CtrlK
BlogDocsLog inGet started
Tessl Logo

docker-patterns

Docker and Docker Compose patterns for local development, hardened CLI installer harnesses, container security, networking, volumes, and multi-service orchestration. Use when creating or reviewing Dockerfiles and Compose services, testing installers across Linux distributions, or planning accurate native macOS and Windows validation.

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/docker-patterns/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly executable pattern catalog with a genuinely well-validated installer-harness workflow. The main weaknesses are the monolithic single-file structure — the ECC harness deep-dive should be split into a referenced file — and some duplication across the volumes/networking sections.

Suggestions

Move the 'Hardened CLI Installer Harnesses' section (~145 lines of project-specific ECC detail) into a separate reference file (e.g., references/installer-harness.md) and keep a short overview with a clearly signaled link in SKILL.md.

Deduplicate the volume and service-discovery content that appears both in the main Compose example and again in the 'Volume Strategies' and 'Service Discovery' sections.

Complete the 'Dockerfile Hardening' snippet into a full executable example (actual RUN/cap_drop directives instead of the comment-only steps 3-5), and note that commands like `npm run test:plugin-setup-platform` require the host project's scripts.

DimensionReasoningScore

Conciseness

The body is code-forward with almost no explanation of concepts Claude already knows, but volume strategies and service-name resolution each appear twice (in the main Compose example and again in dedicated sections), and the .dockerignore/debugging catalogs could be trimmed — efficient with minor instances that could be tightened, matching anchor 4.

4 / 5

Actionability

Most guidance is fully executable, copy-paste-ready Compose YAML, multi-stage Dockerfiles, and bash commands. Minor gaps keep it below 5: the "Dockerfile Hardening" block is a comment-only checklist ("# 3. Drop capabilities (in compose)"), and commands depend on project files not shipped in the skill (docker/plugin-setup/interactive-plan.js, npm run test:plugin-setup-platform).

4 / 5

Workflow Clarity

The installer-harness workflow is clearly sequenced with explicit validation checkpoints ("Validate the Compose model before building", docker image inspect "before trusting the image", and stated harness rejection criteria) plus clean-up steps. However, the first half of the skill is a reference catalog with no workflow, so it does not reach the comprehensive anchor-5 level.

4 / 5

Progressive Disclosure

Section headers are clear, but this is a single ~520-line file with no reference files at all: the ~145-line project-specific ECC plugin-harness section (with its own env vars like ECC_TMPFS_SIZE and session lifecycle) is inlined content that clearly belongs in a separate reference file, matching anchor 3. The under-50-line simple-skill exception does not apply.

3 / 5

Total

15

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete domain coverage, an explicit and specific "Use when" trigger clause, and low conflict risk. Its only weakness is that the "what" is phrased as topic areas ("patterns for...") rather than concrete actions, which keeps specificity just below the top anchor.

DimensionReasoningScore

Specificity

The description enumerates several specific capability areas — "hardened CLI installer harnesses, container security, networking, volumes, and multi-service orchestration" — plus actions like "creating or reviewing Dockerfiles", but frames the offering as "patterns for" rather than listing multiple concrete actions, so it falls between the several-actions (4) and comprehensive-actions (5) anchors.

4 / 5

Completeness

It explicitly answers both questions: the "what" is the enumerated pattern domains, and the "when" is a concrete trigger clause — "Use when creating or reviewing Dockerfiles and Compose services, testing installers across Linux distributions, or planning accurate native macOS and Windows validation" — matching the anchor-5 example structure.

5 / 5

Trigger Term Quality

Natural trigger terms are well covered: "Docker", "Docker Compose", "Dockerfiles", "Compose services", "Linux distributions", "macOS and Windows validation". A few natural variations users would say (e.g., "containerize", "docker-compose.yml") are missing, matching anchor 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

It occupies a clear Docker/Compose niche with a distinctive installer-harness validation angle, and its triggers (Dockerfiles, Compose services, cross-distro installer testing) are unlikely to fire for an unrelated skill.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (521 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.