CtrlK
BlogDocsLog inGet started
Tessl Logo

remediation

Helps fix security vulnerabilities identified by DryRunSecurity. Activates when the user shares a DryRunSecurity comment (from a GitHub PR or GitLab MR) or asks for help fixing any security finding including SQL injection, XSS, CSRF, SSRF, path traversal, command injection, authentication bypass, authorization flaws, and prompt injection. Researches authoritative sources and applies fixes grounded in the user's specific codebase context.

89

1.16x
Quality

85%

Does it follow best practices?

Impact

100%

1.16x

Average score across 3 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tight, actionable, well-sequenced remediation workflow with a useful context-gathering table and a concrete worked example. Its main defects are minor padding in the preamble, no explicit validation feedback loop after applying a fix, and three referenced bundle files that do not exist, which breaks the otherwise well-signaled progressive disclosure structure.

Suggestions

Add the missing referenced files (DRYRUN_FILTERING.md, FINDING_FORMAT.md, VULNERABILITY_TYPES.md) to the bundle, or remove/inline the links — as written, three of the body's references point to files that are not present.

Turn Step 5's 'suggest verification' into an explicit feedback loop: apply fix → run verification (tests/build/security scan) → if it fails, fix and re-verify before finishing.

Trim the preamble: the three-goal list ('Grounded in authoritative sources / Contextually relevant / Minimal and focused') and 'Each step includes specific actions to take' largely restate what the numbered steps already convey.

DimensionReasoningScore

Conciseness

The body is lean and imperative — a search-pattern table instead of prose, a compact before/after Go example, and no explanation of concepts Claude already knows. Minor padding keeps it out of the level-5 anchor: 'Follow these steps in order. Each step includes specific actions to take.' restates what the section headers already show, and the three-goal preamble ('Grounded in authoritative sources... Contextually relevant... Minimal and focused') partly duplicates content in the steps themselves. Clearly above level 3, which expects unnecessary explanation.

4 / 5

Actionability

Guidance is mostly executable: named tools per step ('Use Glob and Grep to search, Read to examine', 'Use WebFetch'), a concrete table of config/decorator patterns to search for, a copy-paste-ready Go fix with real research URLs, and a commit format template. Not level 5 because only one vulnerability type (SQL injection) has a worked example while the others are delegated to a reference file that is not present in the bundle, leaving minor gaps for the common cases.

4 / 5

Workflow Clarity

A clear five-step ordered sequence ('Parse the DryRunSecurity Finding' → 'Gather Codebase Context' → 'Research the Authoritative Fix' → 'Apply a Contextual Fix' → 'Explain and Verify') with gating checkpoints like 'Do NOT propose a fix until complete' and explicit verification content in Step 5. It sits at level 4 rather than 5 because there is no validate-fix-retry feedback loop — verification is only 'suggested', not an enforced step in the sequence.

4 / 5

Progressive Disclosure

The body itself is well structured with clearly signaled one-level-deep references ('See [DRYRUN_FILTERING.md](./DRYRUN_FILTERING.md)', 'See [FINDING_FORMAT.md](./FINDING_FORMAT.md)', 'See [VULNERABILITY_TYPES.md](./VULNERABILITY_TYPES.md)'), but none of the three referenced files exist in the bundle — there are no reference or bundle directories at all. Navigation as written is broken, so it cannot score at the 'easy navigation' level 4-5 despite the good in-body organization.

3 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: third-person voice, explicit 'Activates when...' trigger clause, comprehensive natural trigger vocabulary, and concrete statements of what the skill does. It answers both 'what' and 'when' clearly with no padding or over-claims.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'fix security vulnerabilities', 'Researches authoritative sources', 'applies fixes grounded in the user's specific codebase context' — and enumerates the concrete scope (SQL injection, XSS, CSRF, SSRF, path traversal, command injection, authentication bypass, authorization flaws, prompt injection). It matches the 'multiple specific concrete actions; comprehensive coverage' anchor and exceeds the level-4 anchor, which expects minor gaps in coverage.

5 / 5

Completeness

Both what and when are explicit: what = 'fix security vulnerabilities identified by DryRunSecurity... Researches authoritative sources and applies fixes grounded in the user's specific codebase context'; when = 'Activates when the user shares a DryRunSecurity comment... or asks for help fixing any security finding'. This matches the level-5 anchor with concrete trigger phrases, exceeding level 4 where the 'when' could be more explicit.

5 / 5

Trigger Term Quality

Natural user phrasings are comprehensively covered: 'DryRunSecurity comment (from a GitHub PR or GitLab MR)', 'asks for help fixing any security finding', plus the full vocabulary users would actually say (SQL injection, XSS, CSRF, SSRF, path traversal, command injection, prompt injection). Not the level-4 anchor because no natural terms are missing — synonyms like 'security finding' and 'security vulnerability' are both present.

5 / 5

Distinctiveness Conflict Risk

The skill has a clear niche anchored to a specific tool ('DryRunSecurity comment', 'GitHub PR or GitLab MR') with distinct trigger terms; it would not naturally fire for unrelated skills. The generic vulnerability names could in principle overlap with a general security-fixing skill, but the vendor-anchored framing keeps conflict risk minimal, fitting the level-5 anchor.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 3 missing

Warning

Total

14

/

16

Passed

Repository
DryRunSecurity/external-plugin-marketplace
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.