CtrlK
BlogDocsLog inGet started
Tessl Logo

cve-recon

Query MITRE, OSV.dev, and Go vulnerability database to produce a structured report of affected packages, ecosystems, and vulnerable version ranges for a CVE.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./ocp-admin/skills/cve-recon/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is well-structured and actionable with a concrete fetch command and explicit error handling, but it is somewhat verbose due to three largely redundant inlined output-format templates. Progression and workflow are solid with only minor gaps.

Suggestions

Consolidate the three output-format templates by sharing the field definitions once and showing only the format-specific shape for markdown/JSON/CSV, reducing redundancy.

Add one short worked example with a real (or representative) CVE and its expected output to lift actionability from concrete-spec to copy-paste-ready.

Move the full JSON schema and CSV column spec into a references/ file and link to it, keeping SKILL.md as a lean overview with the key command and field summary.

DimensionReasoningScore

Conciseness

The body avoids explaining concepts Claude already knows, but the three full inlined output templates (markdown, JSON, CSV) are long and partially redundant across formats, and could be tightened.

3 / 5

Actionability

It provides a concrete copy-paste command, a script-directory existence check, and complete output-format specs; the only minor gap is that templates are placeholder schemas with no worked example using real data.

4 / 5

Workflow Clarity

A clear sequence runs from input validation through script resolution, fetching, explicit error handling, to output, with checkpoints for format and file existence; the only gap is the absence of an explicit retry/feedback loop.

4 / 5

Progressive Disclosure

Section structure is clear, the referenced helper script (scripts/fetch_cve_metadata.py) exists in the bundle, and external doc links are clearly signaled with no nested references; the large inlined output templates are a minor organization gap.

4 / 5

Total

15

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and names concrete sources and outputs, but it omits any explicit 'when to use' trigger guidance, which caps completeness. Trigger-term coverage is good but not exhaustive.

Suggestions

Add a 'Use when...' clause stating natural trigger conditions, e.g. 'Use when the user asks to look up a CVE, find affected packages, or get vulnerable version ranges.'

Include a few more natural synonyms users might say (e.g. 'security advisory', 'vulnerability lookup') to broaden trigger-term coverage.

Disambiguate from sibling skills by noting this is the read-only recon step that feeds container-cve-validator / coreos-cve-validator.

DimensionReasoningScore

Specificity

Names three concrete data sources (MITRE, OSV.dev, Go vulnerability database) and three concrete output dimensions (affected packages, ecosystems, vulnerable version ranges), but it is essentially one composite query-to-report action rather than multiple distinct actions.

4 / 5

Completeness

It clearly answers 'what' (query sources to produce a structured report) but provides no 'Use when...' clause or equivalent trigger guidance, so per the rubric completeness is capped at 3.

3 / 5

Trigger Term Quality

Includes natural terms a user would say ('CVE', 'vulnerability', 'affected packages', 'version ranges'), but omits common synonyms such as 'security advisory' or 'look up', leaving a few natural terms missing.

4 / 5

Distinctiveness Conflict Risk

It targets a distinct CVE-lookup niche with specific sources and output, but related CVE-validator skills exist in the same family, creating minor overlap risk.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
RHEcosystemAppEng/agentic-plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.