CtrlK
BlogDocsLog inGet started
Tessl Logo

homelab-vlan-segmentation

Segmenting home networks into VLANs for IoT, guest, trusted, and server traffic using UniFi, pfSense/OPNsense, and MikroTik — including switch trunk config, firewall rules, and wireless SSID mapping. Use when splitting a home network into IoT, guest, trusted, and server VLANs on UniFi, pfSense/OPNsense, or MikroTik.

66

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/homelab-vlan-segmentation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-organized skill with concrete click-paths, ordered firewall rules, and executable RouterOS commands, plus genuine safety guidance (maintenance windows, per-change isolation testing). Its weaknesses are token efficiency — redundant Pi-hole guidance, a duplicated example, and a trunk-vs-access explainer Claude doesn't need — and the lack of a single unified step sequence with embedded validation checkpoints.

Suggestions

Remove or drastically shorten the 'Switch Trunk vs Access Ports' explainer and the duplicated example block — keep one concrete scenario and reference the design template instead of restating it with device names.

Consolidate the Pi-hole placement guidance (currently in Examples, Anti-Patterns, and Best Practices) into a single statement, and state the DNS-before-RFC1918-block ordering once.

Add an explicit ordered workflow with embedded checkpoints (create VLANs → assign interfaces → DHCP → firewall rules → test isolation after each change) that the per-platform sections then implement, and complete the MikroTik firewall example to match the design template's ruleset.

DimensionReasoningScore

Conciseness

Mostly dense operational content, but the 'Switch Trunk vs Access Ports' section re-explains a concept Claude already knows, the Examples block partially restates the VLAN design template with device names substituted, and Pi-hole placement guidance is repeated across the Examples, Anti-Patterns, and Best Practices sections. More than minor trimming is possible, fitting the 'mostly efficient but includes some unnecessary explanation' anchor.

3 / 5

Actionability

The MikroTik section gives copy-paste RouterOS commands and UniFi/pfSense give exact menu paths with explicit rule ordering ('MUST come before the RFC1918 block rule'). Minor gaps remain — the MikroTik firewall shows only the IoT-to-Trusted drop rule rather than the full ruleset from the design template, and the guest/server VLANs are absent from that platform's example.

4 / 5

Workflow Clarity

Sequences are clear per platform (MikroTik is explicitly Step 1–7, pfSense rules are ordered with the DNS exception before the RFC1918 block) and validation is explicitly stated ('Test isolation after every rule change: from the IoT VLAN, try to ping a trusted device — it should fail', plus the maintenance-window note). However, there is no unified end-to-end procedure and the verification guidance is scattered across sections rather than embedded as ordered checkpoints, which fits 'clear sequence with most checkpoints present; minor validation gaps'.

4 / 5

Progressive Disclosure

The body is well-sectioned with clear headers (design template, per-platform configs, anti-patterns, best practices) and no buried or nested references — no bundle files exist at all. It falls short of the top anchor because ~295 lines with three complete per-platform configuration guides inlined is content that could be split into one-level-deep reference files, leaving SKILL.md as an overview.

4 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly states what the skill does, when to use it, and on which platforms, with concrete configuration domains (trunks, firewall rules, SSID mapping). Its only weakness is slightly incomplete natural-language trigger coverage — phrases like 'isolate IoT devices' or 'guest Wi-Fi' that users commonly say are absent.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'switch trunk config, firewall rules, and wireless SSID mapping' — for segmenting traffic into named VLAN classes, with the three target platforms (UniFi, pfSense/OPNsense, MikroTik) named. Coverage of the skill's config domains is comprehensive rather than leaving minor gaps, matching the top anchor.

5 / 5

Completeness

It explicitly answers both halves: the 'what' ('Segmenting home networks into VLANs ... including switch trunk config, firewall rules, and wireless SSID mapping') and a concrete 'when' clause ('Use when splitting a home network into IoT, guest, trusted, and server VLANs on UniFi, pfSense/OPNsense, or MikroTik'). This matches the anchor where both what and when are explicit with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural terms users would actually say are well covered: 'home network', 'VLAN', 'IoT', 'guest', 'trusted', 'server', plus the exact platform names UniFi, pfSense/OPNsense, and MikroTik. A few common phrasings are missing (e.g. 'isolate IoT devices', 'guest Wi-Fi', 'smart home'), which fits the 'good coverage, a few natural terms missing' anchor rather than the synonym-saturated top anchor.

4 / 5

Distinctiveness Conflict Risk

It occupies a clear niche (home-network VLAN segmentation) with distinct triggers tied to named platforms, so it is unlikely to fire for unrelated networking or smart-home skills. Minimal conflict risk, matching the top anchor.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.