CtrlK
BlogDocsLog inGet started
Tessl Logo

deployment-infrastructure

Configures deployment pipelines, manages environment variables, schedules cron jobs, applies security headers, implements caching strategies. Use when working with Docker, Vercel, AWS, Dockerfile, nginx.conf, or platform deployment configs.

71

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, highly actionable body with exact cache-header values, a cron auth check, an ordered CI pipeline, and a validated release/rollback loop with re-verification. Its one real defect is structural: the primary detail file it defers to (.opencastle/stack/deployment-config.md) is absent from the bundle, so the promised full architecture, env vars, and cron jobs are unreachable.

Suggestions

Ship the referenced file or inline its content: either add .opencastle/stack/deployment-config.md to the bundle (e.g., under references/) or inline the actual env-var inventory and cron-job definitions that the body currently promises there.

Resolve or drop the security-headers pointer: if the security-hardening skill is a real companion bundle, reference it by its actual path/name; otherwise inline the minimal CSP/header set needed to act without it.

Consider folding a few natural trigger phrasings (CI/CD, GitHub Actions, deploy) into the description's 'Use when' clause to round out trigger-term coverage.

DimensionReasoningScore

Conciseness

Every line is a directive or spec — env precedence chain, Zod-at-startup rule, "install (always --frozen-lockfile in CI)", exact Cache-Control values, the curl verification one-liner. No concept explanations, no padding; assumes Claude's competence. Matches the lean anchor-5 example.

5 / 5

Actionability

Mostly executable: exact header values in a table, "return 401 unless the authorization header equals Bearer ${process.env.CRON_SECRET}", "curl -sI https://example.com | grep -E 'HTTP|Strict'", and a concrete rollback preference (platform promote over "git revert -m 1 HEAD && git push"). Not 5 because "full architecture, env vars, cron jobs, caching headers" and the CSP inventory are deferred to references, leaving the actual env-var list and cron-job definitions absent from the body.

4 / 5

Workflow Clarity

CI stages are explicitly ordered ("install → lint → test → production build → deploy"), the release gate is a checklist ("lint + test + build all exiting 0 and no draft PRs"), and rollback is a feedback loop ("rolled back immediately, not patched forward... re-run the curl -sI check before calling it resolved"). Destructive release/rollback operations do have validation and re-verification, so the cap does not apply.

5 / 5

Progressive Disclosure

Sections are well organized and the body is short, but the two deferral pointers are unresolvable: ".opencastle/stack/deployment-config.md" — the designated home for "full architecture, env vars, cron jobs, caching headers" — does not exist in the bundle (no references/, scripts/, or assets/ directories), and the **security-hardening** skill reference is external/unverifiable. Matches anchor 3 (references present but the organization leaves deferred content inaccessible); not 4 because a signaled-but-missing reference is a real navigation failure, not a minor gap.

3 / 5

Total

17

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete, comprehensive, third-person, with an explicit 'Use when...' trigger clause naming platforms and config files. Main weakness is trigger coverage that omits common phrasings like CI/CD and GitHub Actions, plus minor overlap risk with a security-focused sibling skill.

DimensionReasoningScore

Specificity

Five concrete verb+object actions — "Configures deployment pipelines, manages environment variables, schedules cron jobs, applies security headers, implements caching strategies" — comprehensively cover the skill's domain at the same concreteness as the anchor-5 example. Not 4 because no material coverage gap is evident relative to the body's topics.

5 / 5

Completeness

Explicitly answers both questions: the "what" is the five named actions and the "when" is the "Use when working with..." clause with concrete trigger terms. Matches the anchor-5 example structure exactly.

5 / 5

Trigger Term Quality

"Use when working with Docker, Vercel, AWS, Dockerfile, nginx.conf, or platform deployment configs" gives good coverage including concrete file names, but misses natural variations like "CI/CD", "GitHub Actions", "deploy", or "environment variables". Not 5 because synonym coverage is incomplete; not 3 because the included terms are ones users actually say.

4 / 5

Distinctiveness Conflict Risk

Platform-specific triggers (Docker, Vercel, AWS, Dockerfile, nginx.conf) carve out a mostly distinct niche, but "applies security headers" overlaps with a closely related security-hardening domain the body itself defers to. Not 5 due to that overlap risk; not 3 since the infra triggers are specific.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
monkilabs/opencastle
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.