CtrlK
BlogDocsLog inGet started
Tessl Logo

governing-sbx-fleets

Administer Docker Sandbox governance — local versus organization policy, filesystem and network access rules, audit logging, and sign-in enforcement across a fleet of developer machines. Use when creating or scoping an organization policy, diagnosing why an allow rule has no effect, writing filesystem mount rules, configuring audit delivery or SIEM forwarding, or deploying MDM sign-in enforcement. This is the administrator's view; route a single developer's blocked request to diagnosing-sbx-sandboxes instead.

77

Quality

97%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

93%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, expert-level reference that earns its tokens: almost every line is a product-specific rule, trap, or verification command Claude could not infer. Structure and progressive disclosure are exemplary; the only soft spot is that multi-step admin operations are conveyed through prose and tables rather than explicit ordered workflows with checkpoints.

Suggestions

For destructive multi-step operations (applying a filesystem policy change, forcing a policy re-sync with 'sbx policy reset'), present a short ordered sequence with an explicit verify step (e.g., 1. edit policy in Docker Home, 2. wait for sync window, 3. verify with 'sbx policy ls' Sync: line, 4. remove and recreate the sandbox) instead of leaving the sequence implied across prose paragraphs.

For SIEM forwarding setup, a numbered configure-then-verify checklist (configure endpoint, save, then confirm delivery in the Audit Events view) would complement the current prose explanation of what a save failure means.

DimensionReasoningScore

Conciseness

Every paragraph carries a non-obvious, product-specific fact or trap (precedence table, mount-time-only filesystem checks, rotation thresholds, retention windows, reset blast radii) that Claude could not know. There is no explanation of concepts Claude already knows and no padding; time-sensitive material (dates, v0.35.0/v0.38.0 gates) is quarantined in a dedicated 'Last verified' section rather than scattered.

5 / 5

Actionability

Concrete, copy-ready commands throughout: 'sbx policy ls --include-inactive', 'sbx policy check network <host>', 'sbx policy init {allow-all|balanced|deny-all}', '--deny-network <host>', plus exact UI paths (AI Platform > Audit logs > Audit Delivery) and exact SIEM config requirements (HEC endpoint + token, 'logs.ingest' scope). As an instruction/config skill, guidance is fully actionable without code examples.

5 / 5

Workflow Clarity

Diagnostic flows are well sequenced with verification commands ('sbx policy ls' as source of truth, the 'Sync:' line, 'sbx policy check network <host>', 'save failure means connectivity or credentials') and destructive commands carry explicit blast-radius warnings. However, multi-step operations like applying a filesystem policy change or deploying sign-in enforcement are described in prose rather than as ordered sequences with explicit checkpoints — the deploy sequence is delegated to the reference file.

4 / 5

Progressive Disclosure

Clear overview structure with two well-signaled, one-level-deep references that both exist in the bundle ('Full field-by-field schema... in references/audit-record-schema.md'; 'Per-platform deployment payloads... in references/sign-in-enforcement-deploy.md'), each annotated with what it contains and a trap warning up front. Detail payloads are appropriately split out; no nested references.

5 / 5

Total

19

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete third-person actions, an explicit multi-scenario 'Use when' clause, natural trigger terms across all four governance domains, and explicit boundary routing to sibling skills. Every anchor lands at the top level.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions with comprehensive coverage: 'creating or scoping an organization policy', 'diagnosing why an allow rule has no effect', 'writing filesystem mount rules', 'configuring audit delivery or SIEM forwarding', and 'deploying MDM sign-in enforcement'. It names every sub-domain the skill covers (local vs org policy, filesystem, network, audit, sign-in) in third-person voice with no filler.

5 / 5

Completeness

It explicitly answers both questions: the first sentence states what the skill does ('Administer Docker Sandbox governance...'), and the second gives a concrete 'Use when' clause with five specific trigger scenarios. This matches the anchor example structure exactly.

5 / 5

Trigger Term Quality

Natural admin phrasings cover all four sub-domains: 'organization policy', 'allow rule has no effect', 'filesystem mount rules', 'audit delivery or SIEM forwarding', 'MDM sign-in enforcement', plus the common complaint 'diagnosing why an allow rule has no effect'. These mirror what an administrator would actually say, including synonyms (audit delivery/SIEM forwarding).

5 / 5

Distinctiveness Conflict Risk

The description carves a clear niche ('the administrator's view') and actively routes the wrong audience away: 'route a single developer's blocked request to diagnosing-sbx-sandboxes instead'. Combined with distinct governance-specific triggers, conflict risk with adjacent skills is minimal.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
slurpyb/sbx-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.