CtrlK
BlogDocsLog inGet started
Tessl Logo

plano-deployment-security

Apply Plano deployment and production security practices. Use for Docker networking, state storage choices, readiness checks, and environment-based secret handling.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/plano-deployment-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is admirably lean and the checklist is well sequenced with an explicit health-check checkpoint, but it falls short on actionability and progressive disclosure: the three "Apply These Rules" entries point to rule content that does not exist in the bundle, and the instructions lack the concrete commands or configuration needed to actually execute the steps.

Suggestions

Resolve the dangling rule references: either inline the actual `deploy-docker`, `deploy-state`, and `deploy-health` rule content (or a one-line summary of each) or ship them as real files under references/ and link to them by path.

Add executable specifics to the checklist — e.g., the PostgreSQL connection setting/env var for state storage, a sample environment-based secret configuration, and the exact command or assertion used to check `/healthz`.

Add a failure-recovery step after the `/healthz` verification (what to inspect and retry when the check fails) to close the feedback loop the diagnostics step implies.

DimensionReasoningScore

Conciseness

The body is ~25 lean lines of pure directives ("Use `host.docker.internal` for host-side services from inside Plano container", "Prefer PostgreSQL state storage for production multi-turn workloads") with zero padding and no explanation of concepts Claude already knows. Matches the anchor "Lean and efficient; assumes Claude's competence; every token earns its place"; there is nothing to trim and no over-explanation to demote it.

5 / 5

Actionability

Items name concrete values (`host.docker.internal`, PostgreSQL, `/healthz`) but stop short of executable guidance — no commands, config snippets, env var names, or connection settings for PostgreSQL state or secret handling. Additionally, "Apply These Rules: `deploy-docker`, `deploy-state`, `deploy-health`" points to rule content that does not exist anywhere in the bundle. This is "some concrete guidance but incomplete; missing key details" rather than "mostly executable".

3 / 5

Workflow Clarity

The numbered Execution Checklist gives a clear sequence with an explicit checkpoint ("Verify `/healthz` before traffic or CI assertions") and a diagnostics step ("Return deployment checks with failure-mode diagnostics"). Not 5 because there is no error-recovery loop (what to do when the health check fails) and the referenced rules inject undefined steps into the sequence; not 3 because a checkpoint is explicitly present, not implicit.

4 / 5

Progressive Disclosure

Sections (When To Use, Apply These Rules, Execution Checklist) are well organized for a short skill, but the body references `deploy-docker`, `deploy-state`, and `deploy-health` rules and no references/, scripts/, or assets/ directories or rule files exist in the bundle — the references are dangling with no resolvable path. This lands at "some structure but could be better organized; references present but not clearly signaled" rather than 4, since the primary navigation to the actual rule content is broken.

3 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit "Use for" trigger clause, specific practice areas, and a distinctive Plano-scoped niche. The main gap is that the "what" statement is generic ("apply practices") and a few natural synonyms (e.g., health checks, secrets, hardening) are absent.

DimensionReasoningScore

Specificity

"Apply Plano deployment and production security practices. Use for Docker networking, state storage choices, readiness checks, and environment-based secret handling" names the domain and several concrete practice areas. Not 5 because the actions are application areas rather than distinct concrete actions (anchor-5 example lists discrete operations like "extract text... fill forms... merge documents"); not 3 because coverage goes well beyond 1-2 actions.

4 / 5

Completeness

Both parts are present: a "what" ("Apply Plano deployment and production security practices") and an explicit "when" clause ("Use for Docker networking, state storage choices, readiness checks, and environment-based secret handling"). Not 5 because the "what" is generic ("apply practices") compared to the anchor-5 example, which pairs concrete actions with explicit trigger phrases; not 3 because the "when" is explicit, not merely implied.

4 / 5

Trigger Term Quality

Terms like "Docker networking", "state storage", "readiness checks", and "environment-based secret handling" are phrases users would naturally say when needing this skill. Not 5 because common synonyms such as "health checks", "production hardening", "Postgres", or "secrets" are missing; not 3 because coverage of natural terms is good, not just partial.

4 / 5

Distinctiveness Conflict Risk

Scoping to "Plano" deployment gives it a clear niche unlikely to trigger for unrelated skills. Not 5 because the trigger terms themselves (Docker networking, state storage, readiness checks, secret handling) are generic deployment vocabulary that overlaps with general Docker/ops skills; not 3 because the Plano anchoring makes significant overlap unlikely.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
katanemo/plano
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.