CtrlK
BlogDocsLog inGet started
Tessl Logo

bash-defensive-patterns

Master defensive Bash programming techniques for production-grade scripts. Use when writing robust shell scripts, CI/CD pipelines, or system utilities requiring fault tolerance and safety.

71

1.09x
Quality

57%

Does it follow best practices?

Impact

96%

1.09x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/AI-Agents-Safe-Coding-Skills-claude/skills/bash-defensive-patterns/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is concise and well-structured with clear use/do-not-use framing and a short sequenced instruction list, but it is not actionable: it gives high-level hints with no executable Bash patterns, and it depends on a referenced playbook file that is not present in the bundle. The destructive-operation workflow also lacks an explicit validation checkpoint.

Suggestions

Add concrete, copy-paste-ready Bash snippets inline for the core defensive patterns (e.g. `set -euo pipefail`, an ERR/EXIT trap, `[[ -v VAR ]]` / `:=` input checks, `printf '%q'` safe quoting) instead of only high-level hints.

Either create resources/implementation-playbook.md with the detailed patterns/checklists/templates it promises, or remove the dangling reference; a missing referenced file breaks progressive disclosure.

Insert an explicit validation checkpoint in the Instructions workflow for destructive operations, e.g. a dry-run step (`git ... --dry-run`, `rm -i`, or `--noop`) and a verify step that confirms strict mode and traps are active before executing.

DimensionReasoningScore

Conciseness

The body is lean with well-scoped Use/Do-not-use lists and short instructions; only the opening line restates the description and the playbook reference is repeated (line 42 and the Resources section), minor over-explanation that could be trimmed. It is not a 5 because of that redundant intro and duplicate reference, and not a 3 because padding is minimal.

4 / 5

Actionability

The Instructions are high-level hints ("Enable strict mode and safe defaults", "Validate inputs, quote variables, and handle files safely") with no executable code or specific commands, and the referenced implementation-playbook that would carry concrete patterns does not exist. It is not a 1 because a structured 4-step instruction list is present, and not a 3 because there is no executable code or pseudocode and key execution details are missing.

2 / 5

Workflow Clarity

Four sequenced steps are listed (confirm environment, enable strict mode, validate/quote/handle, add logging/traps/tests), but the Safety section flags destructive operations and there is no explicit validation/verification checkpoint, so the destructive-operations cap of 3 applies. It is not a 4 because no validation checkpoint or feedback loop is present, and not a 2 because the sequence is coherent rather than full of gaps.

3 / 5

Progressive Disclosure

Sections are well organized and a one-level-deep reference to resources/implementation-playbook.md is clearly signaled, but that referenced file does not exist (no resources/ directory), so navigation is undermined by a dangling reference. It is not a 4 because the primary detailed-content target is missing, and not a 2 because structure is clear and references are not buried.

3 / 5

Total

12

/

20

Passed

Description

65%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly states a distinct niche and provides an explicit, concrete "Use when" clause with several natural trigger phrases. Its main weakness is specificity: it describes the goal ("master techniques") without naming concrete capabilities, leaving the "what" somewhat abstract.

Suggestions

Replace "Master defensive Bash programming techniques" with 2-3 concrete capabilities, e.g. "Enable strict mode (set -euo pipefail), trap and handle errors, validate inputs, and quote variables safely in production Bash scripts."

Add natural trigger synonyms users actually say, such as "bash script", "error handling", or "shell script that won't fail", to broaden keyword coverage.

DimensionReasoningScore

Specificity

"Master defensive Bash programming techniques" names the domain but enumerates no concrete actions (no mention of strict mode, traps, quoting, input validation), matching the anchor where actions are minimal or generic; it is not a 3 because no 1-2 concrete capabilities are listed, and not a 1 because the domain is clearly named.

2 / 5

Completeness

Both a "what" (defensive Bash programming for production scripts) and an explicit "when" with concrete trigger phrases are present; it is not a 5 because the "what" does not enumerate concrete capabilities like the 5-anchor example does, and not a 3 because the "when" is explicit rather than weakly implied.

4 / 5

Trigger Term Quality

"robust shell scripts, CI/CD pipelines, or system utilities requiring fault tolerance and safety" provides good natural-term coverage a user would say; it is not a 5 because synonyms like "bash script", "error handling", and file extensions are missing, and not a 3 because multiple natural trigger phrases are present.

4 / 5

Distinctiveness Conflict Risk

"Defensive Bash programming" combined with fault-tolerance/CI-CD triggers carves a mostly distinct niche with only minor overlap against general shell-scripting or CI skills; it is not a 5 because the trigger scope (shell scripts, pipelines, utilities) is still fairly broad, and not a 3 because the defensive-production framing narrows it beyond generic scripting.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
administrakt0r/AI-Agents-Safe-Coding-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.