CtrlK
BlogDocsLog inGet started
Tessl Logo

bash-defensive-patterns

Master defensive Bash programming techniques for production-grade scripts. Use when writing robust shell scripts, CI/CD pipelines, or system utilities requiring fault tolerance and safety.

52

Quality

57%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/bash-defensive-patterns/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, concise SKILL.md body that clearly delimits scope, but it instructs at a purely abstract level — no strict-mode snippet, trap example, or concrete command anywhere — and its only depth comes from a reference to a file that is absent from the bundle. The workflow also lacks validation checkpoints despite the skill's own emphasis on destructive-command safety.

Suggestions

Add a minimal strict-mode block under Instructions, e.g. `set -euo pipefail` plus a `trap 'echo "Error on line $LINENO" >&2' ERR`, so the core defensive pattern is copy-paste ready rather than alluded to.

Fix the dangling reference: either create the playbook file in the bundle (e.g. `references/implementation-playbook.md`) or remove the duplicated pointer and inline the few key patterns it promised.

Insert an explicit validation checkpoint in the workflow (e.g. 'Run the script with `bash -n` to syntax-check before deploying; shellcheck and fix before proceeding') to close the feedback-loop gap for destructive/batch operations.

DimensionReasoningScore

Conciseness

The body is lean with well-scoped sections and no explanations of concepts Claude already knows. Minor trimmable padding exists: the opening paragraph restates the frontmatter description, and "Refer to `resources/implementation-playbook.md` for detailed patterns, checklists, and templates" appears twice (after Safety and again under Resources). Matches anchor 4 ('Efficient; minor instances of over-explanation that could be trimmed'); not 5 because of that duplication and the redundant intro.

4 / 5

Actionability

The Instructions are high-level hints with no executable content: "Enable strict mode and safe defaults from the start", "Validate inputs, quote variables, and handle files safely" — none is backed by code (e.g. `set -euo pipefail`, a `trap` example) or a concrete command. Matches anchor 2 ('Minimal concrete guidance; high-level hints but missing the specific steps to execute'); not 3 because there is not even pseudocode-level concrete guidance, and not 1 because the steps do direct behavior rather than merely describing.

2 / 5

Workflow Clarity

A coherent 4-step sequence exists (confirm environment → strict mode → validate/quote → logging/traps/tests), but there are no validation checkpoints or feedback loops — 'Add logging, error traps, and basic tests' is a step, not a verify-and-retry gate. This matches anchor 3 ('Steps listed but validation gaps; checkpoints missing or implicit'); since the skill explicitly covers destructive operations, the rubric's cap of 3 applies, ruling out 4.

3 / 5

Progressive Disclosure

The skill is under 50 lines with clean section headers, which alone would support a high score, but the single external reference is broken: the bundle contains no `references/`, `scripts/`, or `assets/` directories, so `resources/implementation-playbook.md` — promised as holding 'detailed patterns, checklists, and templates' — does not exist, and the pointer is duplicated. Scored against the actual (empty) bundle structure this sits at anchor 3 ('Some structure but could be better organized; references present but not clearly [usable]'); not 4 because a dangling reference is worse than a minor organization gap.

3 / 5

Total

12

/

20

Passed

Description

65%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit 'Use when' clause and good natural trigger coverage for the bash/CI-CD/system-utility space. Its main weakness is a generic 'what' — 'master defensive programming techniques' names no concrete capabilities, capping specificity and completeness below the top anchors.

Suggestions

Replace the generic capability claim with 2-3 concrete actions, e.g. 'Apply strict mode (set -euo pipefail), error traps, and input validation to Bash scripts' — this would lift both specificity and completeness.

Add a couple of natural user phrasings such as 'script fails mid-run', 'error handling', or '.sh scripts' to round out trigger-term coverage.

DimensionReasoningScore

Specificity

"Master defensive Bash programming techniques for production-grade scripts" names the domain (defensive Bash, production scripts) but every action is generic — no concrete capabilities like strict mode, error traps, or input validation are stated. It matches anchor 2 ('Names the domain but actions are minimal or generic'); it is not 3 because no 1-2 concrete actions are listed, and not 1 because the domain is clearly and specifically named rather than abstract.

2 / 5

Completeness

Both parts are present: what ("Master defensive Bash programming techniques for production-grade scripts") and an explicit when ("Use when writing robust shell scripts, CI/CD pipelines, or system utilities requiring fault tolerance and safety"). Matches anchor 4 ('both what and when; when could be more explicit or specific'); not 5 because the 'what' is generic rather than a list of concrete capabilities with concrete trigger phrases.

4 / 5

Trigger Term Quality

Natural trigger phrases present: "robust shell scripts", "CI/CD pipelines", "system utilities", "fault tolerance", "safety" — terms a user would plausibly say. It fits anchor 4 ('Good keyword coverage; a few natural terms missing'): common variations like "error handling", ".sh", or "script keeps failing" are absent, so it falls short of anchor 5's comprehensive synonym/extension coverage.

4 / 5

Distinctiveness Conflict Risk

The Bash defensive-programming niche is fairly clear and the triggers (robust scripts, CI/CD, fault tolerance) are unlikely to fire for unrelated skills, though it could overlap with a general bash-scripting or code-quality skill. Matches anchor 4 ('Mostly distinct; minor overlap risk with closely related skills'); not 5 because it lacks the sharp, distinctive trigger phrasing of the anchor-5 example.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.