CtrlK
BlogDocsLog inGet started
Tessl Logo

dryrunsecurity/remediation

Helps fix security vulnerabilities identified by DryRunSecurity. Activates when the user shares a DryRunSecurity comment (from a GitHub PR or GitLab MR) or asks for help fixing any security finding including SQL injection, XSS, CSRF, SSRF, path traversal, command injection, authentication bypass, authorization flaws, and prompt injection. Researches authoritative sources and applies fixes grounded in the user's specific codebase context.

99

Quality

99%

Does it follow best practices?

Impact

Pending

No eval scenarios have been run

Overview
Skills
Evals
Files

Discovery

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This is a strong skill description that excels across all dimensions. It clearly identifies the tool (DryRunSecurity), specifies concrete actions (researching and applying fixes), provides explicit activation triggers, and enumerates specific vulnerability types that serve as natural keywords. The description uses proper third-person voice throughout.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions: 'fix security vulnerabilities', 'Researches authoritative sources', 'applies fixes grounded in the user's specific codebase context'. Also enumerates specific vulnerability types (SQL injection, XSS, CSRF, SSRF, path traversal, command injection, authentication bypass, authorization flaws, prompt injection).

3 / 3

Completeness

Clearly answers both what ('fix security vulnerabilities', 'Researches authoritative sources and applies fixes') AND when ('Activates when the user shares a DryRunSecurity comment...or asks for help fixing any security finding'). Explicit trigger guidance is provided.

3 / 3

Trigger Term Quality

Excellent coverage of natural terms users would say: 'DryRunSecurity', 'GitHub PR', 'GitLab MR', 'security finding', plus specific vulnerability names (SQL injection, XSS, CSRF, etc.) that users would naturally mention when seeking help.

3 / 3

Distinctiveness Conflict Risk

Clear niche focused on DryRunSecurity findings and specific security vulnerability types. The combination of the tool name 'DryRunSecurity' and the enumerated vulnerability categories creates distinct triggers unlikely to conflict with general coding or documentation skills.

3 / 3

Total

12

/

12

Passed

Implementation

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is an excellent skill that demonstrates best practices across all dimensions. It provides a clear, actionable workflow for security remediation with appropriate validation checkpoints, concrete examples, and well-organized progressive disclosure to supporting documentation. The content respects Claude's intelligence while providing the specific, contextual guidance needed for this specialized task.

DimensionReasoningScore

Conciseness

The content is lean and efficient, avoiding explanations of basic security concepts Claude already knows. Every section serves a purpose with no padding or unnecessary context.

3 / 3

Actionability

Provides concrete, executable guidance with specific tool names (Glob, Grep, Read, Edit, WebFetch), exact search patterns, a clear before/after code example, and specific commit format. The table of config files to search is immediately actionable.

3 / 3

Workflow Clarity

Clear 5-step sequential process with explicit checkpoints ('Do NOT propose a fix until complete', 'Do NOT rely on memorized examples'). Each step has specific actions and the workflow includes verification in Step 5.

3 / 3

Progressive Disclosure

Well-structured overview with clear one-level-deep references to supporting files (FINDING_FORMAT.md, VULNERABILITY_TYPES.md, DRYRUN_FILTERING.md). Content is appropriately split between quick reference in main file and detailed references elsewhere.

3 / 3

Total

12

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Install with Tessl CLI

npx tessl i dryrunsecurity/remediation

Reviewed

Table of Contents