CtrlK
BlogDocsLog inGet started
Tessl Logo

1k-auditing-pre-release-security

Audits security and supply-chain risk between two git refs with Codex cross-validation. 预发布安全审计(含 Codex 交叉验证)。Use when performing pre-release security audits, supply-chain reviews, or comparing two git refs for security regressions. Triggers on “预发布审计”, “security audit”, “release audit”, “安全预审”.

74

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, highly actionable audit workflow with excellent sequencing and validation checkpoints. Its main weakness is that a ~320-line monolithic body inlines sizable templates that could be split into reference files.

Suggestions

Move the full report template (Section 5) and the Codex Agent dispatch prompt (Step I.1) into separate reference files (e.g., references/report-template.md, references/codex-prompt.md) and link to them one level deep to improve progressive disclosure.

Trim explanatory prose such as the Step I purpose paragraph ('The purpose of this step is to get an independent second opinion...') since the cross-validation intent is already clear from the section title and table.

Consider extracting the keyword-scan patterns (Step F) into a reference table so the main body stays a lean overview of the audit procedure.

DimensionReasoningScore

Conciseness

Dense and procedural with little concept padding, though the ~320-line body includes explanatory prose (e.g., the Step I purpose paragraph) and a large inline report template that could be trimmed.

4 / 5

Actionability

Fully executable guidance throughout — concrete git/yarn commands ('git rev-parse --verify', 'yarn install --immutable'), explicit keyword-scan patterns, and a copy-paste-ready Agent dispatch prompt covering common cases.

5 / 5

Workflow Clarity

Clearly sequenced Steps A–J with explicit validation checkpoints (ref verification in Step A, Codex readiness in Step 3, cross-validation/dedup/confidence rules), feedback loops (degraded mode on Codex failure), and checklists.

5 / 5

Progressive Disclosure

Well-organized into numbered sections, lettered steps, and tables, but the skill is a large monolith with no one-level-deep bundle references (the sizable report template and Agent prompt are fully inline); the simple-skill exception does not apply at this length.

4 / 5

Total

18

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-constructed description that states concrete capabilities, gives explicit 'Use when' guidance, and supplies natural bilingual trigger terms. It is third-person and distinct from neighboring skills.

DimensionReasoningScore

Specificity

Names the domain and several concrete actions — 'Audits security and supply-chain risk between two git refs with Codex cross-validation' — covering auditing, supply-chain review, ref comparison, and cross-validation, though not the full breadth (deps, CI) found in the body.

4 / 5

Completeness

Explicitly answers both what ('Audits security and supply-chain risk between two git refs with Codex cross-validation') and when ('Use when performing pre-release security audits, supply-chain reviews, or comparing two git refs... Triggers on...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage in both English and Chinese — 'pre-release security audits', 'supply-chain reviews', 'comparing two git refs for security regressions' plus explicit triggers '预发布审计', 'security audit', 'release audit', '安全预审'.

5 / 5

Distinctiveness Conflict Risk

Clear niche — pre-release security auditing between two specific git refs with Codex cross-validation — with distinctive bilingual triggers that minimize overlap with general security-review skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
OneKeyHQ/app-monorepo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.