CtrlK
BlogDocsLog inGet started
Tessl Logo

antinet-security-scan

信息安全分析师与软件开发工程师在搭建文档处理流水线时,当需要拦截违规文件或外部URL,请挂载此技能作为强制前置安检,自动输出 pass/reject 判定与详细合规扫描报告,一键守住零信任安全底线。

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/antinet-security-scan/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-structured single-purpose skill body with concrete I/O contracts, named dependencies, explicit failure handling, and a verified runnable script — held just short of top marks by light marketing framing and the script's reliance on the parent package runtime.

DimensionReasoningScore

Conciseness

The body is lean, sectioned, and free of concepts Claude already knows; only minor trims are warranted (the 复用价值 marketing framing and 锦衣卫 branding add a little padding).

4 / 5

Actionability

Provides concrete fields, named dependencies (python-magic, blacklist CSV/JSON), a copy-paste command ('python skills/security-scan/scripts/run_security_scan.py'), and a verified executable entry script — but running it depends on the surrounding package's core.runtime.AgentSession, a minor gap.

4 / 5

Workflow Clarity

The single gate action is unambiguous and the 失败处理 section gives explicit error-recovery decisions (reject+alert, conservative full-reject fallback); the main flow is not explicitly step-sequenced, leaving minor checkpoint gaps.

4 / 5

Progressive Disclosure

Well under 50 lines with cleanly organized sections and a single one-level-deep reference to a real bundle file (scripts/run_security_scan.py, verified present), satisfying the simple-skill exception.

5 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description conveys a clear, distinct capability with concrete actions and an explicit when-condition, but is held back by second-person imperative voice, a marketing-tail clause, and slightly scenario-heavy phrasing rather than a crisp capability-plus-trigger statement.

Suggestions

Rewrite in third person and add a clean trigger clause, e.g. 'Intercepts policy-violating files and external URLs in document pipelines, outputting a pass/reject verdict and compliance scan report. Use when a document processing pipeline needs a mandatory pre-ingest security gate.'

Drop the marketing tail '一键守住零信任安全底线' and the audience preamble to cut fluff and over-claims.

Add a couple of natural synonyms (黑名单/域名过滤) to broaden trigger coverage.

DimensionReasoningScore

Specificity

Names the domain and several concrete actions — '拦截违规文件或外部URL', '自动输出 pass/reject 判定与详细合规扫描报告' — but the second-person imperative framing ('请挂载此技能') triggers the voice penalty, reducing the base of 4 by one.

3 / 5

Completeness

Both 'what' (强制前置安检 + pass/reject 判定 + 合规扫描报告) and 'when' ('当需要拦截违规文件或外部URL') are present; the when-clause is an explicit trigger but is embedded in a wordy scenario rather than a clean 'Use when...' statement.

4 / 5

Trigger Term Quality

Good natural keyword coverage — '违规文件', '外部URL', '拦截', 'pass/reject', '合规扫描报告', '文档处理流水线' — though a few synonyms (e.g. 黑名单/域名过滤) are missing and '一键' is marketing rather than a trigger.

4 / 5

Distinctiveness Conflict Risk

The compliance/security-gate niche (拦截违规文件/URL, pass/reject, 零信任) is mostly distinct from sibling skills, with only minor overlap risk against general security-audit skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
anbeime/skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.