CtrlK
BlogDocsLog inGet started
Tessl Logo

healthcheck

Host security hardening and risk-tolerance configuration for Bitterbot deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, Bitterbot cron scheduling for periodic checks, or version status checks on a machine running Bitterbot (laptop, workstation, Pi, VPS).

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Content

73%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable hardening workflow with strong sequencing and explicit validation checkpoints. Its main weakness is conciseness — repeated guidance across sections adds tokens without new information — and the absence of progressive disclosure into bundle files.

Suggestions

Consolidate the model self-check guidance so it appears once (either in 'Core rules' or Step 0), and merge the repeated approval/confirmation lists into a single canonical list referenced where needed, to reduce token redundancy.

Split the long monolithic file: move the detailed command reference and risk-profile definitions into reference files (e.g., COMMANDS.md, PROFILES.md) with one-level-deep links from SKILL.md to improve progressive disclosure.

Fill in the 'bitterbot cron add' command with the concrete flags/arguments so the scheduling guidance is fully copy-paste ready.

DimensionReasoningScore

Conciseness

Mostly efficient with concrete commands and minimal concept-explanation, but repeats guidance (model self-check appears in both 'Core rules' and Step 0; approval requirements are restated in 'Core rules', 'Required confirmations', and Step 7), pushing it below the 'minor instances' level-4 anchor.

3 / 5

Actionability

Provides concrete, mostly copy-paste-ready commands throughout (uname, sw_vers, ss, ufw, bitterbot security audit --deep, bitterbot cron add/list) with a supported-flags reference, matching level 4; minor gaps like the '... ' placeholder in 'bitterbot cron add' keep it short of fully executable level 5.

4 / 5

Workflow Clarity

Clear numbered Steps 0–8 with an explicit verification step (Step 8 re-checks firewall, ports, access, re-runs audit), 'stop on unexpected output' feedback loop, rollback plans, and a Required confirmations checklist — satisfying the level-5 anchor including validation for destructive operations.

5 / 5

Progressive Disclosure

Well-organized into clear headers (Overview, Core rules, Workflow, Required confirmations, Periodic checks, Command accuracy) with good structure, but it is a single monolithic ~240-line file with no one-level-deep bundle references, so it does not reach the clear overview-pointing-to-details level-5 anchor.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states what the skill does and when to use it, scoped to a distinct Bitterbot niche. Trigger-term coverage is good but could add a few synonyms to reach the top anchor.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'security audits', 'firewall/SSH/update hardening', 'risk posture', 'exposure review', 'cron scheduling', 'version status checks' — giving comprehensive coverage, matching the level-5 anchor rather than the 'several actions with minor gaps' of 4.

5 / 5

Completeness

Explicitly answers both what ('Host security hardening and risk-tolerance configuration for Bitterbot deployments') and when ('Use when a user asks for security audits, firewall/SSH/update hardening, risk posture...') with concrete trigger phrases, matching the level-5 anchor.

5 / 5

Trigger Term Quality

Good natural-keyword coverage matching what users would say ('security audits', 'hardening', 'risk posture', 'exposure review'), but lacks synonym/variant expansion (e.g., 'lockdown', 'patching') that would reach the comprehensive level-5 anchor.

4 / 5

Distinctiveness Conflict Risk

Tied to a clear niche ('Bitterbot deployments', 'a machine running Bitterbot (laptop, workstation, Pi, VPS)') with distinct triggers and minimal overlap risk with other skills, matching the level-5 anchor.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Bitterbot-AI/bitterbot-desktop
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.