CtrlK
BlogDocsLog inGet started
Tessl Logo

apply-native-policy-to-instance

Apply, list, or edit provider-native policies on API instances (Kong plugin, Apigee template, Azure policy, or MuleSoft/Anypoint) via the MuleSoft Platform MCP Server. TRIGGER when: the user asks what protection they have on a provider's APIs ("what protection do I have for my Apigee APIs"), wants to change an already-applied native policy ("improve the IP filtering to include 1.1.1.1"), or apply one native plugin to an already-chosen instance ("add ip-restriction on this Kong service"). DO NOT TRIGGER when: they want one Universal/canonical policy across many instances or providers — use skill apply-universal-policy. DO NOT TRIGGER to remove, detach, enable, or disable a policy, or when they are driving Anypoint REST (skill apply-policy-to-api-instance).

77

Quality

96%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured instruction skill: concrete tool/parameter guidance, explicit routing and gating, and one-level-deep references to a real bundle file. The only friction is mild repetition of the completion-checking guidance across several sections.

Suggestions

Consolidate the 'status: success + HTTP 202 is acceptance, not done — poll list_instance_policy_operations' guidance into one place (e.g. Step 5 / Reference file) and back-reference it instead of restating it in Rules, Best Practices, and Troubleshooting.

Merge the repeated 'confirm the native-policy → API+instance mapping then wait for yes' reminders into the Rules section with light cross-references to avoid restating the gate in Steps 3, E, and Best Practices.

DimensionReasoningScore

Conciseness

Dense and largely free of concepts Claude already knows, but the completion/202-acceptance reminder (Rules 5, Step 5, Best Practices, Troubleshooting) and the confirm-mapping reminder recur several times and could be consolidated.

4 / 5

Actionability

Names exact tools (find_assets, prepare_policy_creation, get_policy_template_form, apply_policy_to_instance, edit_applied_policy) with their precise parameters and field-level guidance (Apigee @-prefixed attributes, @name immutability), covering the common audit/edit/apply cases.

5 / 5

Workflow Clarity

A routing table splits Audit/Edit/Apply paths, with explicit [GATE] confirm checkpoints and feedback loops (poll list_instance_policy_operations, handle FAILED error.retryable, re-read schema on 422) — strong sequencing for batch write operations.

5 / 5

Progressive Disclosure

Body is an overview that signals one-level-deep references — the "Reference files" block plus inline "See references/native-apply.md" cues — and native-apply.md exists in ./references/, so navigation is clean and shallow.

5 / 5

Total

19

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A tight, third-person description that states concrete actions, gives natural-language trigger phrases, and draws explicit negative boundaries against sibling skills. It is both comprehensive and distinguishable, with no vague fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "Apply, list, or edit provider-native policies on API instances (Kong plugin, Apigee template, Azure policy, or MuleSoft/Anypoint)" — with comprehensive coverage of the four provider surfaces.

5 / 5

Completeness

Explicitly answers both what (apply/list/edit native policies on instances via the MuleSoft Platform MCP Server) and when via concrete TRIGGER and DO NOT TRIGGER clauses with example trigger phrases.

5 / 5

Trigger Term Quality

Quotes natural user phrases verbatim ("what protection do I have for my Apigee APIs", "improve the IP filtering to include 1.1.1.1", "add ip-restriction on this Kong service") plus keyword synonyms across all providers.

5 / 5

Distinctiveness Conflict Risk

Clear niche (native per-instance policies over MCP) with explicit negative boundaries redirecting to apply-universal-policy and apply-policy-to-api-instance, minimizing wrong-skill triggering.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
mulesoft/mulesoft-dx
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.