CtrlK
BlogDocsLog inGet started
Tessl Logo

setup-review-sandbox

One-time setup of the sandbox prerequisites used by the reproduce-issue skill and the reproduce-verifier agent — Docker, the isolation runtime (gVisor on Linux / Colima on macOS), healthy container networking, and the nx-review-sandbox toolchain image (built from the repo's mise.toml). Idempotent; re-run any time to verify or repair. Use when the user says "set up the review sandbox", "install the sandbox prereqs", "build the sandbox image", or a reproduce-issue preflight reports something MISSING.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong operational skill: check-first idempotent steps, fully executable commands with per-OS variants, explicit re-checks, error-recovery branches, and a green-criteria smoke test. The only weaknesses are verbosity in section 4's justifications and rationale prose that would sit better in a reference file than the main body.

Suggestions

Trim section 4's war-story justification ('went unnoticed for two weeks, costing ~25 minutes of package downloads on every review') to one sentence — the rule 'build unconditionally; Docker's layer cache already answers the question' stands on its own.

Move the pnpm-store internals (read-only layer, ~2.3 GB copy-up, per-host sharing) and the section 6 security mitigation (store poisoning risk) into a one-level-deep reference file (e.g. references/sandbox-internals.md), keeping only the actionable line in SKILL.md.

State the ✅/❌ reporting requirement from step 5 once in a closing line rather than only inside the smoke-test section, so partial failures of earlier steps are reported in the same format.

DimensionReasoningScore

Conciseness

The body is largely operational facts Claude could not infer (fish shell, BTF-mismatch reboot, minimal build context, read-only store copy-up), but section 4 pads with a war-story justification — 'which is exactly how an image predating the pnpm-store warming went unnoticed for two weeks, costing ~25 minutes' — and a paragraph of copy-up/pnpm-store internals that could be trimmed to their actionable core. Not 5 (some tokens don't earn their place); clearly above 3 (no explanation of concepts Claude already knows).

4 / 5

Actionability

Every step gives copy-paste-ready commands: the runsc detection one-liner, the full gVisor apt/gpg install block, 'sudo modprobe veth', 'bash tools/review-sandbox/build-image.sh', the smoke test with the RUNTIME variable explicitly defined per-OS ('--runtime=runsc on Linux, "" on macOS'), and the exact prune invocations. Common cases and failure cases are both covered.

5 / 5

Workflow Clarity

Six clearly sequenced idempotent steps, each with a check-first command, explicit re-validation ('Then re-check the runtime line above'), error-recovery branches (veth BROKEN → modprobe; BTF mismatch → reboot + persist via /etc/modules-load.d), and a final smoke test with explicit pass criteria ('Green when: the kernel is NOT your host kernel, and node/java/dotnet report versions') and a per-step ✅/❌ reporting requirement.

5 / 5

Progressive Disclosure

The numbered section structure is clean and the ~100-line body needs no bundle files (none exist; referenced paths tools/review-sandbox/build-image.sh and .claude/tools/sandbox are repo tooling, not skill references). But the rationale prose in sections 4 and 6 (the two-week anecdote, the pnpm-store poison mitigation, the host-naming/`--host` explanation) is inline commentary that belongs in a one-level-deep reference. Good structure, minor organization gaps — anchor 4, not 5.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: third person, dense with concrete component names, explicitly idempotent semantics, and an explicit 'Use when' clause quoting the exact natural-language triggers. Every token carries information; nothing is padded or over-claimed.

DimensionReasoningScore

Specificity

The description enumerates concrete, specific components and actions — 'Docker, the isolation runtime (gVisor on Linux / Colima on macOS), healthy container networking, and the nx-review-sandbox toolchain image (built from the repo's mise.toml)' plus 'Idempotent; re-run any time to verify or repair'. Coverage is comprehensive with no vague filler.

5 / 5

Completeness

It explicitly answers both questions: what ('One-time setup of the sandbox prerequisites... Docker... networking... toolchain image; Idempotent; re-run any time to verify or repair') and when ('Use when the user says... or a reproduce-issue preflight reports something MISSING'), with concrete trigger phrases.

5 / 5

Trigger Term Quality

It quotes the natural phrases a user would actually say — 'set up the review sandbox', 'install the sandbox prereqs', 'build the sandbox image' — plus the preflight-MISSING trigger, covering synonyms across command, noun, and verb phrasings. It is not above 5 (nothing missing) and well above 4's 'a few natural terms missing'.

5 / 5

Distinctiveness Conflict Risk

It is scoped to a named niche — prerequisites 'used by the reproduce-issue skill and the reproduce-verifier agent' — with triggers ('review sandbox', 'sandbox prereqs', 'build the sandbox image') that no generic Docker or review skill would claim. Clear niche, minimal conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
nrwl/nx
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.