CtrlK
BlogDocsLog inGet started
Tessl Logo

container-cve-validator

Validate a CVE against a Red Hat container image using official SBOM attestations, Red Hat VEX data, and CVE metadata from MITRE/OSV.dev.

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./ocp-admin/skills/container-cve-validator/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, well-sequenced workflow with concrete commands, exact JSON schemas, and strong validation checkpoints, delegating large detail blocks to verified one-level-deep references. Its only weaknesses are minor conciseness trim opportunities and some inline detail that could be further externalized.

DimensionReasoningScore

Conciseness

The ~300-line body is dense but almost entirely task-specific procedural knowledge Claude would not already know (script JSON schemas, PURL/EVR matching, VEX gap conditions) with no padding about generic concepts; it earns 4 rather than 5 because some content is repeated (registry classification restated) and a few sections could be tightened.

4 / 5

Actionability

Provides copy-paste-ready bash commands for every helper script with exact arguments, precise JSON return schemas, explicit field mappings, and exact print statements to emit, fully covering the common single-scan and batch cases.

5 / 5

Workflow Clarity

Defines a mandatory Step 0–5 sequence with an execution-contract table, per-step validation checkpoints ('✓ Step N complete'), explicit skip conditions, and feedback loops (auth error -> login -> re-run; SBOM null -> syft fallback; validate_input errors stop the pipeline), satisfying the batch-operation validation requirement.

5 / 5

Progressive Disclosure

SKILL.md delegates the two large detail blobs to clearly signaled one-level-deep references (references/01-vex-validation-procedure.md and references/02-report-template.md, both verified to exist) and names bundled scripts by name; earns 4 rather than 5 because substantial inline content (e.g. the ~30-line Step 2 SBOM matching logic) could itself be split into a reference.

4 / 5

Total

18

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinct, clearly naming the domain and three concrete data sources, but it lacks any explicit 'when to use' trigger guidance, which caps completeness at 3. Trigger keywords are good though a few natural synonyms are missing.

Suggestions

Add an explicit 'Use when...' clause naming natural user triggers, e.g. 'Use when the user asks to validate or check a CVE (or RHSA) against a Red Hat container image.'

Include common synonyms in the description such as 'vulnerability' and 'RHSA advisory' to broaden trigger coverage.

Consider naming the concrete outcomes (e.g. 'determine whether a package is affected and whether a patched image exists') to round out the action list.

DimensionReasoningScore

Specificity

Names the domain ('Validate a CVE against a Red Hat container image') and three concrete data sources/mechanisms ('official SBOM attestations, Red Hat VEX data, and CVE metadata from MITRE/OSV.dev'), which is several specific elements even though only one action verb is used; not a full 5 because it describes a single action rather than multiple distinct actions.

4 / 5

Completeness

The 'what' is clear and concrete, but there is no 'Use when...' clause or equivalent explicit trigger guidance, which per the rubric guidelines caps completeness at 3; it is not a 4 because 'when' is entirely missing rather than weakly implied.

3 / 5

Trigger Term Quality

Includes natural domain terms a user would say — 'CVE', 'Red Hat container image', 'SBOM', 'VEX' — giving good keyword coverage; falls short of 5 because common synonyms such as 'vulnerability' or 'RHSA' are absent.

4 / 5

Distinctiveness Conflict Risk

Targets a narrow, well-defined niche (Red Hat container image CVE validation via SBOM attestations and VEX data) with distinctive trigger terms, making conflict with other skills minimal.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
RHEcosystemAppEng/agentic-plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.