CtrlK
BlogDocsLog inGet started
Tessl Logo

threat-detection

Use when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry. Covers hypothesis-driven threat hunting, IOC sweep generation, z-score anomaly detection, and MITRE ATT&CK-mapped signal prioritization.

71

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and highly actionable, with executable commands, concrete data tables, and clearly sequenced workflows that include decision checkpoints. Progressive disclosure is solid but could surface the reference file more explicitly.

Suggestions

Add a dedicated 'References' section that explicitly links references/hunt-playbooks.md and documents scripts/threat_signal_analyzer.py, rather than only mentioning the playbook inside Workflow 2.

Make validation steps explicit in the Full Hunt workflow (e.g., a 'confirm or dismiss' triage checkpoint with retry-on-ambiguous guidance) to strengthen the feedback loop.

Trim a few introductory prose sentences that restate the skill's purpose already covered by the description and Overview section.

DimensionReasoningScore

Conciseness

Content is mostly efficient — tight tables, executable commands, and skill-specific methodology rather than re-explaining concepts Claude already knows — with only minor instances of prose that could be trimmed.

4 / 5

Actionability

Provides fully executable, copy-paste-ready bash invocations with concrete flags, JSON file-format examples, and an exit-code table covering the common cases for all three tool modes.

5 / 5

Workflow Clarity

Three clearly sequenced workflows (Quick Hunt, multi-day Full Hunt, Continuous Monitoring) include decision checkpoints like 'If hunt priority ≥ 7… escalate' and exit-code-2 alerting, though a couple of validation steps are implicit rather than explicit.

4 / 5

Progressive Disclosure

A table of contents and well-organized sections plus a one-level-deep reference to references/hunt-playbooks.md and the bundled scripts/threat_signal_analyzer.py give good structure, but the playbook reference is buried inside a workflow step rather than clearly signaled in a dedicated references section.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit 'Use when…' trigger, multiple concrete capabilities, and a clear niche that distinguishes it from adjacent security skills. Minor room to add a few more natural synonyms, but it is already comprehensive and clear.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'analyzing IOCs', 'detecting behavioral anomalies in telemetry', 'IOC sweep generation', 'z-score anomaly detection', and 'MITRE ATT&CK-mapped signal prioritization' — giving comprehensive coverage rather than vague abstraction.

5 / 5

Completeness

Explicitly answers 'when' with a 'Use when…' clause and 'what' with 'Covers hypothesis-driven threat hunting, IOC sweep generation…', satisfying both requirements with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural phrases like 'hunting for threats', 'analyzing IOCs', and 'detecting behavioral anomalies in telemetry' map to what a SOC analyst would say, but a few common synonyms or shorthand variants are missing.

4 / 5

Distinctiveness Conflict Risk

The proactive threat-hunting niche (hypothesis-driven hunting, IOC sweeps, anomaly detection) is clearly distinct from incident-response and red-team work, minimizing wrong-skill triggering.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 4 suspicious

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.