CtrlK
BlogDocsLog inGet started
Tessl Logo

1k-auditing-pre-release-security

Audits security and supply-chain risk between two git refs with Codex cross-validation. 预发布安全审计(含 Codex 交叉验证)。Use when performing pre-release security audits, supply-chain reviews, or comparing two git refs for security regressions. Triggers on “预发布审计”, “security audit”, “release audit”, “安全预审”.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Excellent operational content: a fully executable, well-validated A–J workflow with a complete report template and explicit degraded-mode handling. The main improvement opportunities are trimming duplicated rules and splitting the report template and Codex prompt into reference files to shorten the main skill file.

DimensionReasoningScore

Conciseness

The body is dense and assumes Claude's competence (checklists, commands, keyword regexes, no elementary explanations), but has minor padding that could be trimmed: filename-safety rules are stated in both section 1 and section 5, and "The purpose of this step is to get an independent second opinion..." re-explains what the section heading already conveys.

4 / 5

Actionability

Fully executable throughout: concrete git commands (`git rev-parse --verify "${BASE_REF}^{commit}"`), yarn lockfile checks (`yarn install --immutable`), case-insensitive keyword scan patterns, a copy-paste-ready Agent dispatch prompt, and a complete report template covering the common output case.

5 / 5

Workflow Clarity

Steps A–J are clearly sequenced with explicit validation checkpoints (ref verification, working-tree cleanliness check, Codex readiness pre-flight) and error-recovery feedback loops (degraded mode when Codex is unavailable, continue without findings on empty Agent result), plus checklists for the complex multi-phase process.

5 / 5

Progressive Disclosure

Well-organized single-level structure with clear numbered sections and no nested references, but the ~320-line monolithic file inlines a ~90-line report template and the full Codex dispatch prompt that could live in separate reference files; there are no bundle files at all, so everything is carried in SKILL.md.

4 / 5

Total

18

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete about what it does, and explicit about when to use it with bilingual trigger phrases. The only improvement space is broader synonym coverage and sharpening the trigger terms to distinguish it from general security reviews.

DimensionReasoningScore

Specificity

"Audits security and supply-chain risk between two git refs with Codex cross-validation" names the domain and several concrete actions (security regression audit, supply-chain review, two-ref comparison, cross-validation), with minor gaps such as not mentioning dependency/lockfile/CI inspection that the body covers.

4 / 5

Completeness

It clearly answers both "what" (audits security and supply-chain risk between two git refs with Codex cross-validation) and "when" ("Use when performing pre-release security audits, supply-chain reviews, or comparing two git refs... Triggers on ..."), matching the top anchor with concrete trigger phrases.

5 / 5

Trigger Term Quality

Explicit trigger phrases "security audit", "release audit", "预发布审计", "安全预审" plus a "Use when..." clause give good, natural, bilingual coverage, but a few natural synonyms like "security review" or "dependency audit" are missing.

4 / 5

Distinctiveness Conflict Risk

The two-git-ref pre-release audit niche with dedicated trigger phrases is mostly distinct, with only minor overlap risk against generic security-review or code-review skills; not 5 because "security audit" alone could also fire for ordinary single-commit security reviews.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
OneKeyHQ/app-monorepo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.