CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-k8s

Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.

75

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, lean security-assessment workflow with clear phased sequencing, verification checkpoints, and an appropriate one-level-deep reference file. The main weakness is actionability: some phases use abstract investigation prompts and vendor-substitution placeholders rather than fully executable commands.

Suggestions

Replace abstract '□' investigation prompts in Phase 1 and Phase 3 with concrete, runnable commands (e.g. 'kubectl get pod -o jsonpath=... {.spec.securityContext.privileged}' for the privileged/hostPath check) so guidance is copy-paste ready.

For Phase 2/3 commands marked '按厂商替换', add at least one complete AWS and one Azure/GCP variant rather than leaving substitution implicit, since the placeholders are not executable as written.

Add a brief validate→fix→retry loop note for the destructive-operation guardrails (e.g. what to do if a scan slips outside authorized scope) to strengthen the existing verification checkpoints into full feedback loops.

DimensionReasoningScore

Conciseness

Dense, fluff-free body using terse checklist boxes and short command blocks; assumes Claude's competence without explaining what Kubernetes or IAM is. Not a 2 because there is no unnecessary explanation to tighten.

3 / 3

Actionability

Provides real executable commands (aws sts get-caller-identity, kubectl auth can-i --list) but several phases rely on investigation prompts ('□ 当前身份...') and vendor-substitution placeholders ('按厂商替换'). Not a 3 because guidance is partly abstract prompts and placeholder commands rather than fully copy-paste-ready; not a 1 because concrete commands are present.

2 / 3

Workflow Clarity

Clear 4-phase sequence with explicit NOW/NEXT/ACT ordering, per-phase checkbox checkpoints, and a completion self-check verifying authorization scope and avoidance of destructive ops. Not a 2 because validation/verification steps are present (not missing) in this destructive-operation context.

3 / 3

Progressive Disclosure

Body points one level deep to the real references/k8s-cloud-checklist.md (verified present) for detail, keeping the SKILL.md as an overview. Not a 2 because the reference is clearly signaled and resolves to an actual bundle file rather than nesting into further references.

3 / 3

Total

11

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A tight, third-person description with an explicit 'Use for' trigger and concrete, distinctive assessment activities. It cleanly answers both what the skill does and when to invoke it.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'metadata SSRF', 'IAM misconfig', 'container escape paths', 'cluster RBAC review' — rather than vague domain language. Not a 2 because it enumerates four distinct assessment activities, not just a domain name.

3 / 3

Completeness

'Use for authorized cloud, container, and Kubernetes security assessment' answers both what (security assessment) and when via an explicit 'Use for' trigger clause. Not a 2 because the explicit trigger guidance is present, not merely implied.

3 / 3

Trigger Term Quality

Uses natural terms users would say — 'cloud', 'container', 'Kubernetes', 'SSRF', 'IAM', 'RBAC' — with good coverage of recognizable domain vocabulary. Not a 2 because the keyword set is broad and user-facing rather than narrow jargon.

3 / 3

Distinctiveness Conflict Risk

Carves a clear niche (authorized cloud/container/K8s assessment) with distinct triggers unlikely to collide with general skills. Not a 2 because the authorization + specific assessment scope sets it apart from adjacent pentest skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.