CtrlK
BlogDocsLog inGet started
Tessl Logo

gitops-repo-audit

Audit and validate Flux CD GitOps repositories by scanning local repo files (not live clusters) — runs Kubernetes schema validation, detects deprecated Flux APIs, reviews RBAC/multi-tenancy/secrets management, and produces a prioritized GitOps report. Use when users ask to audit, analyze, validate, review, or security-check a GitOps repo.

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-architected auditor skill with executable commands, a clear phased workflow, and exemplary progressive disclosure to real bundle files. The main gaps are minor: some trimmable prose and an implicit rather than explicit validation-recovery loop.

Suggestions

Add an explicit feedback loop to Phase 2: if validate.sh exits non-zero with invalid resources, instruct Claude to fix the offending manifests and re-run validation until it exits 0 before proceeding to later phases.

Tighten the Phase 4/5 bulleted 'Has X? Check Y' lists by moving repeated rationale into the referenced checklists, keeping SKILL.md focused on the trigger conditions and concrete checks.

In Phase 4, make the field-index verification step a numbered sub-step with an example grep-and-cite pattern so Claude consistently cites raw-file line numbers alongside rendered-bundle findings.

DimensionReasoningScore

Conciseness

The body is dense with Flux-specific operational knowledge Claude would not reliably know (e.g. the reconcile.fluxcd.io/watch label, substituteFrom namespace rules, ResourceSet Job annotations) and avoids explaining basics, but a few prose passages could be trimmed.

4 / 5

Actionability

Provides copy-paste-ready commands (discover.sh, validate.sh with mktemp and ${bundle:+-b} handling, check-deprecated.sh) plus concrete grep examples against the field index, covering the common audit cases.

5 / 5

Workflow Clarity

A clearly sequenced six-phase workflow with explicit validation scripts and a dotenv rerun feedback loop, but it stops short of an explicit 'fix manifests and re-run validate.sh until exit 0' recovery loop.

4 / 5

Progressive Disclosure

SKILL.md is an overview pointing to six one-level-deep reference files, three scripts, and a CRD table linking nineteen verified field-index files, all clearly signaled with markdown links and a 'Loading References' navigation section.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that explicitly answers what the skill does and when to use it, with concrete actions and a clear Flux CD GitOps niche. Trigger-term coverage is good but could add a few synonyms to reach the top anchor.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'scanning local repo files', 'runs Kubernetes schema validation', 'detects deprecated Flux APIs', 'reviews RBAC/multi-tenancy/secrets management', 'produces a prioritized GitOps report' — giving comprehensive coverage of what the skill does.

5 / 5

Completeness

Clearly states both the 'what' (audit/validate Flux CD GitOps repos) and an explicit 'Use when users ask to...' trigger clause with concrete trigger phrases.

5 / 5

Trigger Term Quality

Includes natural user-facing verbs ('audit, analyze, validate, review, or security-check') plus 'GitOps repo', but lacks synonyms or file extensions that would push it to comprehensive coverage.

4 / 5

Distinctiveness Conflict Risk

The 'Flux CD GitOps repositories... scanning local repo files (not live clusters)' framing carves a clear niche with distinct triggers and minimal overlap with other skills.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 19 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 20 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
fluxcd/agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.