CtrlK
BlogDocsLog inGet started
Tessl Logo

policy-and-managed-settings

Use whenever adding, modifying, or reviewing any Copilot, agent, LLM, AI, tool, permission, sandbox, MCP, model, telemetry, feature-gate, setting, configuration, or enterprise control—especially anything an organization or administrator may need to manage. Start here to decide whether it belongs in runtime managed settings, a typed SDK contract, VS Code configuration policy, extension policy, or a split implementation. Run on every new Copilot/agent/LLM control and ANY change that adds a `policy:` field.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, mostly lean routing skill that gives concrete guidance and a clear decision flowchart. The main gap is that every referenced guide file is a dangling link with no bundle files provided.

Suggestions

Add the referenced bundle files (sdk-runtime-policy.md, vscode-policy.md, extension-policy.md, mixed-policy.md, legacy-permission-policy.md, github-managed-settings.md, local-testing.md) so the one-level-deep navigation actually resolves.

Add an explicit validation step after `npm run export-policy-data` (e.g., confirm policyData.jsonc regenerated and tests pass) to close the workflow feedback loop.

Tighten the settings-to-managed-settings bridge paragraph, which currently re-explains the compatibility gate rationale at length.

DimensionReasoningScore

Conciseness

The body is lean, assumes Claude's intelligence (no explanation of Copilot/VS Code concepts), and uses a compact flowchart plus bullets, though the settings-to-managed-settings bridge paragraph is dense and could be trimmed.

4 / 5

Actionability

Provides a concrete decision flowchart, an explicit command ('Run `npm run export-policy-data`'), and specific file paths to avoid ('build/lib/policies/policyData.jsonc'), giving mostly executable routing guidance appropriate to an instruction skill.

4 / 5

Workflow Clarity

The mermaid flowchart gives a clear sequenced decision routing and the export-policy-data step acts as a checkpoint, though there is no explicit validate/retry feedback loop after the export.

4 / 5

Progressive Disclosure

A clean overview SKILL.md pointing to well-signaled one-level-deep destination guides plus supporting references; however the referenced files (sdk-runtime-policy.md, vscode-policy.md, etc.) are not present in the bundle, so navigation cannot actually complete.

4 / 5

Total

16

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, trigger-rich description that clearly states both purpose and activation conditions with comprehensive natural keywords. Slightly broad scope is the only meaningful conflict-risk concern.

DimensionReasoningScore

Specificity

Enumerates many concrete control domains (Copilot, agent, LLM, MCP, sandbox, telemetry, feature-gate, etc.) and a concrete routing action across five named destinations, but the action set is largely one decision repeated over many domains rather than distinct concrete actions, so it sits just below the comprehensive anchor.

4 / 5

Completeness

Explicitly answers both what (route the control to runtime managed settings, SDK contract, VS Code policy, extension policy, or split implementation) and when ('Use whenever adding, modifying, or reviewing...' and 'Run on every new...control and ANY change that adds a `policy:` field').

5 / 5

Trigger Term Quality

Comprehensive natural trigger terms including synonyms and specific markers a contributor would actually say ('Copilot', 'agent', 'MCP', 'sandbox', 'permission', 'feature-gate', 'enterprise control', and the explicit `policy:` field).

5 / 5

Distinctiveness Conflict Risk

A clear niche (enterprise/admin-managed Copilot policy controls with a distinctive `policy:` field trigger), but the very broad span of control types (any tool, setting, config, model) creates minor overlap risk with general configuration skills.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 7 missing

Warning

Total

15

/

16

Passed

Repository
posit-dev/positron
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.