CtrlK
BlogDocsLog inGet started
Tessl Logo

cost-anomaly-detection

Use when proactively scanning for cost anomalies, unusual spending, unexpected charges, or irregular patterns — during weekly reviews, after incidents, or when something looks off

75

1.25x
Quality

69%

Does it follow best practices?

Impact

100%

1.25x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/cost-analyst/skills/cost-anomaly-detection/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill delivers strong actionability through concrete get_cost_data() invocations and a well-sequenced 11-step workflow with a false-positive validation stage, plus a commendable all-math-in-code rule with security constraints. It is held back by heavy padding — a bloated 11-section output template and four overlapping reference-style sections that should be split into bundle files.

Suggestions

Move the Common Anomaly Types, Advanced Techniques, and Anomaly Detection Techniques sections into a reference file (e.g., references/anomaly-types.md) and keep only a one-line pointer plus the 2-3 most frequent types in SKILL.md, cutting the body roughly in half.

Compress the 11-section Output Format into a single worked example with severity levels and one template per report section, moving the full template to references/report-format.md.

Tighten Step 9 (rate-of-change) into an executable Python snippet consistent with Step 2's outlier code, defining thresholds and variable sources, and merge the four overlapping best-practices/tips sections into one.

DimensionReasoningScore

Conciseness

The 620-line body is noticeably padded: an 11-section output template full of $X,XXX placeholders (~190 lines) plus overlapping back-matter sections ("Anomaly Detection Techniques", "Common Anomaly Types", "Advanced Techniques", "Tips for Effective Anomaly Detection") repeat concepts and re-teach what Claude already knows (z-score formula, percentage change).

2 / 5

Actionability

Seven concrete get_cost_data() calls with real parameters (group_by, granularity, date_range, limit) and mostly executable Python snippets (Step 2 outlier detection, z-score/percentage techniques) give largely copy-ready guidance; minor gaps keep it below fully-executable — Step 9 is pseudocode, recent_costs is never defined, and baseline_costs = [...] placeholders remain.

4 / 5

Workflow Clarity

The 11 steps are clearly sequenced (baseline → total → service → account → resource → region → usage → cross-dimensional → rate-of-change → security/waste → tags → output), with the False Positive Assessment serving as a validation checkpoint. It falls short of a 5 because validation exists only in the output format rather than as explicit in-workflow checkpoints or feedback loops.

4 / 5

Progressive Disclosure

References to ${CLAUDE_PLUGIN_ROOT}/references/*.md are clearly signaled in "See Also", but ~300 lines of output templates, anomaly-type taxonomies, and advanced techniques are inlined in SKILL.md when they belong in reference files — no references/, scripts/, or assets/ bundle files exist to absorb them, so content that should be separate is inline.

3 / 5

Total

13

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-formed description with a clear 'Use when' clause, natural trigger phrases, and good scenario coverage. Its main weakness is an under-specified 'what' — it says the skill scans for anomalies but not what it produces (statistical baselines, severity-classified findings, prioritized action plans).

DimensionReasoningScore

Specificity

"proactively scanning for cost anomalies, unusual spending, unexpected charges, or irregular patterns" names the domain and a single action with concrete target objects, but the skill's real capabilities (severity classification, statistical baselines, prioritized action plans) are absent, matching the 'names domain and 1-2 concrete actions' anchor rather than the several-actions anchor.

3 / 5

Completeness

The 'when' is explicit and multi-scenario ("during weekly reviews, after incidents, or when something looks off") and a 'what' is present ("scanning for cost anomalies"), but the what is thin — no mention of the report, severity classification, or recommendations the skill produces — so it falls short of clearly and explicitly answering both.

4 / 5

Trigger Term Quality

Natural user phrases like "cost anomalies", "unusual spending", "unexpected charges", and "when something looks off" provide good synonym coverage across scenarios ("weekly reviews", "after incidents"), though common variants like "spike", "billing", or "why did costs go up" are missing.

4 / 5

Distinctiveness Conflict Risk

Cost anomaly detection is a clear niche with distinct triggers, but broad phrases like "irregular patterns" and "something looks off" create minor overlap risk with sibling cost-analysis or waste-identification skills in the same plugin.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (622 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
Cloudzero/cloudzero-claude-marketplace
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.