CtrlK
BlogDocsLog inGet started
Tessl Logo

stride-analysis-patterns

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

52

Quality

59%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/AI-Agents-Safe-Coding-Skills-claude/skills/stride-analysis-patterns/SKILL.md

The canonical home for this skill is stride-analysis-patterns in rmyndharis/antigravity-skills

SKILL.md
Quality
Evals
Security

Quality

Content

36%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a generic placeholder that fails to deliver STRIDE-specific guidance: no concrete methodology steps, no examples, and a broken reference to a non-existent playbook. Its only real strength is brevity.

Suggestions

Replace the generic 'Instructions' bullets with the concrete STRIDE workflow: model the system (data-flow diagram), enumerate threats per STRIDE category (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege), prioritize, and propose mitigations — with a validation/check review step.

Add a short worked example or per-category threat prompt so the guidance is actionable rather than abstract.

Either create the referenced 'resources/implementation-playbook.md' bundle file or remove the broken reference, so progressive disclosure points to real content.

DimensionReasoningScore

Conciseness

The body is lean with no padding or explanation of concepts Claude already knows, though its generic phrasing adds little value; it sits just below the 'lean and efficient, every token earns its place' anchor.

4 / 5

Actionability

Instructions such as 'Apply relevant best practices and validate outcomes' and 'Provide actionable steps and verification' are entirely abstract with no concrete STRIDE steps, examples, or commands — matching the 'entirely vague or abstract' anchor.

1 / 5

Workflow Clarity

Only a rough, generic sequence is present ('Clarify goals… Apply best practices… validate outcomes') with no defined threat-modeling steps (DFD modeling, per-category enumeration, prioritization, mitigation) and no validation checkpoints.

2 / 5

Progressive Disclosure

Sections are organized and a one-level reference to 'resources/implementation-playbook.md' is signaled, but the referenced file/directory does not exist in the bundle, so the structure is only partially realized.

3 / 5

Total

10

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is well-formed: it pairs a clear statement of capability with explicit, natural trigger phrases and occupies a distinct niche. Its only gap is action breadth — it names one core action rather than enumerating several specific threat-identification activities.

DimensionReasoningScore

Specificity

The description names the STRIDE domain and one concrete action ('systematically identify threats'), but does not enumerate several specific actions, matching the '1-2 concrete actions but not comprehensive' anchor.

3 / 5

Completeness

It explicitly answers both what ('Apply STRIDE methodology to systematically identify threats') and when ('Use when analyzing system security, conducting threat modeling sessions, or creating security documentation') with concrete trigger phrases.

5 / 5

Trigger Term Quality

'analyzing system security', 'conducting threat modeling sessions', and 'creating security documentation' are natural phrases users would say, giving good coverage; a few synonyms/extensions are missing so it stops short of comprehensive.

4 / 5

Distinctiveness Conflict Risk

STRIDE-based threat modeling is a clear niche with distinct triggers, creating minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
administrakt0r/AI-Agents-Safe-Coding-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.