CtrlK
BlogDocsLog inGet started
Tessl Logo

governing-sbx-fleets

Administer Docker Sandbox governance — local versus organization policy, filesystem and network access rules, audit logging, and sign-in enforcement across a fleet of developer machines. Use when creating or scoping an organization policy, diagnosing why an allow rule has no effect, writing filesystem mount rules, configuring audit delivery or SIEM forwarding, or deploying MDM sign-in enforcement. This is the administrator's view; route a single developer's blocked request to diagnosing-sbx-sandboxes instead.

75

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

93%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A high-quality, expert-oriented reference skill: concise, densely actionable, and well-structured with correctly linked one-level-deep references. The only gap is the absence of an explicit validation feedback loop around the destructive reset commands.

DimensionReasoningScore

Conciseness

Lean and dense with no padding or re-explanation of known concepts; every paragraph carries a non-obvious rule or trap, and version-gated/time-sensitive details are isolated in a 'Last verified' section rather than inflating the body.

5 / 5

Actionability

Provides concrete, copy-paste-ready commands throughout (sbx policy ls/inspect/check/reset/init, allow|deny with --source/--decision/--include-inactive/--wide, --deny-network) plus specific Docker Home navigation paths covering the common admin cases.

5 / 5

Workflow Clarity

Diagnostic flows include real checkpoints (verify licensing/enforcement before debugging the pipeline, 'sbx policy ls' as source of truth, propagation timing) and clearly flag the blast radius of destructive commands, but lack an explicit validate-fix-retry loop for the destructive reset operations.

4 / 5

Progressive Disclosure

SKILL.md is a well-organized overview with two real, one-level-deep references (audit-record-schema.md, sign-in-enforcement-deploy.md) clearly signaled via markdown links, each previewed with what it contains; heavy deployment payloads and the full schema are appropriately split out.

5 / 5

Total

19

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete administrative actions and provides explicit 'Use when' trigger guidance with clear routing to distinguish it from the developer-facing skill. Only minor room to broaden trigger-term synonyms.

DimensionReasoningScore

Specificity

Lists multiple concrete admin actions — 'creating or scoping an organization policy, diagnosing why an allow rule has no effect, writing filesystem mount rules, configuring audit delivery or SIEM forwarding, or deploying MDM sign-in enforcement' — with comprehensive coverage across governance domains.

5 / 5

Completeness

Explicitly answers both what ('Administer Docker Sandbox governance ... across a fleet of developer machines') and when via a concrete 'Use when ...' clause enumerating triggering scenarios.

5 / 5

Trigger Term Quality

Strong natural keyword coverage ('allow rule has no effect', 'filesystem mount rules', 'audit delivery', 'SIEM forwarding', 'MDM sign-in enforcement') that admins would actually say, with only a few synonyms missing.

4 / 5

Distinctiveness Conflict Risk

Clear admin-fleet niche that explicitly scopes out the developer view ('route a single developer's blocked request to diagnosing-sbx-sandboxes instead') and MCP, giving minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
slurpyb/sbx-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.