CtrlK
BlogDocsLog inGet started
Tessl Logo

network-policy-architect

Design and validate Kubernetes NetworkPolicies following Zero Trust principles (NIST SP 800-207). Two-tier analysis — architecture review then live cluster verification — produces a verified implementation plan with apply-and-verify results. Use when: - "Create NetworkPolicies for my namespace" - "Audit network isolation for this workload" - "Design network segmentation for a new application" - "Verify NetworkPolicies implement Zero Trust" - User mentions "network policy", "microsegmentation", "default-deny" NOT for Admin Network Policy (ANP) cluster-wide rules — those are cluster-admin infrastructure guardrails, not application-level microsegmentation. NOT for CNI plugin configuration or Multus secondary networks.

73

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced two-tier workflow with strong validation and feedback loops. The main weakness is monolithic structure with duplicated tool references and no progressive disclosure into separate files.

Suggestions

Split the per-MCP-tool parameter reference into a single reference file (e.g. references/mcp-tools.md) and link to it, eliminating the duplication between the Prerequisites and Dependencies sections.

Move the detailed Example Usage walkthrough into references/examples.md, keeping only a brief pointer inline so SKILL.md stays a lean overview.

Trim rhetorical padding (the 'Recommendations carry the weight of a security audit' paragraph and the block-quoted NIST definition) to tighten the opening without losing operational substance.

DimensionReasoningScore

Conciseness

Dense and mostly operational, but includes minor rhetorical padding ('Recommendations carry the weight of a security audit. Every rule proposed must be justified...') and a quoted NIST block that could be trimmed without losing actionability.

4 / 5

Actionability

Each step names a specific MCP tool with concrete parameters (apiVersion/kind/namespace), gives an executable default-deny YAML manifest, and provides structured tables for per-pod rules — copy-paste ready and covering the common cases.

5 / 5

Workflow Clarity

Two mandatory tiers, 16 numbered steps, explicit PASS/FAIL validation with evidence, and clear feedback loops (on FAIL → cleanup, report, ask how to proceed) plus human-confirmation checkpoints for destructive operations.

5 / 5

Progressive Disclosure

Well-sectioned with clear headers, but the skill is a ~430-line monolith with no bundle/reference files; the MCP tool reference is duplicated across Prerequisites and Dependencies and bulk detail that could be externalized is inlined.

3 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that concretely states the skill's actions, provides natural trigger phrases, and draws clear boundaries against adjacent tools. It fully answers both 'what' and 'when' with minimal conflict risk.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Design and validate Kubernetes NetworkPolicies', 'architecture review then live cluster verification', 'produces a verified implementation plan with apply-and-verify results' — giving comprehensive coverage of what the skill does.

5 / 5

Completeness

Explicitly answers both what (design/validate NetworkPolicies via two-tier analysis producing a verified implementation plan) and when (a concrete 'Use when' trigger list plus a 'NOT for' negative-boundary clause).

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage with synonyms users actually say: 'Create NetworkPolicies for my namespace', 'Audit network isolation', 'network segmentation', 'microsegmentation', 'default-deny', plus the generic 'network policy'.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (Kubernetes/OpenShift NetworkPolicies under Zero Trust) and explicitly excludes adjacent domains (Admin Network Policy, CNI/Multus), minimizing overlap with other skills.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 2 suspicious

Warning

Total

14

/

16

Passed

Repository
RHEcosystemAppEng/agentic-plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.