CtrlK
BlogDocsLog inGet started
Tessl Logo

cve-watchlist-action-recommendation-generator

Generate prioritized CVE watchlists and actionable security recommendations for repositories. Use when analyzing CVE scan results, creating security reports, prioritizing vulnerability remediation, or generating security gate reports for CI/CD. Takes CVE scan results (JSON/SARIF from npm audit, pip-audit, Snyk), reachability analysis, and cutoff date as input. Combines severity, reachability, exploitability, and dependency criticality to rank CVEs by practical risk. Outputs markdown reports with concrete next-step guidance (immediate upgrade, monitor, ignore with justification, apply mitigation) suitable for issue trackers, security reviews, and CI security gates.

90

1.38x
Quality

90%

Does it follow best practices?

Impact

86%

1.38x

Average score across 3 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

80%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is highly actionable and well-structured with clear progressive disclosure to real bundle files, but the workflow lacks explicit validation/verification checkpoints for a batch report-generation process, which limits workflow clarity.

Suggestions

Add validation checkpoints between pipeline stages (e.g., verify parsed_cves.json is non-empty and well-formed before scoring, confirm scored_cves.json before report generation) to raise workflow clarity above 3.

Move the full per-tool input JSON schema examples and the complete example output report into a reference file, keeping only one representative example inline, to tighten conciseness.

Add an explicit error-recovery/feedback loop (what to do when a scan file fails to parse or a referenced CVE lacks reachability data) to satisfy the batch-operation feedback-loop expectation.

DimensionReasoningScore

Conciseness

The body is largely efficient with executable commands and concrete examples, but includes lengthy inline JSON schema examples for multiple input formats and a full example output report that pads the content somewhat.

4 / 5

Actionability

Provides copy-paste-ready bash commands for each pipeline stage, an explicit risk-scoring formula, a numeric decision tree, and concrete upgrade commands in the example, covering the common cases fully.

5 / 5

Workflow Clarity

The four-step workflow is clearly sequenced, but it performs batch prioritization/report generation without validation or verification checkpoints (e.g., confirming parsed CVEs, verifying scores, validating report output), which caps the score at 3 per the destructive/batch operation rule.

3 / 5

Progressive Disclosure

SKILL.md is a well-organized overview that signals one-level-deep references to real bundle files (references/risk_scoring.md, references/action_guidelines.md, assets/report_template.md) and scripts, with no nested references and clear navigation via the Resources section.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is comprehensive, concrete, and explicitly provides both a 'what' and a 'Use when' clause with natural trigger terms. It uses third-person voice throughout and avoids vague fluff, clearly distinguishing its niche.

DimensionReasoningScore

Specificity

Lists multiple concrete actions (generate prioritized watchlists, rank CVEs by practical risk, output markdown reports with concrete next-step guidance) across the full pipeline from parsing scan results to report generation.

5 / 5

Completeness

Explicitly answers both what (generate prioritized CVE watchlists and actionable recommendations) and when ('Use when analyzing CVE scan results, creating security reports, prioritizing vulnerability remediation, or generating security gate reports for CI/CD') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Includes natural terms users would say ('CVE scan results', 'npm audit', 'pip-audit', 'Snyk', 'security reports', 'CI/CD', 'security gate reports') plus file-format synonyms (JSON/SARIF), giving comprehensive keyword coverage.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (CVE vulnerability prioritization and remediation guidance) with distinct triggers unlikely to conflict with general security or reporting skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ArabelaTso/Skills-4-SE
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.