CtrlK
BlogDocsLog inGet started
Tessl Logo

cx-alerts

This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts", "check which alerts are active", "find alerting rules", "set up an alert", "configure alerting", "mute an alert", "silence an alert", "see alert definitions", "check alert priority", or wants to manage Coralogix alert definitions using the cx CLI.

68

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable — exact commands, flags, and three complete JSON payloads — with sensible progressive disclosure to five real one-level-deep reference files. It loses points for duplicated sections (suppression table, alert-type table, priority rule), content that belongs in the reference files, and a lack of validation around the destructive delete operation.

Suggestions

Remove the duplicate suppression-rules table (keep only the '## Suppression Rules' section) and trim the 12-row alert-types table to a pointer into references/alert-schemas.md, which already documents all 12 types.

Add an explicit verification checkpoint to destructive and multi-profile operations, e.g. confirm the alert ID with `cx alerts get <id>` before `cx alerts delete <id>`, and re-list per profile when using repeatable `-p <profile>`.

State the 'always ask for priority' rule once (in '## Priority Levels') instead of repeating it in '## Key Principles', freeing tokens for the missing delete/multi-profile validation guidance.

DimensionReasoningScore

Conciseness

Mostly efficient tables and examples, but there is real duplication: the suppression-rules command table appears twice verbatim ("## CLI Commands" and "## Suppression Rules"), the 12-row alert-types table re-states content already covered in references/alert-schemas.md, and "Always ask for priority" is stated in both "## Priority Levels" and "## Key Principles". This fits level 3 ('could be tightened') better than 4 ('minor instances'), since whole sections are redundant rather than individual phrases.

3 / 5

Actionability

Fully executable throughout: a command table with exact flags (`cx alerts list --name <filter>`, `-o json`, `--from-file <path>`, `-p <profile>`), three complete copy-paste JSON payloads covering the common cases (logs threshold, metric threshold, logs immediate), and concrete bash snippets like `cx alerts list -o json | jq '.[] | select(.status == "ALERTING")'`. Not below 5 because commands and examples cover the common cases with no pseudocode.

5 / 5

Workflow Clarity

The create workflow is a clear 6-step sequence with an explicit validation checkpoint ("Verify with `cx alerts list --name`" / "Verify after create"), but the skill covers the destructive `cx alerts delete <id>` with no verification step for deletion, and the batch-style `-p <profile>` repeatable multi-profile flag has no validation either. Per the rubric's cap, a destructive operation without validation cannot score above 3; the mitigation 'Disable, don't delete' is a principle, not a checkpoint, so level 4's 'most checkpoints present' is not reached for the destructive path.

3 / 5

Progressive Disclosure

Good structure: SKILL.md is an overview with clear sections, all five referenced files (references/alert-schemas.md, dataprime-reference.md, logs-querying.md, promql-guidelines.md, spans-querying.md) exist, are one level deep, and are well-signaled with per-file descriptions in "## Additional Resources" plus an inline pointer in the create workflow. Not 5 because the 12-type alert table and duplicated suppression-rules content are inline material that belongs in the reference files, leaving minor organization gaps; not 3 because navigation is easy and references are clearly signaled, not buried.

4 / 5

Total

15

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it explicitly answers both what and when with an extensive list of natural trigger phrases including synonyms, scoped to a clear Coralogix/cx-CLI niche in third-person voice. The only weakness is mild overlap risk with sibling investigation-oriented cx skills on 'investigate'/'check active' phrasing.

DimensionReasoningScore

Specificity

The description explicitly names a comprehensive set of concrete actions — "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "mute an alert", "silence an alert", "configure alerting", "check alert priority" — plus the target object (Coralogix alert definitions) and tool (cx CLI). It is not level 4 because the gaps (e.g., no mention of suppression rules or getting a single alert by ID) are minor relative to the fourteen distinct actions explicitly stated; not below 5 because no anchor lists more complete, concrete coverage.

5 / 5

Completeness

Both what ("manage Coralogix alert definitions using the cx CLI") and when ("This skill should be used when the user asks to ... or wants to manage Coralogix alert definitions") are explicitly and concretely answered with trigger phrases, matching the level-5 anchor exactly. Not level 4 because the 'when' is maximally explicit rather than 'could be more specific'.

5 / 5

Trigger Term Quality

Natural user phrasings are comprehensively covered with synonyms and variations: "set up an alert" / "configure alerting", "mute an alert" / "silence an alert", "investigate firing alerts", "check which alerts are active", "find alerting rules", "see alert definitions". Not level 4 because the synonym coverage is unusually thorough (mute/silence, set up/configure, firing/active) rather than missing a few natural terms.

5 / 5

Distinctiveness Conflict Risk

The niche is clear ("Coralogix alert definitions using the cx CLI") and management triggers (create/enable/disable/delete) are distinct, but investigation-flavored phrases like "investigate firing alerts" and "check which alerts are active" overlap with closely related sibling skills (cx-telemetry-querying, cx-slos whose error-budget burn raises alerts). This fits level 4 ('mostly distinct; minor overlap risk with closely related skills') better than 5 ('minimal conflict risk').

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
coralogix/cx-cli
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.