CtrlK
BlogDocsLog inGet started
Tessl Logo

ci-cd

CI/CD pipeline design, optimization, DevSecOps security scanning, and troubleshooting. Use this skill whenever the user mentions CI/CD, GitHub Actions, GitLab CI, pipelines, workflows, builds, or DevSecOps. Triggers include creating new CI/CD workflows, debugging pipeline failures or flaky tests, implementing SAST/DAST/SCA security scanning, optimizing slow builds with caching or parallelization, setting up deployment workflows, securing pipelines with OIDC or secrets management, implementing matrix builds or test sharding, and troubleshooting Docker, permissions, or timeout issues.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable and well-structured with real, clearly-signaled bundle files, but it is verbose for a SKILL.md overview — several inline sections duplicate content already available in templates and references, and some multi-step workflows omit explicit validation checkpoints.

Suggestions

Trim redundancy: remove the 'Quick Reference Commands' section (it repeats gh/gl commands already shown under Troubleshooting) or consolidate into one location.

Move the large inline DevSecOps YAML and 'Common Patterns' (caching/matrix/conditional) examples into the existing templates/references, keeping SKILL.md as a pointer-driven overview.

Add explicit validate→fix→retry checkpoints to the deployment and security-gate workflows (e.g., 'verify health check passes before proceeding; on failure, rollback and re-diagnose').

DimensionReasoningScore

Conciseness

Mostly efficient and free of concept-explanation fluff, but the ~280-line body duplicates material that exists in templates/references (e.g., 'Quick Reference Commands' repeats gh commands already shown in Troubleshooting, and 'Common Patterns' re-inlines caching/matrix examples present in template files), so it could be tightened.

3 / 5

Actionability

Densely packed with copy-paste-ready executable guidance — YAML snippets, bash commands (gh/gl/act), the pipeline_analyzer.py invocation, decision trees, and lookup tables — covering the common cases concretely.

5 / 5

Workflow Clarity

Core workflows are clearly sequenced (the 4-step Troubleshooting flow, deployment pattern selection) with checklists and feedback loops (rollback on failure, security gate), but some workflows lack explicit validate→fix→retry checkpoints, leaving minor validation gaps.

4 / 5

Progressive Disclosure

Good structure with well-signaled one-level-deep references (all 5 references/*.md, scripts/pipeline_analyzer.py, and 10 template files are real and listed in dedicated 'Reference Documentation' and 'Templates' sections), but a fair amount of detail (DevSecOps YAML, platform patterns) is inlined in SKILL.md rather than split into the bundle files.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is excellent: it concisely states concrete capabilities, provides comprehensive natural trigger terms, explicitly covers both what and when, and occupies a clear CI/CD niche with low conflict risk. Third-person voice is maintained throughout.

DimensionReasoningScore

Specificity

Lists many concrete actions — 'pipeline design, optimization, DevSecOps security scanning, and troubleshooting' plus 'creating new CI/CD workflows, debugging pipeline failures or flaky tests, implementing SAST/DAST/SCA... optimizing slow builds with caching or parallelization... matrix builds or test sharding' — comprehensive coverage of specific capabilities.

5 / 5

Completeness

Explicitly answers both: what ('CI/CD pipeline design, optimization, DevSecOps security scanning, and troubleshooting') and when ('Use this skill whenever the user mentions... Triggers include...'), with concrete trigger phrases.

5 / 5

Trigger Term Quality

Covers the natural terms users say — 'CI/CD, GitHub Actions, GitLab CI, pipelines, workflows, builds, or DevSecOps' — plus synonyms and specifics (SAST/DAST/SCA, OIDC, Docker), giving comprehensive keyword coverage.

5 / 5

Distinctiveness Conflict Risk

CI/CD is a clear niche anchored to specific platforms (GitHub Actions, GitLab CI) and concrete triggers, giving minimal conflict risk with other skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ahmedasmar/devops-claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.