CtrlK
BlogDocsLog inGet started
Tessl Logo

cua-spaces

Work inside cua Spaces through the cua MCP server. A Space is a remote or local computer the user can watch; you can run commands in it, move files in and out, show its desktop or a single window on the user's screen, start coding agents inside it, teleport a signed-in app session into it, and share the host's network with it. Use when the user mentions Spaces, asks you to do work "in a Space", or wants a task isolated but visible.

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, highly actionable reference: exact commands, dense tool tables, and a well-sequenced ssh host setup. Its weaknesses are the destructive lifecycle (creating and deleting cloud Spaces) having no verification or confirmation checkpoints before deletion, and several viewer/agent tools described without enough invocation detail to call them directly.

Suggestions

Add a validation checkpoint before destructive cleanup, e.g., 'Before delete_space, confirm with the user that no files need downloading, and run a final download of anything created in the Space.'

Give invocation details for the under-specified tools — e.g., 'stream_endpoint(space, target: "desktop" | "window:<id>")' and the parameter shapes for agent_status / agent_message / agent_stop.

Consider moving the ssh host-setup procedure into a references/ file (e.g., HOST-SETUP.md) linked from a one-line pointer, keeping SKILL.md focused on using Spaces and bringing the body under ~50 lines.

DimensionReasoningScore

Conciseness

The body is dense tool tables plus one exact command sequence, with no explanations of concepts Claude already knows; every line delivers a tool, parameter, or operational constraint. Even the apparent asides earn their place (e.g., 'Tailscale is only the ssh transport, the same as any LAN or internet address' prevents a real misreading, and the LaunchAgent/Aqua-session note is non-obvious operational detail). This matches the 5-anchor ('lean and efficient; every token earns its place') rather than the 4-anchor, which requires trimmable over-explanation.

5 / 5

Actionability

The ssh setup section is copy-paste ready ('curl -fsSL https://cua.ai/install.sh | sh -s -- -y --select spaces,host --no-onboarding', 'cua host setup --profile spare --name "<name>"', 'create_space(on="host:<name>", count=2)') and key tools list parameters ('space_bash' with 'space, command, optional timeout'; 'agent_start' with 'space, agent, prompt'). It falls short of the 5-anchor because several tools are described only by purpose without invocation detail ('stream_endpoint' — 'Get a ticketed media URL'; 'agent_status / agent_message / agent_stop / agent_list' — 'Follow, steer and stop runs'; 'open_space_viewer' with no arguments shown), which are minor but real gaps.

4 / 5

Workflow Clarity

The ssh host setup is a clearly sequenced 6-step process with a real checkpoint (show the device code and URL and have the user approve), but the skill's lifecycle workflow ends in destructive operations without any validation or confirmation step: 'A cloud Space costs money: delete the ones you created when the task ends' and 'delete_space — Delete a Space's sandbox and stop metering' involve irreversible deletion with no verify-first checkpoint (e.g., confirm files are downloaded or ask the user). Per the judging guidelines, missing validation in workflows involving destructive operations caps workflow_clarity at 3; the sequence itself is better than the 2-anchor but does not meet the 4-anchor's 'most checkpoints present'.

3 / 5

Progressive Disclosure

Sections are well organized (Get a Space / Work in it / Show it / Agents, apps and network / host setup / Rules) and no references are buried, matching the 4-anchor ('good structure; most content appropriately placed'). It cannot take the 5-anchor's simple-skill exception because the body is ~84 lines (over the ~50-line guideline), and the specialized ssh host-setup procedure — a distinct advanced topic — is fully inlined rather than split into a reference file, a minor organization gap.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with a comprehensive, concrete capability list and an explicit 'Use when...' trigger clause. Its main flaws are the second-person voice ('you can run commands in it'), which the guidelines penalize, and trigger coverage that omits natural synonyms a user might say instead of 'Space'.

Suggestions

Rewrite the capability list in third person (e.g., 'Runs commands in a Space, moves files in and out, shows its desktop or a single window...') to remove the second-person 'you can' phrasing the guidelines penalize.

Add a few natural synonyms to the trigger clause, e.g., 'Use when the user mentions Spaces, a remote/isolated machine, or wants a task isolated but visible'.

DimensionReasoningScore

Specificity

The description lists multiple concrete, comprehensive actions ('run commands in it, move files in and out, show its desktop or a single window on the user's screen, start coding agents inside it, teleport a signed-in app session into it, and share the host's network with it'), which matches the 5-anchor, but it uses second person ('the user can watch; you can run commands in it'), which the judging guidelines penalize by reducing specificity by 1. It is above the 3-anchor ('1-2 concrete actions') and the 4-anchor ('minor gaps in coverage') because action coverage is essentially complete, not partial.

4 / 5

Completeness

It explicitly answers both questions: the 'what' is a concrete list of capabilities, and the 'when' is an explicit 'Use when...' clause with concrete trigger phrases ('the user mentions Spaces, asks you to do work "in a Space", or wants a task isolated but visible'). This matches the 5-anchor exactly; the 4-anchor ('when' could be more explicit or specific) understates how direct the trigger guidance is.

5 / 5

Trigger Term Quality

'Use when the user mentions Spaces, asks you to do work "in a Space", or wants a task isolated but visible' gives good natural trigger phrasing including a quoted exact phrase users would say. It falls short of the 5-anchor because common synonyms are missing (e.g., 'remote machine', 'sandbox', 'isolated environment', 'virtual desktop'), but it clearly exceeds the 3-anchor's 'missing common variations'.

4 / 5

Distinctiveness Conflict Risk

The niche is clearly defined by the product-specific terms 'cua Spaces' and 'the cua MCP server', with distinct triggers ('Spaces', '"in a Space"') unlikely to fire for unrelated skills. Only 'wants a task isolated but visible' has slight overlap risk with sandbox/VM skills, which keeps it at the 5-anchor ('minimal conflict risk') rather than suggesting the 4-anchor's 'minor overlap risk'.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
trycua/cua
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.