CtrlK
BlogDocsLog inGet started
Tessl Logo

audit-context-building

Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

50

Quality

55%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/AI-Agents-Safe-Coding-Skills/skills/audit-context-building/SKILL.md

The canonical home for this skill is audit-context-building in sickn33/agentic-awesome-skills

SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body lays out a clear, sequenced analysis methodology with concrete checklists, but it is weakened by redundant sections and by referencing three bundle files that are not actually present, which undercuts both actionability and navigation.

Suggestions

Consolidate the near-duplicate section 1 (Purpose) and section 3 (How This Skill Behaves) into a single section to remove the repetition restated across sections 1, 3, 7, 9, and 10.

Provide FUNCTION_MICRO_ANALYSIS_EXAMPLE.md, OUTPUT_REQUIREMENTS.md, and COMPLETENESS_CHECKLIST.md as actual bundle files under references/, or inline their key content so the skill is self-contained.

Inline a concrete output template (instead of deferring to the missing OUTPUT_REQUIREMENTS.md) so the required analysis format is immediately executable.

DimensionReasoningScore

Conciseness

The methodology is substantive, but section 1 (Purpose) and section 3 (How This Skill Behaves) are near-duplicate bullet lists and the "build context / no vulnerability finding" theme is restated across sections 1, 3, 7, 9, and 10, so it could be noticeably tightened.

3 / 5

Actionability

The per-function checklist (5.1) and numeric quality thresholds (5.4) are concrete, but the actual output template and worked example are deferred to OUTPUT_REQUIREMENTS.md and FUNCTION_MICRO_ANALYSIS_EXAMPLE.md, which do not exist, leaving key details missing.

3 / 5

Workflow Clarity

A clear phased sequence (Phase 1 to 3) is present with a completeness checkpoint (5.5) and an explicit contradiction feedback loop (section 7); the only minor gap is the missing COMPLETENESS_CHECKLIST.md file.

4 / 5

Progressive Disclosure

References are one-level-deep and clearly signaled, but FUNCTION_MICRO_ANALYSIS_EXAMPLE.md, OUTPUT_REQUIREMENTS.md, and COMPLETENESS_CHECKLIST.md do not exist in any bundle directory, so navigation breaks and content that should be bundled or inlined is in a broken middle state.

3 / 5

Total

13

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is third-person and names a clear niche, but it lacks an explicit trigger clause and relies on jargon over natural user phrases, leaving what/when only partially answered.

Suggestions

Add an explicit 'Use when...' trigger clause naming concrete user phrases, e.g. 'Use when the user requests a security audit, codebase review, or threat model before vulnerability hunting.'

Replace jargon ("ultra-granular", "architectural context") with natural trigger terms users actually say, such as "audit", "code review", and "understand a codebase".

List a couple more concrete actions (e.g. trace call chains, map invariants) to lift specificity from 1-2 actions toward comprehensive coverage.

DimensionReasoningScore

Specificity

Names the domain and 1-2 concrete actions ("line-by-line code analysis", "build deep architectural context") but does not list several specific actions, so it is not comprehensive.

3 / 5

Completeness

The "what" is clear, but the "when" is only weakly implied ("before vulnerability or bug finding" is workflow sequencing, not a trigger) and there is no explicit "Use when..." clause, capping completeness at 3.

3 / 5

Trigger Term Quality

"vulnerability" and "bug finding" are natural terms, but "ultra-granular" and "architectural context" lean technical and common variants like "audit", "code review", or "understand a codebase" are missing.

3 / 5

Distinctiveness Conflict Risk

The context-building-before-auditing niche is mostly distinct with only minor overlap risk against general code-review or security-audit skills.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
administrakt0r/AI-Agents-Safe-Coding-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.