CtrlK
BlogDocsLog inGet started
Tessl Logo

audit-log

Durable, access-scoped, append-only record of who changed what app data, when, and whether it was the agent or a human. Use when adding an activity feed or change history, declaring what a mutating action targets, auditing sensitive reads, or answering "what did the agent change / who edited this".

67

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Excellent single-file reference: highly actionable with copy-paste code, exact flags and env vars, and explicit anti-patterns, organized under clear headers with no wasted explanation. The main improvement lever is moving rot-prone inventory (the enumerated admins event types, detailed filter API) into a reference file or trimming it to protect conciseness.

DimensionReasoningScore

Conciseness

The body is dense and assumes Claude's competence — exact config keys, terse rules, no padding about what auditing is. It falls to anchor 4 rather than 5 because of time-sensitive inline inventory ('The `admins` events today: default model (`agent-default-model`), app member roles, app permission roles...') that will rot, and a Settings-page paragraph that partially duplicates the action reference; per the rubric's time-sensitivity guideline this penalizes conciseness.

4 / 5

Actionability

Fully executable, copy-paste-ready guidance throughout: complete defineAction code with real audit fields, a named import path ('@agent-native/core/audit') with both action and Nitro-route usage, exact override flags ('audit: { onRead: true }', 'recordInputs: false'), concrete filter/paging semantics for each read action, and exact env vars (AGENT_NATIVE_AUDIT_RETENTION_DAYS, AGENT_NATIVE_AUDIT_ENABLED). The only elided code (the run body) is app-specific and its omission is justified.

5 / 5

Workflow Clarity

This is a reference/config skill rather than a multi-step pipeline, and it contains no destructive or batch agent operation, so the validation cap does not apply. Each task has unambiguous guidance (defaults, override flags, helper functions for org settings, named read actions, an explicit 'Never' checklist), matching anchor 4; it stops short of 5 only because the sections are parallel guidance rather than a sequenced workflow with explicit checkpoints.

4 / 5

Progressive Disclosure

The skill is a single self-contained file (no references/, scripts/, or assets/ exist) with clear section headers, no nested or buried references, and easy in-file navigation — matching anchor 4. It is not a 5 because reference-grade inventory (the visibility table, the enumerated admins event types, the full filter API) is inlined where a separate reference file could keep SKILL.md leaner, though at ~150 lines the single-file choice is defensible.

4 / 5

Total

17

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that explicitly answers both what the skill provides and when to use it, with natural trigger phrases including a quoted user question. Minor room to grow: adding synonyms like 'audit trail' or 'change log' and clarifying the boundary versus product analytics would push trigger quality and distinctiveness to 5.

DimensionReasoningScore

Specificity

The description concretely defines the capability ('Durable, access-scoped, append-only record of who changed what app data, when') and the use-when clause enumerates specific tasks (activity feed, change history, declaring targets, auditing sensitive reads). It sits at anchor 4 rather than 5 because the 'what' is a single well-formed definition rather than a list of multiple discrete operations, and above 3 because coverage of capability and use cases is broad and concrete.

4 / 5

Completeness

Both halves are explicit: the 'what' is a clear, concrete definition of the record, and the 'when' is an explicit 'Use when...' clause with concrete trigger phrases including a verbatim user question. This matches the anchor-5 example pattern exactly.

5 / 5

Trigger Term Quality

Natural phrases users would actually say are present: 'activity feed', 'change history', 'what did the agent change / who edited this', 'auditing sensitive reads'. This matches anchor 4 — good keyword coverage but missing common synonyms such as 'audit trail' or 'change log' that would earn a 5.

4 / 5

Distinctiveness Conflict Risk

Terms like 'audit', 'activity feed', and 'who edited this' carve a distinct niche with minimal conflict risk, but the description borders on product-analytics/tracking territory without signaling that boundary, so anchor 4 ('mostly distinct; minor overlap risk with closely related skills') is the best fit rather than 5.

4 / 5

Total

17

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

13

/

16

Passed

Repository
BuilderIO/agent-native
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.