CtrlK
BlogDocsLog inGet started
Tessl Logo

ssh-doctor

SSH triage: Remote Login, launchd sshd, pre-auth closes, stale sessions.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/ssh-doctor/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exemplary lean, command-first triage runbook: fully executable bash, explicit branch conditions, safety rules, and validation around the destructive stale-session kill. Its only weaknesses are an implicit rather than explicit step sequence (no post-fix SSH re-test) and a tangential OP Profile Block section that inflates the single-file footprint.

DimensionReasoningScore

Conciseness

The body is almost entirely terse directives and executable commands with no explanation of SSH or macOS basics Claude already knows; the single explanatory line ('This means launchd accepted TCP but refused to spawn more sshd inetd copies.') captures non-obvious domain insight. Every token earns its place, matching the 'lean and efficient' anchor.

5 / 5

Actionability

Every section provides copy-paste-ready bash (e.g. 'ssh -o RequestTTY=no -o RemoteCommand=none HOST '\''hostname; id -un'\'', the launchctl inspect/kickstart commands, and the marker-checked awk presence test), covering the common cases. Fully executable throughout.

5 / 5

Workflow Clarity

The triage flow has clear branch logic ('Validate locally first: loopback failure means server-side sshd/launchd/config; loopback success plus remote failure means network/firewall/filter/listen path'; 'Only after loopback works but remote fails') and validation around the destructive batch kill (inspect-first, post-TERM ps re-check, 're-check ownership ... before using KILL'), so the destructive-operation cap does not apply. Falls short of 5 because the sequence is implied by section order rather than explicit checkpoints or feedback loops (e.g. no re-test of SSH after clearing stale sessions).

4 / 5

Progressive Disclosure

No bundle files exist; the skill is a self-contained, well-organized single file with clear section headers, and the core diagnostic commands belong inline. Minor gap: the niche 'OP Profile Block' section (~30 lines for a specific token-sync scenario) is arguably separate-reference material, keeping it below the top anchor.

4 / 5

Total

18

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, distinctive, and names concrete macOS-specific SSH failure modes, but it omits any 'Use when...' trigger guidance and relies on a single action verb ('triage'), leaving both completeness and action specificity below their potential.

Suggestions

Add an explicit 'Use when...' clause, e.g. 'Use when SSH connects then closes before authentication, Remote Login is on but unreachable, or stale sshd sessions block new logins.'

Include natural user phrasings as trigger terms such as 'connection closed', 'connection refused', or 'can't SSH into the Mac'.

Promote 'triage' into one or two concrete verbs (e.g. 'diagnose and clear') so the capability is stated, not just the failure areas.

DimensionReasoningScore

Specificity

Names the domain ("SSH triage") and lists several concrete focus areas ("Remote Login, launchd sshd, pre-auth closes, stale sessions"), matching the 'lists several specific actions; minor gaps' anchor. Not 5 because 'triage' is the only action verb and the actual diagnostic actions are not spelled out; not 3 because it goes beyond naming the domain with only 1-2 items.

4 / 5

Completeness

Has a clear 'what' (SSH triage across named failure modes) but no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. Not 4 because the 'when' is entirely absent rather than merely weakly implied.

3 / 5

Trigger Term Quality

Good natural keyword coverage — 'SSH', 'Remote Login', 'stale sessions', 'launchd sshd' — but common user phrasings like 'connection closed', 'connection refused', or 'can't SSH in' are missing. Fits the 'good keyword coverage; a few natural terms missing' anchor, better than the 'some relevant keywords' level.

4 / 5

Distinctiveness Conflict Risk

Clear niche (macOS sshd/launchd/Remote Login diagnostics) with distinct, specific triggers unlikely to collide with other skills, matching the 'clear niche with distinct triggers; minimal conflict risk' anchor.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
steipete/agent-scripts
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.