CtrlK
BlogDocsLog inGet started
Tessl Logo

daytona-windows-cert

test on Windows, enterprise CA, corporate certificate, GPO cert, TLS fetch failed, Windows sandbox, daytona windows, self-hosted cert. Use when validating OpenWork Windows enterprise TLS/OS-trust fixes in a Daytona Windows sandbox.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.opencode/skills/daytona-windows-cert/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a high-quality operational skill: an unambiguous numbered workflow, copy-paste-ready commands, explicit verification steps with expected outputs, and valuable session-0 and shell-quoting traps Claude would not otherwise know. The main costs are token efficiency (three repeated 'verified session shape' command blocks and a fully inlined bundled script) and minor organization (the probe script should be referenced, not inlined).

Suggestions

Delete the redundant 'The release command shape from the verified session was' and 'The Windows download/extract shape from the verified session was' blocks and the second 'daytona sandbox start' example; each restates a command already shown verbatim.

Replace the inlined ca-probe.js source with an instruction to read and copy scripts/ca-probe.js from the bundle, since the file already ships alongside SKILL.md.

Consider moving the shell/quoting gotchas section into a reference file (e.g. references/windows-gotchas.md) linked from the main workflow to slim the always-loaded context.

DimensionReasoningScore

Conciseness

The body is almost entirely commands and hard-won gotchas with no known-concept padding, but it repeats itself: the 'gh release create' shape, the curl/tar download shape, and 'daytona sandbox start' are each shown twice, and the full 34-line ca-probe.js is inlined despite shipping at scripts/ca-probe.js.

3 / 5

Actionability

Fully copy-paste ready throughout: exact 'daytona create --snapshot windows-medium', base64 EncodedCommand payloads, concrete curl/tar/stage download commands, the complete runnable ca-probe.js, and the expected verified result JSON for comparison.

5 / 5

Workflow Clarity

A clearly sequenced 1-5 workflow with explicit validation checkpoints (netstat listener check, ca-probe exit-code semantics, VNC success/fail expectations for :8443 vs :9443), an error-recovery gotchas section, and a cleanup section covering the destructive sandbox and prerelease deletion.

5 / 5

Progressive Disclosure

Well-organized one-level-deep sections and the bundled scripts/ca-probe.js exists and is referenced, but its entire source is duplicated inline instead of loaded from the file, and the shell-quoting gotchas are candidates for a reference file.

4 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has strong, natural trigger coverage with good synonym variety and an explicit 'Use when' clause, and its niche is well-defined. Its main weakness is the 'what' half: it states the validation goal without naming any concrete actions the skill performs.

Suggestions

Replace or augment the bare keyword list with one sentence of concrete actions, e.g. 'Installs a fake corporate CA into the Windows machine store, serves healthy and broken HTTPS control planes, and verifies the app and spawned runtimes use the OS trust path.'

Add missing natural trigger variants users would say: 'fetch failed', 'certificate error', 'cert chain', 'Windows trust store', 'NODE_EXTRA_CA_CERTS'.

Sharpen the 'when' clause to distinguish this from the general daytona skill, e.g. 'Use when validating Windows-specific enterprise TLS or OS-trust behavior; for general Windows sandbox driving use the daytona skill.'

DimensionReasoningScore

Specificity

The description names the domain precisely ('OpenWork Windows enterprise TLS/OS-trust fixes in a Daytona Windows sandbox') and gives one action ('validating'), but omits the actual capabilities (installing a fake corporate CA, serving healthy/broken HTTPS control planes, probing the OS trust path).

3 / 5

Completeness

Both parts are present: an explicit 'when' ('Use when validating OpenWork Windows enterprise TLS/OS-trust fixes...') and a 'what' naming the domain, but the 'what' states the goal rather than concrete actions, keeping it below a 5.

4 / 5

Trigger Term Quality

Includes natural user phrases with synonym coverage ('enterprise CA', 'corporate certificate', 'GPO cert', 'self-hosted cert') and a real error string ('TLS fetch failed'), but misses common variants like 'fetch failed' alone, 'certificate error', or 'trust store'.

4 / 5

Distinctiveness Conflict Risk

The enterprise-CA plus Daytona-Windows combination is a distinct niche, but broad triggers like 'test on Windows', 'Windows sandbox', and 'daytona windows' carry minor overlap risk with a general daytona or Windows-testing skill.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 5 missing, 5 deeper-than-1-level

Warning

Total

15

/

16

Passed

Repository
different-ai/openwork
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.