CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-k8s

Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A compact, well-structured security-assessment skill with executable commands, a phased workflow, a real reference file, and explicit authorization guardrails. Adding explicit validate→fix→retry feedback loops for destructive/batch operations would lift workflow clarity, and trimming bilingual preamble padding would improve conciseness.

Suggestions

Add explicit validation feedback loops (e.g., after 'kubectl auth can-i --list', state: review permissions → if cluster-admin over-grant found → record finding → continue) to satisfy the destructive/batch validation expectation.

Tighten the bilingual ACTION REQUIRED preamble into concise English directives to reduce token overhead without losing the guardrail.

Convert the Phase 1-4 '□' checklists into numbered imperative steps so the sequence and checkpoints are unambiguous.

DimensionReasoningScore

Conciseness

The body is largely efficient — checklist tables and code blocks assume Claude's competence — but a few bilingual preamble notes ('ACTION REQUIRED(读完后立刻执行)') and inline guidance could be trimmed slightly.

4 / 5

Actionability

Provides concrete, executable commands ('aws sts get-caller-identity', 'kubectl auth can-i --list', 'kubectl get pods,secrets,svc -A') and a real tools table, with only minor gaps such as placeholder substitution notes for Azure/GCP.

4 / 5

Workflow Clarity

Four clearly sequenced phases with an ACTION REQUIRED setup and a final self-check; destructive/batch guardrails are present ('MUST 在授权账号内', '禁止破坏性操作') but error-recovery validate→fix→retry loops are mostly implicit rather than explicit.

4 / 5

Progressive Disclosure

Well-organized sections with a single one-level-deep reference to a real file (references/k8s-cloud-checklist.md, confirmed present) and clear routing context to sibling skills; only minor organization gaps keep it from the top anchor.

4 / 5

Total

16

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete actions and includes an explicit 'Use for' trigger clause answering both what and when. Adding synonyms like 'k8s' and provider names would push trigger-term quality to comprehensive.

Suggestions

Add common synonyms and provider names (e.g., 'k8s', 'EKS/GKE/AKS', 'IMDS') so the description matches a wider range of natural user phrasings.

Consider naming one or two concrete deliverables (e.g., 'produce a findings report') to sharpen the 'what' further.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'metadata SSRF', 'IAM misconfig', 'container escape paths', and 'cluster RBAC review' — giving comprehensive coverage of the cloud/container/K8s security domain.

5 / 5

Completeness

Explicitly answers both 'what' (the listed assessment activities) and 'when' via the 'Use for authorized cloud, container, and Kubernetes security assessment' trigger clause with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural phrases like 'cloud, container, and Kubernetes security assessment' are present, but common synonyms such as 'k8s' and provider names (EKS/GKE/AKS) are missing, placing it just below comprehensive.

4 / 5

Distinctiveness Conflict Risk

The cloud/K8s security-assessment niche is clearly distinct from generic web scanning, with only minor overlap risk against the related supply-chain-security skill.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.