sqlspn-review skillA
sqlspn-review is agent-read markdown (skill) from vanterx/mssql-performance-skills: Analyzes SQL Server SPN (Service Principal Name) configuration and Kerberos delegation settings to diagnose authentication failures, NTLM fallback, and double-hop connectivity problems. Use this skill when users receive Kerberos errors, "Cannot generate SSPI context", ANONYMOUS LOGON failures, linked servers fall back to NTLM, AG listener connections fail, or constrained delegation is needed for a middle-tier application, and you need to identify missing, duplicate, or misconfigured SPNs and del.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# SQL Server SPN and Kerberos Delegation Review Skill ## Purpose Analyze SQL Server SPN configuration and Active Directory delegation attributes to surface Kerberos authentication failures, NTLM fallback causes, and double-hop connectivity problems. Applies 54 checks (K1–K54) across eleven categories: - **K1–K6** — MSSQLSvc SPN presence: default instance, named instance, FQDN variant, short-hostname variant, port mismatch, and FCI Virtual Network Name - **K7–K11** — Service account binding: SPN on wrong account, duplicate SPNs, machine account vs domain account, stale SPNs from old accounts, MSA/gMSA auto-registration gaps - **K12–K16** — AG listener and alias: listener SPN, named instance port conflict, SQL Browser, alias SPN, multi-subnet listener coverage - **K17–K20** — Configuration and permissions: HTTP SPN, registration permission gap, unconstrained delegation, NTLM fallback signal - **K21–K25** — Kerberos delegation — service account: constrained delegation (KCD) not configured, missing target SPN, protocol transition, RBCD misconfiguration, delegation scope - **K26–K30** — AD account and computer sensitivity: AccountNotDelegated on end-user, Protected …
Read the whole file at its exact version.
How to install
mdr add vanterx/mssql-performance-skills/sqlspn-review@git:20260907.492bd70mdr add vanterx/mssql-performance-skills/sqlspn-review@sha256:a2057a08195f570cPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_yxvmbushmnr6g2ve)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260907.492bd70 latest | 2026-09-07 | 492bd70 | 52,842 B | A | view · diff |
| git:20260621.d1ce43d | 2026-06-21 | d1ce43d | 29,887 B | A | view · diff |
| git:20260607.6ff4f7a | 2026-06-07 | 6ff4f7a | 29,699 B | A | view · diff |
| git:20260605.9ec0ebe | 2026-06-05 | 9ec0ebe | 28,521 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (52842 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
vanterx/mssql-performance-skills · 5 stars · license MIT · pushed 2026-09-19 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_yxvmbushmnr6g2ve GET https://markdownregistry.com/api/v1/resolve?ref=vanterx/mssql-performance-skills/sqlspn-review GET https://markdownregistry.com/api/v1/blob/a2057a08195f570c99941abb2e46b0e06cb2b32ffa4f55e4665d83adb6e001b0
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.