CtrlK
BlogDocsLog inGet started
Tessl Logo

variant-analysis

Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

67%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a well-structured variant analysis skill with a clear five-step methodology, good tool selection guidance, and valuable pitfall documentation. Its main strengths are the logical workflow progression and the concrete pitfall examples that add genuine value. Weaknesses include some verbosity in framing sections, lack of executable query examples despite referencing template files, and the absence of bundle files to verify referenced resources.

Suggestions

Add at least one concrete, executable CodeQL or Semgrep query example showing pattern evolution from specific to generalized, rather than only referencing template files

Trim the 'When to Use' and 'When NOT to Use' sections — Claude can infer appropriate usage from the skill description and process steps

DimensionReasoningScore

Conciseness

The skill is reasonably efficient but includes some unnecessary framing (e.g., 'You are a variant analysis expert' preamble, the 'When to Use' and 'When NOT to Use' sections are somewhat verbose). The pitfalls section, while valuable, is lengthy with examples that could be more compact. The tables and key principles are well-structured but some content could be tightened.

3 / 5

Actionability

Provides concrete guidance with the five-step process, includes a ripgrep command example, clear tables for tool selection and abstraction points, and specific thresholds (50% FP rate). However, it lacks executable CodeQL/Semgrep query examples despite referencing template files, and the generalization steps are somewhat abstract without showing actual pattern evolution examples.

4 / 5

Workflow Clarity

The five-step process is clearly sequenced with logical progression from understanding to triaging. Step 4 includes an implicit feedback loop (generalize → review → revert if needed). However, explicit validation checkpoints could be stronger — there's no formal 'verify your results' step beyond the FP rate heuristic, and the triage step could include more structured verification guidance.

4 / 5

Progressive Disclosure

Good structure with clear sections, references to METHODOLOGY.md for deeper guidance, and organized resource references (CodeQL templates, Semgrep templates, report template). However, no bundle files were provided to verify these references exist, and the inline content is well-balanced between overview and detail. Minor gap: the resources section could better signal what's in each template file.

4 / 5

Total

15

/

20

Passed

Description

95%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This is a strong skill description that clearly communicates its purpose, provides concrete trigger terms, and explicitly states when it should be used. The inclusion of specific tool names (CodeQL/Semgrep) and the precise framing around variant analysis after finding an initial issue make it both distinctive and easy for Claude to match against user requests. Minor improvement could come from listing one or two more concrete actions (e.g., generating detection rules, triaging findings).

DimensionReasoningScore

Specificity

Lists several specific actions: finding similar vulnerabilities, pattern-based analysis, hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, and performing systematic code audits. Minor gaps in coverage (e.g., doesn't mention specific output formats or reporting), but good overall.

4 / 5

Completeness

Clearly answers both 'what' (find similar vulnerabilities and bugs using pattern-based analysis) and 'when' (explicit 'Use when' clause with four concrete trigger scenarios: hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, performing systematic code audits after finding an initial issue).

5 / 5

Trigger Term Quality

Excellent coverage of natural terms users would say: 'vulnerabilities', 'bugs', 'bug variants', 'CodeQL', 'Semgrep', 'security vulnerabilities', 'code audits', 'pattern-based analysis'. These are the exact terms security engineers and developers would use when seeking this functionality.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche: variant analysis and pattern-based vulnerability hunting across codebases. The mention of specific tools (CodeQL, Semgrep), the focus on finding *similar* bugs after an initial finding, and the systematic audit angle make this highly distinct from general security scanning or code review skills.

5 / 5

Total

19

/

20

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
administrakt0r/AI-Agents-Safe-Coding-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.