CtrlK
BlogDocsLog inGet started
Tessl Logo

static-analysis

Run Clang Static Analyzer (scan-build) on Z3 source and log structured findings to z3agent.db.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.github/skills/static-analysis/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a strong, executable workflow: concrete commands verified against the bundled script, per-step checkpoints with failure branches, and a complete parameter table. Its main weaknesses are minor — a small amount of intro padding and the unsignaled ../../shared/z3db.py dependency.

DimensionReasoningScore

Conciseness

The body is efficient: each step's Action/Expectation/Result adds concrete operational detail, and commands are shown rather than described. Minor over-explanation remains — the intro sentence "This skill wraps scan-build into a reproducible, logged workflow suitable for regular analysis sweeps and regression tracking" is padding, and the Step 1 Action prose partially duplicates the bash commands. Not a 5 because a few sentences could be trimmed; not a 3 because there is no concept-teaching or real padding.

4 / 5

Actionability

All guidance is copy-paste executable: the three bash invocations reference a real script (scripts/static_analysis.py) whose argparse flags (--build-dir, --output-dir, --timeout, --db, --debug) exactly match the documented parameters, the Step 3 SQL queries are concrete, and example output shows real diagnostic lines. Fully executable with specific examples covering the common cases.

5 / 5

Workflow Clarity

A clear three-step sequence where every step carries an Expectation checkpoint and a Result branch, including failure recovery ("On failure: verify that clang and scan-build are installed and that the build directory contains a valid CMake configuration") and regression interpretation in Step 3. Not a 5 because there is no explicit re-run/re-validate feedback loop after a failure or after addressing findings — the recovery guidance is stated once but not looped.

4 / 5

Progressive Disclosure

Scored against the actual bundle: the single file in scripts/ is correctly referenced via the executable commands, and the amount of content kept inline in SKILL.md (a short workflow plus a parameters table) is appropriate for this size — nothing that belongs in a separate file is inlined. Not a 5 because the Step 3 references to ../../shared/z3db.py are an external, un-signaled path with no indication of what that script does or whether it exists in the bundle.

4 / 5

Total

17

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete, tool-specific, and highly distinctive, but it answers only 'what' — there is no explicit trigger guidance, and natural keyword coverage (e.g., 'static analysis') is thin. The missing 'Use when...' clause caps its completeness at the midpoint of the scale.

Suggestions

Add an explicit trigger clause, e.g. "Use when the user asks to run static analysis, scan-build, or the Clang analyzer on the Z3 codebase, or wants to check for null dereferences and dead stores."

Include natural synonym phrasings users would actually say — "static analysis", "code analysis", "analyzer warnings" — rather than relying solely on the formal tool names.

Consider mentioning the downstream capabilities (comparing against prior runs, regression tracking) so the 'what' coverage extends beyond the two run-and-log actions.

DimensionReasoningScore

Specificity

"Run Clang Static Analyzer (scan-build) on Z3 source" and "log structured findings to z3agent.db" name the domain and two concrete actions with specific tooling, but coverage stops at two actions (no parsing, querying, or regression-tracking verbs). Not a 4 because 'several specific actions' would require a broader list; not a 2 because the actions are concrete and domain-specific rather than generic.

3 / 5

Completeness

The 'what' is clear (run the analyzer on Z3 source, log structured findings to z3agent.db), but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. It is a solid 3 rather than 2 because the 'what' is concrete and unambiguous.

3 / 5

Trigger Term Quality

"Clang Static Analyzer", "scan-build", "Z3", and "findings" are relevant keywords, but the description omits common natural phrasings like "static analysis", "code analysis", or "analyzer" variants a user would say. Matches anchor 3 (some relevant keywords, missing common variations) rather than 4, since more than 'a few' natural terms are absent.

3 / 5

Distinctiveness Conflict Risk

"Clang Static Analyzer (scan-build)", "Z3 source", and "z3agent.db" carve out a clear niche that no other skill would plausibly trigger for. Minimal conflict risk; the anchor 5 example demonstrates the same pattern of concrete, tool-specific triggers.

5 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Z3Prover/z3
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.