access rules, middleware host selection, failure behavior... Trigger keywords - ...'), with explicit trigger guidance.

3 / 3

Trigger Term Quality

Includes an explicit, natural keyword list ('generate policy, create policy, update policy... sandbox policy, network policy, API policy, security policy, allow API, restrict API, network middleware'), giving good coverage of phrases a user would actually say.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear sandbox network-policy and middleware niche with domain-specific triggers; unlikely to fire for unrelated skills. The generic verbs ('generate policy') introduce minor overlap risk but the sandbox framing keeps it distinct, so it sits at level 3 rather than 2.

3 / 3

Total

12

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (617 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 1 missing, 3 suspicious

Warning

Total

14

/

16

Passed

Repository
NVIDIA/OpenShell
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.