📖 Gemini Spark File Content Manual & Writing Rules
Learn how to format each specific file so Gemini Spark understands when to trigger, where to look, and how to execute tools without errors.
1. Writing `SKILL.md` (The Master Conductor)
YAML Frontmatter + Step-by-Step Orchestration- YAML Frontmatter: Must begin on line 1 with
---and close with---. - name: lowercase slug with hyphens (e.g.,
docker-compose-guard). - description: The router prompt. Gemini reads this to determine if your skill should trigger on user prompts.
- Body: Write imperative markdown instructions (Step 1, Step 2, Step 3) referencing subfolder paths directly.
SKILL.md သည် Skill တစ်ခုလုံး၏ ခေါင်းဆောင်ဖိုင်ဖြစ်ပါသည်။ အပေါ်ဆုံးတွင် --- ဖြင့်စပြီး name နှင့် description ကို တိကျစွာ ရေးရပါမည်။ ဤ description ကို ဖတ်ပြီး Gemini က အလိုအလျောက် ခေါ်ယူအသုံးပြုပေးခြင်း ဖြစ်ပါသည်။ စာကိုယ်တွင် အဆင့် ၁၊ ၂၊ ၃ အဖြစ် မည်သည့် scripts ကို run ရမည်၊ မည်သည့် template ကို သုံးရမည်ကို ညွှန်ကြားရပါသည်။
---
name: docker-compose-guard
description: Audits Docker Compose YAML files, runs syntax & security linters, and scaffolds production-ready templates.
---
# Docker Security Guard Instructions
When a user provides or asks to audit a Docker Compose file:
1. Save their YAML into a temporary file.
2. Execute `scripts/lint_compose.py` to test for exposed open ports and root permissions.
3. Compare any script warnings with `references/security_rules.md`.
4. If the user asks to generate a fresh service, copy `assets/secure-compose-template.yml`.
5. Return a clean report detailing any fixed vulnerabilities.
2. Writing `references/` (Domain Knowledge & Guidelines)
Read on-demand only (Saves tokens & cost)- Use structured Markdown with clear H1, H2, bullet points, and code snippets.
- Do NOT dump 100-page unstructured text; divide into clean files like
security_rules.mdorapi_spec.md. - Gemini only indexes and reads the specific reference requested by `SKILL.md`.
ဤဖိုဒါတွင် ကုမ္ပဏီစည်းမျဉ်းများ၊ ဥပဒေများ၊ စံချိန်စံညွှန်းများ (Style Guide) ကို သိမ်းဆည်းရပါမည်။ မေးခွန်းတိုင်းအတွက် အကုန်မဖတ်ဘဲ လိုအပ်သည့်အချိန်တွင်သာ Gemini က သီးသန့်ဆွဲထုတ်ဖတ်ရှုသောကြောင့် Token မကုန်ဘဲ မြန်ဆန်စေပါသည်။
# Container Security Policies
## 1. Privilege Escalation
Containers must not run as root.
- Enforce: `security_opt: ["no-new-privileges:true"]`
- Disallow: `privileged: true`
## 2. Public Network Bindings
- Databases (Postgres 5432, MySQL 3306, Redis 6379) must never bind to `0.0.0.0`.
- Instead, link them via internal Docker networks or `127.0.0.1:5432:5432`.
## 3. Version Pinning
- Ban `:latest` tags in production declarations. Use pinned image versions (e.g. `node:20.11-alpine`).
3. Writing `scripts/` (Sandbox Executables)
Deterministic Automation (Python, Bash, Node)- Accept inputs as CLI arguments (
sys.argv[1]) or standard input. - Print output cleanly to
stdoutso Gemini can read the results. - Use exit code
0for success, and non-zero for failures. - No GUI prompts or interactive
input()loops. Must be non-interactive.
