CtrlK
BlogDocsLog inGet started
Tessl Logo

skill-vetter

Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./configs/microservice/bff-service/configs/agent-skills/security/skill-vetter/SKILL.md

The canonical home for this skill is skill-vetter in netease-youdao/LobsterAI

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actionable vetting protocol with concrete checklists, commands, and a clear output format, and it stays lean without explaining known concepts. Its main gaps are the absence of explicit validation/error-recovery checkpoints in the workflow and decorative formatting overhead.

Suggestions

Add validation checkpoints to the protocol, e.g. 'If any file cannot be read or is obfuscated, classify as HIGH risk' and a re-check step before issuing the final verdict.

Trim decorative ASCII box art and consolidate the 'Remember' section, which repeats guidance already implied by the trust hierarchy and risk table.

Give concrete guidance for the mandatory code review step, such as specific commands or patterns for scanning a downloaded skill directory.

DimensionReasoningScore

Conciseness

The body is efficient — checklists, a table, and commands with no explanations of concepts Claude already knows — but the ASCII divider lines, decorative box art, the partly redundant 'Remember' section, and the tagline are minor padding that could be trimmed.

4 / 5

Actionability

Provides a concrete red-flag checklist, permission-scope questions, a risk decision table, executable GitHub API curl commands, and a fill-in report template; minor gaps remain, such as 'Read ALL files in the skill' giving no method for how to review them.

4 / 5

Workflow Clarity

Steps 1-4 are clearly sequenced with a risk-classification table and report output acting as checkpoints; however there is no explicit validation or error-recovery loop (e.g., what to do when a file cannot be read or when findings are ambiguous), which keeps it below the top anchor.

4 / 5

Progressive Disclosure

No bundle files exist and the single SKILL.md is well-sectioned with all content appropriately inline (when-to-use, protocol, output format, trust hierarchy); minor organization gaps from the ASCII-box formatting and inconsistent checklist styles keep it from a top score.

4 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly and explicitly states both what the skill does and when to use it, with natural trigger terms and a distinct niche. Its main weakness is that the capability list leans on generic terms ('red flags', 'suspicious patterns') rather than concrete actions.

Suggestions

Replace generic phrases like 'red flags' and 'suspicious patterns' with concrete capabilities, e.g. 'Scans skill files for credential access, data exfiltration, obfuscated payloads, and over-broad permissions'.

Add natural trigger synonyms such as 'audit', 'security check', or 'review a skill before installing' to broaden keyword coverage.

State the output the user gets (a vetting report with a risk level and install verdict) so the 'what' is fully concrete.

DimensionReasoningScore

Specificity

Names the domain ('skill vetting') and lists actions, but 'red flags' and 'suspicious patterns' are generic and overlapping rather than concrete; fits the anchor for 1-2 concrete actions without comprehensive coverage rather than the several-specific-actions anchor.

3 / 5

Completeness

Explicitly answers both what ('Checks for red flags, permission scope, and suspicious patterns') and when ('Use before installing any skill from ClawdHub, GitHub, or other sources') with concrete trigger phrases, matching the top anchor rather than the weaker-'when' anchor at 4.

5 / 5

Trigger Term Quality

'vetting', 'installing any skill', 'ClawdHub', and 'GitHub' are natural terms a user would say, giving good keyword coverage; common synonyms like 'audit', 'security check', or 'review before install' are missing, so it falls short of comprehensive coverage.

4 / 5

Distinctiveness Conflict Risk

It occupies a clear niche (pre-install security vetting) with distinct triggers like 'ClawdHub' and 'installing any skill'; only minor overlap risk with general security-review skills keeps it below the minimal-conflict anchor.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
UnicomAI/wanwu
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.