CtrlK
BlogDocsLog inGet started
Tessl Logo

crypto-key-rotation

AES 密钥轮换设计与开发指南,涵盖 AES_KEY_SHA 指纹、CryptoHelper、CryptoKeyRefreshWriter、历史密钥 used-*-keys、aes.refresh 启动刷新任务。当用户新增加密表字段、接入密钥轮换、修改 Token/凭证/证书加解密、配置 aes.refresh 或 used-git-keys 时使用。

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./ai/skills/crypto-key-rotation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An extremely lean pointer skill that is maximally token-efficient, but it delegates nearly all actionable content to an external document outside the skill bundle. It names the four implementation chains and a mandatory startup task, yet provides no executable steps or validation checkpoints inline for what is a batch data-reencryption operation.

Suggestions

Inline a minimal quick-start in SKILL.md — the four chains with one concrete example each (e.g., the AES_KEY_SHA column DDL, a CryptoHelper call, the CryptoKeyRefreshStartup registration) — so the skill remains useful even if the external doc is unreachable.

Add an explicit validation checkpoint for the rotation workflow (e.g., verify old rows decrypt with historical used-*-keys before/after running aes.refresh), since key rotation is a batch operation and missing validation caps workflow quality.

Move or copy the guide into references/ inside the skill bundle (or note that the skill is repo-embedded), so the single reference is self-contained and resolvable rather than depending on ../../../docs/.

DimensionReasoningScore

Conciseness

The body is two sentences plus one link — "完整设计与开发指南见 [docs/dev/crypto_key_rotation.md]…" and "必须先阅读该文档,再按其中的四条链路(DDL / DAO / Helper / Writer)实现" — with zero padding and no explanation of concepts Claude already knows; every token earns its place.

5 / 5

Actionability

There is some concrete guidance (the four named chains DDL/DAO/Helper/Writer, the mandatory "CryptoKeyRefreshStartup" addition with a section pointer "见文档 5.5"), but all executable specifics — code, commands, actual steps — are deferred entirely to an external document, matching the anchor for incomplete concrete guidance.

3 / 5

Workflow Clarity

A rough sequence exists (read the doc → implement the four chains → add CryptoKeyRefreshStartup for new services), but key rotation is a batch/destructive data operation and no validation or verification checkpoints are stated in the skill itself, so it sits at the anchor for sequence-with-validation-gaps.

3 / 5

Progressive Disclosure

The reference is clearly signaled and only one level deep (SKILL.md → crypto_key_rotation.md), and content is appropriately split. However, the linked doc lives outside the skill bundle at "../../../docs/dev/crypto_key_rotation.md", so navigation depends on repo layout rather than self-contained references/, preventing a top score.

4 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with an explicit trigger clause and concrete named components. Its main weaknesses are the absence of synonyms in trigger coverage, an inconsistent key-pattern term ("used-git-keys" vs "used-*-keys"), and one broad encryption-related trigger that risks overlap with adjacent skills.

DimensionReasoningScore

Specificity

The description names the domain ("AES 密钥轮换设计与开发指南") and enumerates several concrete covered components — "AES_KEY_SHA 指纹、CryptoHelper、CryptoKeyRefreshWriter、历史密钥 used-*-keys、aes.refresh 启动刷新任务" — which is specific, though these are named artifacts rather than action verbs, so it falls short of the fully comprehensive anchor 5.

4 / 5

Completeness

It explicitly answers both questions: a concrete "what" (a design/development guide covering five named mechanisms) and an explicit "when" ("当用户新增加密表字段…或 used-git-keys 时使用") with concrete trigger phrases, matching the anchor-5 example structure exactly.

5 / 5

Trigger Term Quality

The "当用户…时使用" clause supplies natural trigger phrases users would say ("新增加密表字段、接入密钥轮换、修改 Token/凭证/证书加解密、配置 aes.refresh"), but coverage lacks synonyms/variations and contains the inconsistent term "used-git-keys" alongside "used-*-keys", keeping it below anchor 5.

4 / 5

Distinctiveness Conflict Risk

Project-specific names (CryptoKeyRefreshWriter, AES_KEY_SHA, aes.refresh) give it a clear niche with minimal conflict risk, but the broad trigger "修改 Token/凭证/证书加解密" could plausibly fire for general credential/certificate work handled by other skills, so it sits at anchor 4 rather than 5.

4 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 1 suspicious

Warning

Total

14

/

16

Passed

Repository
TencentBlueKing/bk-ci
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.