CtrlK
BlogDocsLog inGet started
Tessl Logo

personwise/personwise-security-awareness-training

Employees are the attack surface, and a skimmed policy PDF does not change behavior. Turn your security policies into an interactive digital-human security awareness training course that builds recognition and reporting reflexes — and answers employee questions on demand. Honest by design: awareness reduces risk, it never claims to eliminate it.

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body excels at actionability and workflow clarity with executable commands and strong validation feedback loops for credit-consuming, publish, and source operations. It loses points on conciseness due to repeated passages and on progressive disclosure because a large monolithic operational spec is inlined rather than split into reference files.

Suggestions

Deduplicate the `run advance` no-op / `awaiting_sources` guidance and the `materials_only` reminders so each rule appears once, then cross-references it.

Extract the freshness/update protocol and the source-upload lifecycle into separate reference files (e.g. UPDATE.md, SOURCES.md) and link to them from SKILL.md to improve progressive disclosure.

Move the long update-ratchet decision tree into a short checklist with the verbose branch table in a referenced file.

DimensionReasoningScore

Conciseness

The body is dense and assumes Claude's competence (no basic-concept padding), but it repeats the same guidance in multiple places — e.g. the `run advance` 200 no-op / `awaiting_sources` behavior is explained in both 'Build and submit the blueprint' and 'Finish, recover and report', and `materials_only` is reiterated several times — so it is 'mostly efficient but includes some unnecessary explanation or could be tightened' rather than lean.

3 / 5

Actionability

Provides fully executable, copy-paste-ready commands with concrete flags throughout ('personwise version --json', 'personwise --account <alias> course readiness --json', 'source add --run-id <run-id> --path <exact-path> --json', 'run wait --run-id <run-id> --timeout-seconds 1800 --json') and parameterizes the common cases, matching the top anchor.

5 / 5

Workflow Clarity

The multi-step process (readiness → blueprint → sources → checkpoints → publish) is clearly sequenced with explicit validation checkpoints (`can_create=false` gating, `source status` polling until `ready`, review-at-`paused`, `--expected-revision`) and concrete feedback loops (retry once then stop on repeated error; `read_current_state` conflict → bounded retry → stop), matching the 'clear sequence with explicit validation steps; feedback loops' anchor.

5 / 5

Progressive Disclosure

Section headers give the single SKILL.md some structure and the bundled assets (bootstrap.sh, bootstrap.ps1, service-descriptor.signed.json) are referenced one level deep, but the body is a long monolithic operational wall where sizable subprotocols (freshness/update handling, source lifecycle) are inlined rather than split into separate reference files, fitting 'some structure but could be better organized; content that should be separate is inline'.

3 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: third-person voice, explicit what-and-when with concrete trigger language, and a well-scoped niche with explicit exclusions. Minor gaps in trigger synonyms and action coverage keep two dimensions at 4 rather than 5.

DimensionReasoningScore

Specificity

Lists several concrete actions ('Produce a grounded interactive digital-human course learners can interrupt with voice questions', 'install or update the official PersonWise CLI', 'uses browser OAuth') with only minor coverage gaps, fitting the 'several specific actions; minor gaps' anchor rather than the fully comprehensive level 5.

4 / 5

Completeness

Explicitly answers both 'what' ('Produce a grounded interactive digital-human course learners can interrupt with voice questions') and 'when' ('Use when the user asks for Security Awareness Training from supplied source materials. Trigger language: …') with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Provides strong natural trigger phrases ('security awareness training; cyber awareness training; employee security training') with synonyms, but a few natural terms a user might say (e.g. 'phishing training', 'security training') are missing, so it stops at 'good keyword coverage; a few natural terms missing' rather than level 5.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (PersonWise security awareness training from supplied materials) with distinct triggers and explicit negative scope ('Do not use it for technical security operations training, incident response certification, or penetration-testing instruction'), giving minimal conflict risk.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Reviewed

Table of Contents