CtrlK
BlogDocsLog inGet started
Tessl Logo

1k-auditing-pre-release-security

Audits security and supply-chain risk between two git refs with Codex cross-validation. 预发布安全审计(含 Codex 交叉验证)。Use when performing pre-release security audits, supply-chain reviews, or comparing two git refs for security regressions. Triggers on “预发布审计”, “security audit”, “release audit”, “安全预审”.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, highly actionable audit workflow with clear sequencing and validation, but it is long and keeps content inline that could be externalized into reference files for better progressive disclosure.

Suggestions

Move the full Chinese report template (section 5) into a references file (e.g. report-template.md) and summarize its structure inline, reducing SKILL.md length and improving progressive disclosure.

Extract the Codex Agent dispatch prompt block (Step I.1) into a separate reference so the main body stays a lean overview.

Tighten explanatory prose in Steps I and J (e.g. the cross-validation purpose paragraph and confidence-level rationale) to one line each.

DimensionReasoningScore

Conciseness

The body is mostly tight checklists and commands, but ~320 lines with explanatory prose (the Step I purpose paragraph, confidence-level rationale, "explain why this matters for release determinism") that could be trimmed; not fully lean.

2 / 3

Actionability

Highly actionable: concrete git commands (git rev-parse --verify, git diff --name-status), explicit keyword-scan patterns, exact filename templates, a full Agent dispatch code block, and a copy-paste report template.

3 / 3

Workflow Clarity

Clearly sequenced Steps 0–J with explicit validation checkpoints (ref verification, Codex readiness check, cross-validation/dedup rules); the audit is read-only so the destructive-operation cap does not apply.

3 / 3

Progressive Disclosure

Well-organized into numbered sections, but it is a monolithic single file with no bundle references; the ~90-line report template and the Codex dispatch prompt are large static blocks that could be split into reference files.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-formed description: it states concrete capabilities, gives explicit bilingual triggers, and clearly delimits when to invoke the skill. No over-claims or vague fluff.

DimensionReasoningScore

Specificity

Names multiple concrete actions — "Audits security and supply-chain risk", "Codex cross-validation", "comparing two git refs for security regressions" — in third-person voice, matching the anchor for listing several specific concrete actions.

3 / 3

Completeness

Clearly answers both what ("Audits security and supply-chain risk between two git refs with Codex cross-validation") and when ("Use when performing pre-release security audits... Triggers on...") with explicit triggers.

3 / 3

Trigger Term Quality

Provides explicit natural-language triggers in both English and Chinese ("security audit", "release audit", "预发布审计", "安全预审"), giving good coverage of terms users would actually say.

3 / 3

Distinctiveness Conflict Risk

Carves a clear niche — pre-release security/supply-chain audit between two git refs with Codex cross-validation — with distinct triggers unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
OneKeyHQ/app-monorepo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.