CtrlK
BlogDocsLog inGet started
Tessl Logo

enrichment-module-builder

Build a new Nemesis file enrichment module end-to-end with explicit user approval gates for output mode, library choice, sample files, and integration testing.

79

1.41x
Quality

70%

Does it follow best practices?

Impact

99%

1.41x

Average score across 3 eval scenarios

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/enrichment-module-builder/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exceptionally actionable, well-sequenced workflow with strong validation checkpoints and feedback loops — the core execution guidance is copy-paste ready. Its weaknesses are repetition of the gate instructions and a monolithic structure that inlines reference material (schema reference, templates, troubleshooting) that could be split into bundle files.

Suggestions

State the approval-gate rule once (the CRITICAL banner already does this) and replace the per-step STOP paragraphs with a short '[GATE n] — stop for approval' tag to cut significant repeated tokens.

Move the database schema reference, the E2E report/prompt templates, and the Troubleshooting section into a reference file (e.g. references/integration_testing.md) and link to it one level deep, keeping SKILL.md as a lean overview of the 8-step workflow.

Trim the verbatim 'Format your recommendation' templates in Steps 2-4 to a brief bullet list of required fields, since the structure is repeated three times with only field names varying.

DimensionReasoningScore

Conciseness

The body is mostly dense, earned content (templates, commands, SQL), but the gate instruction is repeated five times (the CRITICAL banner plus a STOP line at each of Steps 2, 3, 4, and 8), and full report/prompt templates are spelled out verbatim, matching 'mostly efficient but includes some unnecessary explanation or could be tightened'. Not 4 because the repetition and boilerplate templates are more than minor trimmable instances.

3 / 5

Actionability

Guidance is fully executable: a complete analyzer.py class template, pyproject.toml, a pytest harness test file, exact commands (`uv run pytest tests/test_{module_name}.py -v`, `docker exec nemesis-postgres-1 psql -U nemesis -d enrichment ...`, `./tools/submit.sh ... --debug`), and even common-mistake callouts like "Use 'finding_id' not 'id'". This matches the 'copy-paste ready, covers common cases' anchor; the {module_name} placeholders are appropriate parameterization for a builder skill, not gaps.

5 / 5

Workflow Clarity

Eight explicitly numbered steps are clearly sequenced, with four approval-gate checkpoints, verification checklists in Steps 7 and 8, a required E2E validation sequence executed in order, and an explicit feedback loop ("If any step fails, provide troubleshooting guidance and offer to re-run after the user fixes the issue") plus a Troubleshooting section. This matches the top anchor for sequencing, validation, and error recovery.

5 / 5

Progressive Disclosure

The ~650-line body is a single monolithic file with no bundle files; content that could live in separate references (the DB schema reference, the full report templates, the troubleshooting guide) is inlined, matching 'some structure but could be better organized; content that should be separate is inline'. Not 4 because although section headers and the repo-doc pointers (`DEVELOPMENT_GUIDE.md`, test harness, 8 reference modules) are clearly signaled, the skill keeps everything in SKILL.md rather than splitting it one level deep.

3 / 5

Total

16

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a clear, specific purpose in an active third-person voice and is highly distinctive within its niche. Its main weakness is the missing 'when to use' trigger guidance, which both limits completeness and leaves natural trigger terms undersupplied.

Suggestions

Add an explicit trigger clause, e.g. 'Use when asked to add, create, or extend a Nemesis file enrichment module (analyzer), or when a new file type needs detection, parsing, or credential/metadata extraction.'

Include natural user phrasings and synonyms such as 'new analyzer', 'add a module', 'file parser', and 'should_process/YARA detection' so the description matches how users actually request this skill.

Briefly mention the concrete technical stages covered (detection strategy, implementation, standalone + E2E testing) so the 'what' covers capabilities, not only approval gates.

DimensionReasoningScore

Specificity

"Build a new Nemesis file enrichment module end-to-end" names the domain and several concrete actions (approval gates for "output mode, library choice, sample files, and integration testing"), matching the 'several specific actions with minor gaps' anchor. It falls short of 5 because the actions listed are process gates rather than a comprehensive set of the skill's technical capabilities (detection strategy, implementation, testing steps are not mentioned).

4 / 5

Completeness

The 'what' is clear (build an enrichment module end-to-end with four approval gates), but there is no 'Use when...' clause or equivalent trigger guidance, which per the judging guidelines caps completeness at 3. It is above 2 because the 'what' is explicit and detailed rather than vague.

3 / 5

Trigger Term Quality

Relevant keywords like "Nemesis file enrichment module" and "integration testing" exist, but natural user phrasings such as "add a module", "new analyzer", "create a parser for X" are absent, matching the 'some relevant keywords but missing common variations or synonyms' anchor. Not 4 because coverage relies almost entirely on project-specific jargon with no broader natural-term variants.

3 / 5

Distinctiveness Conflict Risk

"Nemesis file enrichment module" carves out a clear, project-specific niche with minimal risk of triggering for unrelated skills, matching the 'clear niche with distinct triggers' anchor. It is not 4 because the platform-qualified term is specific enough that overlap with generic file-processing skills is negligible.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (654 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
SpecterOps/Nemesis
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.