Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Kubernetes operations: debugging, security, RBAC, and infrastructure tooling.
.claude/skills/notque-kubernetes/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | 88% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 26% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -4% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 18% | 0% |
| case-21 | ✗→✓ | ▲ Improved | 23% | 0% |
Kubernetes debugging, security hardening, and infrastructure tooling. Covers pod triage, RBAC, network policies, and cobaltcore hypervisor components.
| Signal | Reference | Size | |--------|-----------|------| | CrashLoopBackOff, OOMKilled, config error, health check, liveness probe, ImagePullBackOff, Pending, FailedScheduling | references/crash-diagnosis.md | ~140 lines | | service resolution, DNS, CoreDNS, port-forward, NetworkPolicy ingress/egress | references/network-debugging.md | ~50 lines | | CPU throttling, memory limit, OOMKill, ephemeral storage, DiskPressure, debug container | references/resource-debugging.md | ~100 lines | | RBAC, Role, RoleBinding, ClusterRole, ServiceAccount, least-privilege | references/rbac-patterns.md | ~60 lines | | PodSecurity, SecurityContext, runAsNonRoot, readOnlyRootFilesystem, restricted, baseline | references/pod-security.md | ~90 lines | | NetworkPolicy, default-deny, allow-list, namespace isolation | references/network-policies.md | ~70 lines | | cosign, Kyverno, OPA, admission controller, Sealed Secrets, External Secrets | references/supply-chain.md | ~120 lines | | kvm-exporter, metrics, prometheus, libvirt, hypervisor, collector, scrape, steal time, NUMA, cgroups, cloud hypervisor | references/cobalt-kvm-exporter.md | ~800 lines | | cobaltcore concurrency, goroutine, semaphore, TryLock | references/cobalt-concurrency-patterns.md | ~200 lines | | cobaltcore testing, mock, moq, Kind cluster | references/cobalt-testing-patterns.md | ~200 lines | | kubernetes debugging process, triage flow, diagnosis routing | references/kubernetes-debugging.md | ~50 lines | | kubernetes security process, RBAC + pod security + network hardening | references/kubernetes-security.md | ~50 lines | | cobaltcore overview, KVM exporter architecture, component identification | references/cobalt-core.md | ~50 lines |
Loading rule. Read the references whose signals match the task before responding.
Determine which Kubernetes domain the request targets:
| Domain | Load references | Action | |--------|----------------|--------| | Pod failure, CrashLoop, OOM | crash-diagnosis, resource-debugging | Triage flow | | Network, DNS, service resolution | network-debugging, network-policies | Connectivity diagnosis | | RBAC, permissions, roles | rbac-patterns | Access control | | Pod hardening, container security | pod-security | Security posture | | Image signing, secrets, admission | supply-chain | Supply chain | | Cobaltcore / KVM exporter | kvm-exporter + cobalt refs | Component-specific |
Always specify -n <namespace> explicitly in every kubectl command.
Gate: Domain identified and relevant references loaded.
For debugging: follow the triage flow — describe, logs, events, exec. Use read-only commands to gather evidence before proposing changes.
For security: provide concrete YAML manifests and specific configurations. Answer with reference-backed specifics, not generic advice.
For cobaltcore: use component-specific reference knowledge for architecture, metrics, configuration, and deployment details.
Gate: Specific, reference-backed diagnosis or response provided.
For debugging: confirm the fix resolves the symptom. For security: validate against the misconfiguration table in supply-chain.md. For cobaltcore: verify against component test patterns.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 21,692 | 11,771 | -46% | 1 | 1 | 0% | 3,571 | 2,993 | -16% | 0 | 0 | — |
case-02 | pass→pass | 9,862 | 9,290 | -6% | 1 | 1 | 0% | 1,661 | 2,242 | +35% | 0 | 0 | — |
case-03 | fail→pass | 7,505 | 9,425 | +26% | 1 | 1 | 0% | 1,229 | 2,306 | +88% | 0 | 0 | — |
case-04 | pass→pass | 16,491 | 11,588 | -30% | 1 | 1 | 0% | 2,859 | 2,978 | +4% | 0 | 0 | — |
case-05 | pass→pass | 8,128 | 6,080 | -25% | 1 | 1 | 0% | 1,410 | 1,901 | +35% | 0 | 0 | — |
case-06 | pass→pass | 7,586 | 5,141 | -32% | 1 | 1 | 0% | 1,488 | 1,763 | +18% | 0 | 0 | — |
case-07 | pass→pass | 8,711 | 8,113 | -7% | 1 | 1 | 0% | 1,506 | 2,335 | +55% | 0 | 0 | — |
case-08 | pass→pass | 11,570 | 8,708 | -25% | 1 | 1 | 0% | 1,919 | 2,262 | +18% | 0 | 0 | — |
case-09 | pass→pass | 6,054 | 6,957 | +15% | 1 | 1 | 0% | 1,052 | 2,045 | +94% | 0 | 0 | — |
case-10 | fail→pass | 17,300 | 13,370 | -23% | 1 | 1 | 0% | 2,500 | 3,150 | +26% | 0 | 0 | — |
case-11 | fail→pass | 21,337 | 12,175 | -43% | 1 | 1 | 0% | 3,043 | 2,935 | -4% | 0 | 0 | — |
case-12 | pass→pass | 12,644 | 8,835 | -30% | 1 | 1 | 0% | 2,100 | 1,958 | -7% | 0 | 0 | — |
case-13 | pass→pass | 4,920 | 3,822 | -22% | 1 | 1 | 0% | 883 | 1,512 | +71% | 0 | 0 | — |
case-14 | pass→pass | 13,052 | 7,596 | -42% | 1 | 1 | 0% | 2,260 | 2,246 | -1% | 0 | 0 | — |
case-15 | pass→pass | 9,143 | 5,017 | -45% | 1 | 1 | 0% | 1,684 | 1,800 | +7% | 0 | 0 | — |
case-16 | pass→pass | 14,658 | 13,756 | -6% | 1 | 1 | 0% | 2,768 | 3,120 | +13% | 0 | 0 | — |
case-17 | fail→fail | 12,615 | 5,554 | -56% | 1 | 1 | 0% | 2,205 | 1,833 | -17% | 0 | 0 | — |
case-18 | pass→pass | 9,442 | 7,036 | -25% | 1 | 1 | 0% | 1,559 | 1,915 | +23% | 0 | 0 | — |
case-19 | fail→pass | 17,426 | 14,454 | -17% | 1 | 1 | 0% | 2,530 | 2,982 | +18% | 0 | 0 | — |
case-20 | pass→pass | 15,169 | 12,087 | -20% | 1 | 1 | 0% | 2,626 | 3,020 | +15% | 0 | 0 | — |
case-21 | fail→pass | 16,241 | 15,403 | -5% | 1 | 1 | 0% | 3,262 | 4,005 | +23% | 0 | 0 | — |
case-22 | pass→pass | 10,891 | 8,146 | -25% | 1 | 1 | 0% | 2,065 | 2,329 | +13% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +23 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.