CtrlK
BlogDocsLog inGet started
Tessl Logo

nic-add-policy

Step-by-step checklist for adding a new Policy CRD type to NIC. Use when implementing a new policy like AccessControl, RateLimit, JWTAuth, ExternalAuth, BasicAuth, IngressMTLS, EgressMTLS, OIDC, WAF, APIKey, Cache, or CORS, or extending the policy system with a new policy type.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally dense, executable checklist: every step names the file to edit, the code to add, and the regeneration command, with explicit ordering, per-edition snapshot validation, and a failure-mode gotchas section. The only structural improvement is moving the two code-pattern blocks into a references/ file to slim the main body.

DimensionReasoningScore

Conciseness

Every line carries non-obvious, project-specific knowledge — exact file paths, make targets, JSON-tag casing conventions, the crds symlink, Plus-vs-OSS template rules. There is no explanation of concepts Claude already knows and no padding to trim, matching the 5 anchor.

5 / 5

Actionability

Concrete commands ('make update-codegen', 'make test-update-snaps', "git diff -- '**/__snapshots__/**'"), exact function signatures, and a copy-paste-ready Go add*Config() pattern with real secret-resolution logic. The guidance is fully executable against the actual codebase, matching the 5 anchor.

5 / 5

Workflow Clarity

The 13 steps are explicitly ordered ('Follow these steps IN ORDER. Each step depends on the previous'), with validation checkpoints in Step 10 (regenerate snapshots, inspect the golden-file diff per edition, run 'make test', commit) and a Gotchas section covering failure modes and recovery. This matches the 5 anchor's sequence, explicit validation, and feedback loops.

5 / 5

Progressive Disclosure

Well-organized single file with clear step, Gotchas, and Pattern sections, but at ~185 lines the two full code-pattern sections (add*Config() and NGINX template) are inlined rather than split into reference files, and no bundle files are used. This matches anchor 4 ('good structure; most content appropriately placed; minor organization gaps') better than 5.

4 / 5

Total

19

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit 'Use when...' clause and concrete policy-name triggers that make activation reliable. The only meaningful gap is that it states a single capability (add a policy type) rather than enumerating what the checklist covers, and 'NIC' is not spelled out for users who say 'NGINX Ingress Controller'.

DimensionReasoningScore

Specificity

The description names the domain and one concrete capability ('Step-by-step checklist for adding a new Policy CRD type to NIC') but does not list several distinct actions, matching anchor 3. It is not 4 because the multi-step mechanics (CRD definition, config generation, templates) are absent from the description itself.

3 / 5

Completeness

It explicitly answers both questions: 'what' ('Step-by-step checklist for adding a new Policy CRD type to NIC') and 'when' ('Use when implementing a new policy like... or extending the policy system') with concrete trigger phrases. This matches the 5 anchor exactly; the 'when' clause is already specific, so 4 would underrate it.

5 / 5

Trigger Term Quality

'Use when implementing a new policy like AccessControl, RateLimit, JWTAuth, ExternalAuth, BasicAuth, IngressMTLS, EgressMTLS, OIDC, WAF, APIKey, Cache, or CORS' provides good natural keyword coverage users would actually say. It falls short of 5 only because 'NIC' is internal jargon without the spelled-out 'NGINX Ingress Controller' synonym.

4 / 5

Distinctiveness Conflict Risk

A clear niche (the NIC policy CRD system) with distinct, enumerated policy-type triggers; it would not plausibly fire for an unrelated skill. Minimal conflict risk, matching the 5 anchor.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
nginx/kubernetes-ingress
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.