CtrlK
BlogDocsLog inGet started
Tessl Logo

drift-detector

Detect infrastructure drift between Terraform state and actual cloud resources. Identifies unmanaged resources, manual changes, and configuration drift. Use when: - User asks to check for infrastructure drift - User wants to find unmanaged cloud resources - User mentions "drift detection" or "Terraform drift" - User asks to compare cloud state to IaC - User wants to audit infrastructure changes

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./command_directives/synchronous_remediation/skills/drift-detector/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, well-sequenced operational runbook with excellent CLI coverage, held back by two structural problems: destructive remediation steps lack validation/feedback loops, and progressive disclosure is broken — two referenced files are missing from the bundle and the one shipped reference file is orphaned. Fixing the bundle layout and adding pre/post-remediation verification would lift the weakest dimensions substantially.

Suggestions

Add validation checkpoints around destructive remediation: before Step 4.2 require an explicit confirmation and a filtered re-scan of the specific resources to delete, and after Steps 4.1-4.4 re-run `snyk iac describe` to verify drift is resolved before declaring success.

Reconcile the bundle with the body: either add the referenced SERVICES.md and EXAMPLES.md files or remove/inline those pointers, and link the existing references/drift-remediation.md from Phase 4 instead of duplicating its import/delete decision guidance inline.

Trim the redundancy: drop the body 'Note' that repeats the frontmatter compatibility block, and merge the Constraints section with Prerequisites to remove the overlap.

DimensionReasoningScore

Conciseness

The body is dominated by executable commands, tables, and tight step blocks with almost no explanation of concepts Claude already knows. Minor trimming is possible: the body "Note" duplicates the frontmatter compatibility text, "Core Principle: Your cloud should match your code" is filler, and the Constraints section repeats Prerequisites — efficient with minor over-explanation, i.e. anchor 4 rather than 5.

4 / 5

Actionability

Guidance is copy-paste ready throughout: exact CLI invocations with flags (`snyk iac describe --from=tfstate+s3://... --service=aws_s3,aws_ec2,aws_rds --json`), executable credential checks per provider, a complete Terraform `import` block, and a runnable GitHub Actions snippet. The specific examples cover the common cases (local state, S3 remote, TFC, service filtering, JSON output), matching the top anchor.

5 / 5

Workflow Clarity

The five phases are clearly sequenced with per-phase goals and an error-handling section, but Phase 4 performs destructive operations (`aws s3 rb s3://unauthorized-bucket --force`, `aws ec2 terminate-instances`) with no validation checkpoint or feedback loop — only an implicit "After verification" comment. Per the rubric, destructive workflows missing validation/verification cap this dimension at 3; it is not a 2 because the sequence itself is coherent and gaps are confined to the remediation phase.

3 / 5

Progressive Disclosure

Scored against the actual bundle: the body signals "see `SERVICES.md`" and "see `EXAMPLES.md`", but neither file exists in the bundle, while the one provided file (references/drift-remediation.md) is never referenced and duplicates the import/delete guidance already inlined in Phase 4. Navigation outward is broken and content that belongs in the reference file is inlined, matching anchor 2; it is not a 3 because two of the skill's three external pointers resolve to nothing.

2 / 5

Total

14

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, concrete capabilities, and an explicit multi-item 'Use when' trigger list with good synonym coverage. The only weaknesses are mild overlap risk from the generic 'audit' trigger and an action list that restates one capability rather than enumerating distinct functions.

DimensionReasoningScore

Specificity

"Detect infrastructure drift between Terraform state and actual cloud resources. Identifies unmanaged resources, manual changes, and configuration drift" lists several concrete, domain-anchored actions (detect, identify unmanaged/changed/missing resources). It falls short of a 5 because the listed actions are variations of one capability rather than the comprehensive, distinct action set (e.g. detect/extract/fill/merge) of the top anchor.

4 / 5

Completeness

It explicitly answers both questions: the 'what' is stated concretely up front ("Detect infrastructure drift... Identifies unmanaged resources, manual changes, and configuration drift") and the 'when' is an explicit "Use when:" list with five concrete trigger conditions, matching the top anchor exactly.

5 / 5

Trigger Term Quality

The 'Use when' list covers natural phrasings and synonyms comprehensively: "check for infrastructure drift", "find unmanaged cloud resources", "drift detection", "Terraform drift", "compare cloud state to IaC", "audit infrastructure changes". These are the phrases a user would naturally say; it is not a 4 because no obviously common variation is missing.

5 / 5

Distinctiveness Conflict Risk

The Terraform/IaC drift niche is clear and most triggers ("drift detection", "Terraform drift", "unmanaged cloud resources") are distinct. It is not a 5 because broader triggers like "User wants to audit infrastructure changes" and "compare cloud state to IaC" could overlap with general Terraform or security-audit skills.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.