CtrlK
BlogDocsLog inGet started
Tessl Logo

agentlas-security-scan

Use when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to run/interpret `hephaestus security scan`.

73

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable skill body with concrete commands, an exact output contract, and a clear gated workflow with validation. Only slight conciseness gains are available by dropping plan-reference asides.

Suggestions

Drop the 'Plan §6.2' and 'v1 Non-Goal' asides — they reference an external doc Claude cannot see and add no actionable guidance.

Consider moving the full JSON contract into a references/ file if the skill grows, keeping only the field list inline in SKILL.md.

DimensionReasoningScore

Conciseness

Largely lean and efficient with no basic-concept padding, but includes minor unnecessary context ('Plan §6.2', 'v1 Non-Goal: no server-side model execution') that could be trimmed.

4 / 5

Actionability

Fully executable guidance: concrete CLI commands with flags, exact copy-paste JSON contract, and specific file paths cover the common cases.

5 / 5

Workflow Clarity

Clear Stage 1 -> Stage 2 sequence with explicit validation (re-run scan merges judgment) and verdict gating with exit codes plus feedback loops (BLOCK->fix, WARN->user approval); validation is present so no cap applies.

5 / 5

Progressive Disclosure

Self-contained with no bundle files, well-organized into clearly signaled sections (Stage 1, Stage 2, CLI, Output) and no nested references; content is appropriately placed inline.

5 / 5

Total

19

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states both capability and trigger conditions with natural keywords and a distinct niche. Minor room for more synonym/extension coverage in trigger terms.

DimensionReasoningScore

Specificity

Names the domain and several concrete actions ('static rules + BYOK LLM judgment', 'private sync or public publish', 'run/interpret `hephaestus security scan`'), with only minor coverage gaps keeping it below a 5.

4 / 5

Completeness

Explicitly answers both what ('pass the Agentlas Cloud 2-stage security scan') and when ('before private sync or public publish, or when asked to run/interpret') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Includes natural terms users would say ('security scan', 'private sync', 'public publish') plus the literal CLI command, but lacks synonyms or file-extension variants for a 5.

4 / 5

Distinctiveness Conflict Risk

Targets a clear product-specific niche (Agentlas Cloud / hephaestus) with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
agentlas-ai/Agentlas-OS
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.