CtrlK
BlogDocsLog inGet started
Tessl Logo

ai-ecoverse/advanced-skills

Quarantined high-risk skills (browser session capture, WebSocket interception) for Slack and Microsoft Teams. Install only after reviewing the security implications.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with strong, validated workflows for destructive and batch operations, but it is verbose and inlines substantial reference-grade detail (manifest wire facts, Enterprise Grid admin methods, repeated audit caveats) that would be better placed in the existing reference files. Conciseness and progressive disclosure are the weakest dimensions.

Suggestions

Move the App Manifest API wire facts and the Enterprise Grid admin command reference into references/endpoints.md (or a new references/admin.md), leaving SKILL.md with a one-line pointer per command — the inlined detail is reference-grade and bloats the overview.

Deduplicate the audit-attribution caveat: it appears both in the 'Admin user management' section and the 'Enterprise Grid' section; state it once and cross-reference.

Collect the scattered 'verified live 2026-09-18/22' date stamps into a single 'Verified wire facts' subsection (or a dated changelog in references/) so time-sensitive markers stop penalizing the body's conciseness.

DimensionReasoningScore

Conciseness

Mostly efficient and packed with genuinely non-obvious API gotchas, but the ~1225-line body carries notable padding: the audit-attribution caveat is repeated in two sections, long storytelling about Zapier/Lars Trieloff, a verbose explanation of why the web UI is unautomatable, and many scattered 'verified live 2026-09-18/22' date stamps that the guidelines say should penalize conciseness unless isolated in a deprecated section. Not a 4 because the repetition and date-stamping are more than minor trimmable instances; not a 2 because the bulk is hard-won Slack-specific detail Claude would not already know.

3 / 5

Actionability

The body is dominated by copy-paste-ready bash commands with concrete flags and real IDs (e.g. 'slack post C087NCG774J "Hello from SLICC!"', 'slack-ext app set-scopes A0123456789 --add=reactions:read --confirm'), covering the common cases fully and matching the score-5 anchor.

5 / 5

Workflow Clarity

Multi-step processes are explicitly sequenced with validation checkpoints and feedback loops: the approve/deny workflow ends with 'Verify — the entry should no longer appear in pending', the manifest flow enforces export-modify-update with a required 'app diff' review before apply, and destructive/batch commands have dry-run, --confirm, --allow-deletions gates plus per-user read-back verification, satisfying the score-5 anchor and avoiding the destructive-cap at 3.

5 / 5

Progressive Disclosure

Section structure is clear and the References section cleanly signals one-level-deep pointers to the real references/endpoints.md and references/watch-architecture.md files, but large reference-grade blocks (the entire ~150-line App manifest management section and ~250-line Enterprise Grid commands section, including wire facts that endpoints.md is meant to hold) are inlined in SKILL.md rather than split out, matching the score-3 anchor where content that should be separate is inline.

3 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a strong, third-person statement that explicitly covers what the skill does and when to use it, with a dedicated trigger-terms clause and comprehensive concrete actions. Its only weakness is mild verbosity and the broad 'automate any Slack task' phrasing.

DimensionReasoningScore

Specificity

Lists many concrete actions — 'read messages, post to channels, search message text, search channels, read threads, find and look up users by name, username, or email, view activity/notifications, manage Slack support requests, and watch channels for new messages in real time' plus admin 'guest conversion, guest channels' and 'app manifest reads and diffs' — comprehensive coverage matching the score-5 anchor.

5 / 5

Completeness

Both 'what' (the long action list) and 'when' ('Use when the user wants to check Slack messages...') are answered explicitly with concrete trigger phrases, satisfying the score-5 anchor; the minor over-claim 'automate any Slack task' does not displace the concrete coverage.

5 / 5

Trigger Term Quality

An explicit 'Triggers on mentions of Slack, channels, DMs, threads, messages, Slackbot, notifications, activity, support requests, help requests, watching/monitoring, or searching message text' covers natural terms and synonyms comprehensively, matching the score-5 anchor.

5 / 5

Distinctiveness Conflict Risk

Every trigger is Slack-specific (Slack, channels, DMs, threads, Slackbot, support requests) giving a clear niche with minimal overlap risk against other skills, matching the score-5 anchor.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (1226 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Reviewed

Table of Contents