CtrlK
BlogDocsLog inGet started
Tessl Logo

nic-code-review

Workflow, guardrails, and output format for reviewing NIC pull requests. Use when reviewing a PR locally (Copilot Chat, Claude, or other agent), when running the pr-review prompt, or when acting as the GitHub Copilot Code Review bot. Delegates codebase-specific detail to the domain skills (nic-structure, nic-add-feature, nic-add-policy, nic-docker-images, nic-ci-pipelines, nic-testing) rather than duplicating them.

70

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An unusually disciplined process skill: the workflow is explicitly sequenced with hard verification checkpoints, the guidance is fully executable with exact commands, paths, and severities, and there is essentially no fluff or over-explanation. Its main structural weakness is that SKILL.md inlines two large codebase-specific verdict/completeness tables that its own delegation principle says should live in the referenced domain skills or in reference files, and no bundle files exist to offload them.

Suggestions

Move the domain-specific rows of the Fixed verdicts table (e.g., telemetry, pytest markers, values.schema.json rows) into the corresponding domain skills (nic-structure, nic-testing, nic-add-feature) or a references/ file, keeping only cross-domain verdicts and the tie-break rules in SKILL.md.

Move the per-area rows of the completeness gate into the referenced domain skills, keeping in SKILL.md only the rule 'run the completeness gate for every area the diff touches' plus a one-line index of which skill owns which gate.

Deduplicate the values.yaml schema guidance (type/shape change vs. new key severity appears three times: Fixed verdicts, Review dimensions, and the completeness gate) into a single authoritative location.

DimensionReasoningScore

Conciseness

The body is dense and assumes competence throughout — it never explains what a PR, NGINX, or CI is, and every line is a concrete rule, path, or verdict (e.g., "Telemetry Data/NICResourceCounts changed without make telemetry-schema -> Blocking"). It misses the 5 anchor because some content is repeated across sections (the values.yaml schema-type-vs-new-key severity appears in Fixed verdicts, Review dimensions, and the completeness gate), and the ~290-line body inlines tables that its own opening paragraph says should live in the domain skills.

4 / 5

Actionability

Fully executable guidance throughout: exact commands ("git diff origin/main...HEAD", "gh pr diff <n>", "make update-codegen", "make test-update-snaps"), exact paths ("pkg/apis/**/types.go", "charts/nginx-ingress/values.schema.json", "validate-workflow-gating.sh"), a copy-paste-ready output format template, and per-row concrete verification requirements. This matches the 'copy-paste ready; specific examples cover the common cases' anchor.

5 / 5

Workflow Clarity

The 9-step "Review workflow" is clearly sequenced with explicit validation checkpoints: a "Verify before flagging" table requiring confirmation before any comment, a "Completeness gate" that must run "before writing anything", and a "Confidence downgrades" error-recovery path telling the reviewer to drop rather than hedge a failing finding. This matches the anchor requiring clear sequence, explicit validation steps, feedback loops, and checklists.

5 / 5

Progressive Disclosure

The body is well-sectioned and clearly signals the six domain skills it delegates to (a dedicated "Cross-reference skill" column), but there are no bundle files at all (no references/, scripts/, or assets/ directories), and large codebase-specific tables — the ~25-row Fixed verdicts table and the 11-row completeness gate — are inlined in SKILL.md despite the opening paragraph stating such detail belongs in the domain skills. That 'content that should be separate is inline' pattern matches the 3 anchor; it is not 4 because the inlined tables are precisely the material the skill claims to delegate, and not 2 because the structure and cross-references that do exist are clearly signaled and one level deep.

3 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concise, and explicit about both what the skill provides and the three concrete contexts in which to invoke it. The only improvement space is adding a couple of natural trigger synonyms (e.g., "review the diff", "review my branch") to widen keyword coverage.

DimensionReasoningScore

Specificity

The description names concrete deliverables — "Workflow, guardrails, and output format for reviewing NIC pull requests" — plus a concrete delegation behavior ("Delegates codebase-specific detail to the domain skills (nic-structure, nic-add-feature, ...)"), which lists several specific capabilities. It falls short of the 5 anchor's comprehensive action list because "workflow, guardrails, output format" are categories of guidance rather than the enumerated concrete actions a fully comprehensive description would show.

4 / 5

Completeness

It explicitly answers both questions: what ("Workflow, guardrails, and output format for reviewing NIC pull requests") and when (an explicit "Use when..." clause with three concrete trigger scenarios: local PR review, pr-review prompt invocation, Copilot Code Review bot). This matches the anchor requiring clear, explicit what AND when with concrete trigger phrases; not the 4 anchor since the 'when' clause is already fully explicit and specific.

5 / 5

Trigger Term Quality

Natural trigger phrases are present: "Use when reviewing a PR locally (Copilot Chat, Claude, or other agent), when running the pr-review prompt, or when acting as the GitHub Copilot Code Review bot." These are phrases a user would actually say, but common variations like "review the diff" or "review my branch" (which the body lists as trigger phrasings) are absent from the description, matching the 'a few natural terms missing' anchor rather than comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

The niche is sharply defined — "NIC pull requests", the "pr-review prompt", and the "GitHub Copilot Code Review bot" are distinct triggers no other skill would claim, and the first sentence binds everything to NIC. It clearly fits the 'clear niche with distinct triggers; minimal conflict risk' anchor; at most it marginally overlaps a generic code-review skill via "reviewing a PR locally", but the NIC scoping keeps conflict minimal.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 2 missing

Warning

Total

15

/

16

Passed

Repository
nginx/kubernetes-ingress
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.