CtrlK
BlogDocsLog inGet started
Tessl Logo

aegisops-ai

Autonomous DevSecOps & FinOps Guardrails. Orchestrates Gemini 3 Flash to audit Linux Kernel patches, Terraform cost drifts, and K8s compliance.

25

Quality

16%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

—

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./skills/aegisops-ai/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

0%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill reads like a project README or marketing document rather than an actionable skill for Claude. It extensively describes what AegisOps-AI does conceptually but provides virtually no concrete guidance on how to actually perform any of the three audit tasks. The content is padded with explanations of well-known concepts, emoji-laden headers, and problem/solution narratives that consume tokens without adding actionable value.

Suggestions

Replace the descriptive problem/solution sections with concrete, executable examples for each module—show actual command invocations with sample inputs and expected output formats (e.g., `python3 patch_analyzer.py --diff kernel_patch.diff` with example JSON output).

Add clear step-by-step workflows for each audit type with explicit validation checkpoints (e.g., 'verify the diff file exists and contains C code before running the analyzer; check analysis_results.json for CRITICAL findings before proceeding').

Remove all explanatory content Claude already knows (what UAF is, what Terraform does, what least privilege means) and the 'Generative AI Integration' marketing section—focus exclusively on how to invoke and interpret results.

Provide example inputs and outputs for each module so Claude knows exactly what format to pass in and what to expect back (e.g., a sample Git diff snippet and the corresponding analysis_results.json structure).

DimensionReasoningScore

Conciseness

The content is highly verbose, explaining concepts Claude already knows (what UAF is, what Terraform does, what Kubernetes security contexts are, what IaC is). Sections like 'Generative AI Integration' and problem/solution descriptions for each module are padded with marketing-style language that adds no actionable value. Emoji headers and repeated explanations of the same concepts waste tokens.

1 / 3

Actionability

Despite describing three core modules (patch_analyzer.py, cost_auditor.py, k8s_policy_generator.py), the skill provides no concrete usage examples, no actual commands to invoke individual modules, no example inputs/outputs, and no executable code beyond basic setup commands. The guidance is entirely descriptive rather than instructive—Claude wouldn't know how to actually use any of these tools.

1 / 3

Workflow Clarity

There is no clear multi-step workflow for any of the three audit processes. The skill describes what each module does conceptually but never sequences the steps for performing an actual audit. There are no validation checkpoints, no error handling guidance, and no feedback loops for when audits fail or produce unexpected results.

1 / 3

Progressive Disclosure

The content is a monolithic wall of text with no references to supporting files despite mentioning three separate Python modules. No bundle files are provided, and the skill doesn't reference any detailed documentation for the individual modules. The content that is present is all high-level description without any layered structure for deeper exploration.

1 / 3

Total

4

/

12

Passed

Description

32%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is buzzword-heavy and lacks a clear 'Use when...' clause, making it difficult for Claude to know when to select this skill. While it names specific technologies (Terraform, K8s, Linux Kernel), the actual actions are vague ('orchestrates', 'audit'), and the reference to 'Gemini 3 Flash' is confusing in a Claude skill context. The description would benefit significantly from concrete action verbs, natural trigger terms, and explicit usage guidance.

Suggestions

Add an explicit 'Use when...' clause with natural trigger terms, e.g., 'Use when the user asks about Kubernetes compliance checks, Terraform cost analysis, or Linux kernel patch security reviews.'

Replace buzzwords like 'DevSecOps & FinOps Guardrails' and 'Orchestrates Gemini 3 Flash' with concrete actions and outputs, e.g., 'Scans Linux kernel patches for security vulnerabilities, detects Terraform cost drift and estimates budget impact, validates Kubernetes configurations against compliance policies.'

Include common keyword variations users would naturally say, such as 'Kubernetes' (not just 'K8s'), 'infrastructure costs', 'security audit', 'patch review', and 'policy compliance'.

DimensionReasoningScore

Specificity

Names specific domains (Linux Kernel patches, Terraform cost drifts, K8s compliance) and some actions (audit, orchestrate), but the actions themselves are vague — 'orchestrates' and 'audit' don't describe concrete steps or outputs. The buzzword-heavy framing ('DevSecOps & FinOps Guardrails') reduces clarity.

2 / 3

Completeness

Provides a partial 'what' (audit patches, cost drifts, compliance) but completely lacks a 'when' clause — there is no 'Use when...' or equivalent explicit trigger guidance. Per rubric guidelines, a missing 'Use when...' clause should cap completeness at 2, and since the 'what' is also vague and buzzword-laden, this scores a 1.

1 / 3

Trigger Term Quality

Includes some relevant technical keywords (Terraform, K8s, Linux Kernel, cost drifts, compliance) that users might mention, but terms like 'DevSecOps', 'FinOps Guardrails', and 'Gemini 3 Flash' are jargon-heavy and not natural trigger terms a user would typically say. Missing common variations like 'Kubernetes', 'infrastructure cost', 'security audit', 'patch review'.

2 / 3

Distinctiveness Conflict Risk

The combination of Linux Kernel patches, Terraform cost drifts, and K8s compliance is fairly specific, but the broad umbrella terms 'DevSecOps' and 'FinOps' could overlap with other security, infrastructure, or cost-management skills. The mention of 'Gemini 3 Flash' is oddly specific to a non-Claude tool, which is distinctive but potentially confusing.

2 / 3

Total

7

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.