CtrlK
BlogDocsLog inGet started
Tessl Logo

cve-reachability-analyzer

Analyze CVE reachability in software repositories by examining how vulnerable dependencies are imported and used. Determines whether vulnerable components, classes, or functions are reachable from project code through call chain analysis, reflection detection, dynamic loading patterns, and configuration-gated behavior. Classifies each CVE as likely reachable, possibly reachable, or likely unreachable with supporting evidence. Use when analyzing security vulnerabilities in dependencies, performing post-disclosure CVE triage, assessing vulnerability impact, or when users ask to analyze CVE reachability, check if vulnerabilities are exploitable, or evaluate dependency security risks.

90

1.05x
Quality

85%

Does it follow best practices?

Impact

99%

1.05x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable analysis workflow with clear sequencing and excellent progressive disclosure to three real reference files. Its main weakness is length: guidelines and limitations duplicate content already present in the steps and output template.

Suggestions

Remove the standalone 'Important Guidelines' items that restate step content (test-vs-production, configuration, transitive dependencies, language-specific analysis) and keep only genuinely additive guidance, or fold them into the relevant steps.

Eliminate the duplicated Limitations block — keep it in either the output template or the 'Limitations' section, not both.

Tighten the per-step sub-bullets by collapsing enumerated search hints (e.g., the reflection/dynamic-loading/eval lists) into compact inline examples to reduce token load.

DimensionReasoningScore

Conciseness

The 9-step procedure is mostly efficient, but the 'Important Guidelines' section restates guidance already embedded in the steps (e.g., test-vs-production, configuration gates) and Limitations appears both inside the output template and as a standalone section — noticeable tightening is possible without the verbosity of a 2.

3 / 5

Actionability

Gives concrete search targets (Java: `Class.forName()`, Python: `getattr()`/`importlib`, JS: `require(variable)`, `eval()`/`exec()`), named dependency files, and a copy-ready output template; it stops short of fully prescriptive tooling commands, keeping it below a 5.

4 / 5

Workflow Clarity

A clearly sequenced 9-step workflow with explicit decision/early-exit checkpoints (Step 2 Not Applicable/Not Vulnerable; Step 3 branch on imports; Step 8 classification), but it is a read-only analysis so it lacks the fix-and-retry feedback loops that would warrant a 5.

4 / 5

Progressive Disclosure

The body is an overview/workflow that signals one-level-deep references to three real, clearly named bundle files (language_guide.md, reachability_patterns.md, cve_analysis.md) both inline and in a References section, matching the clear-navigation anchor.

5 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that names concrete capabilities, supplies comprehensive natural trigger terms, and explicitly pairs a 'what' with a 'when'. It is distinguishable from neighboring security skills with minimal conflict risk.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'call chain analysis, reflection detection, dynamic loading patterns, and configuration-gated behavior' plus a three-way classification (likely/possibly/likely unreachable) with evidence — giving comprehensive coverage rather than the minor gaps of a 4.

5 / 5

Completeness

Explicitly answers both 'what' (analyze reachability and classify each CVE with evidence) and 'when' via a concrete 'Use when analyzing security vulnerabilities in dependencies, performing post-disclosure CVE triage... or when users ask to analyze CVE reachability...' clause, satisfying the top anchor.

5 / 5

Trigger Term Quality

Covers natural terms a user would say — 'analyze CVE reachability', 'post-disclosure CVE triage', 'check if vulnerabilities are exploitable', 'evaluate dependency security risks' — with genuine synonyms, matching the comprehensive anchor; file extensions are not applicable to this domain.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (CVE reachability in dependencies) with distinct triggers unlikely to fire for unrelated skills, matching the minimal-conflict-risk anchor; not merely 'broad with minor overlap' as a 4 would be.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ArabelaTso/Skills-4-SE
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.