Gemini သည် တွက်ချက်မှု၊ regex စစ်ဆေးမှုနှင့် syntax အမှားရှာဖွေမှုများကို အမှားအယွင်း (Hallucination) မရှိစေရန် Python Script များကို run ပြီး အဖြေရှာပါသည်။ Script များကို Terminal CLI command အနေဖြင့် တိုက်ရိုက် run နိုင်အောင် ရေးပေးရပါမည်။
#!/usr/bin/env python3
import sys
def lint(file_path):
issues = []
with open(file_path, 'r') as f:
content = f.read()
# Deterministic pattern checks
if '0.0.0.0:' in content:
issues.append("SECURITY WARN: Found public binding '0.0.0.0:'")
if ':latest' in content:
issues.append("VERSION WARN: Image pinned with ':latest' tag")
if issues:
print("FAILURES DETECTED:")
for item in issues:
print(f" - {item}")
sys.exit(1)
else:
print("SUCCESS: 0 security violations found.")
sys.exit(0)
if __name__ == '__main__':
target = sys.argv[1] if len(sys.argv) > 1 else 'compose.yml'
lint(target)
4. Writing `assets/` (Boilerplates & Starter Templates)
Copied and adapted into user deliverables- Store clean production skeletons (YAML, JSON, boilerplate Markdown, config templates).
- Use clear comments indicating customizable parameters (e.g.
# Set your service name here). - Gemini duplicates and fills in this template rather than inventing structure from scratch.
အသုံးပြုသူထံ ပြန်လည်ထုတ်ပေးရမည့် ဖိုင်ပုံစံကြမ်း (Template) များကို ဤနေရာတွင် ထည့်ထားရပါမည်။ Gemini သည် သုညမှ အသစ်မစဘဲ ဤ Template ကို အခြေခံပြီး လိုအပ်သောအချက်အလက်များကို ဖြည့်သွင်း၍ အဖြေထုတ်ပေးပါသည်။
version: '3.8'
services:
web:
image: nginx:1.25-alpine
restart: unless-stopped
security_opt:
- no-new-privileges:true
ports:
- "127.0.0.1:8080:80"
networks:
- secure_network
networks:
secure_network:
driver: bridge
SKILL.md is mandatory. assets/, references/, and scripts/ are 100% optional! You only create the folders you actually need.
SKILL.md
Primary Entry Point & Metadata Coordinator
The core orchestrator file. It tells Gemini when to activate (YAML frontmatter) and gives precise step-by-step instructions on when to read references, execute scripts, and inject assets.
စွမ်းရည်၏ ဗဟိုဦးနှောက်ဖိုင် ဖြစ်ပါသည်။ အသုံးပြုသူ၏ မေးခွန်းနှင့် ကိုက်ညီပါက စွမ်းရည်ကို အလိုအလျောက် ခေါ်ယူပေးမည့် အချက်အလက် (YAML frontmatter) နှင့် မည်သည့်အချိန်တွင် Script များကို Run မည်၊ မည်သည့် reference စည်းမျဉ်းများကို ကြည့်မည်ကို အသေးစိတ် ညွှန်ကြားပေးရပါသည်။
📦 How to Properly Zip Your Skill Folder on Your Computer
The #1 reason skills fail to import into Gemini Spark is the "Double-Folder Nesting Trap". Follow these instructions for your operating system:
- Open your skill folder (e.g.
my-skill/). - Press Ctrl + A to select all files inside.
- Right-click on
SKILL.md. - Choose Compress to ZIP file.
- Done! Now SKILL.md sits at the zip root.
Inside Terminal, run:
zip -r ../my-skill.zip .
Or in Finder: Open the folder, select all items, right-click → Compress X Items.
Run the standard command:
zip -r ../my-skill.zip *
Guarantees zero hidden top-level directory wrapper.
If Gemini Spark opens the zip and sees an outer folder instead of SKILL.md directly at root level, it will reject the skill with an "Invalid Skill Archive" error.
Our online Studio automatically exports using this exact format. You can drag and drop the exported .zip directly into Gemini Spark!