CtrlK
BlogDocsLog inGet started
Tessl Logo

attack-tree-construction

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-attack-tree-construction/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized, appropriately scoped, and takes safety seriously, but it under-delivers on substance: instructions are conceptual rather than executable, the workflow has no validation checkpoints on the produced tree, the authorization warning is duplicated, and the single referenced playbook file is missing from the bundle entirely. It reads as a skeleton for a good skill rather than a complete one.

Suggestions

Fix the broken reference: either ship `resources/implementation-playbook.md` in the bundle or remove the two mentions of it (Instructions and Resources sections) — as written, the skill points to a file that does not exist.

Add a minimal worked example of the output format (a small AND/OR tree with leaf annotations for cost/skill/time/detectability) so the 'decompose' and 'annotate' instructions become concretely executable rather than conceptual.

Deduplicate the safety preamble — merge the two back-to-back AUTHORIZED USE ONLY blocks into one, and trim the 'Use this skill when' bullets that restate the description verbatim.

DimensionReasoningScore

Conciseness

The core instructions are tight, but the body opens with two near-identical authorization warnings ("⚠️ AUTHORIZED USE ONLY" block followed by another "AUTHORIZED USE ONLY: Use this skill only for authorized security assessments..." quote) and the "Use this skill when" bullets restate the frontmatter description almost verbatim. This is more than the "minor instances of over-explanation" of anchor 4, fitting anchor 3's "includes some unnecessary explanation or could be tightened".

3 / 5

Actionability

The instructions give real method substance — "Decompose into sub-goals with AND/OR structure", "Annotate leaves with cost, skill, time, and detectability" — but no worked example, notation sample, or template showing what a produced attack tree looks like, so execution details are left to inference. That lands between anchor 2 ("high-level hints") and anchor 4 ("mostly executable guidance"), at anchor 3's "some concrete guidance but incomplete"; for an instruction-only skill the guidance is specific but not copy-paste actionable.

3 / 5

Workflow Clarity

The instruction bullets imply a sequence (confirm scope → decompose → annotate → map mitigations) and the confirmation gate is an explicit checkpoint for any probing commands, but there are no checkpoints on the construction itself — nothing about validating the tree against scope, reviewing with the stakeholder, or what to do when the model is incomplete. Anchor 3 ("steps listed but validation gaps; sequence present but checkpoints missing or implicit") fits; the operation is not destructive or batch, so no cap applies, but anchor 4's "most checkpoints present" is not met.

3 / 5

Progressive Disclosure

The body is cleanly sectioned (Use when / Do not use / Instructions / Safety / Resources / Limitations) and the reference is clearly signaled in both Instructions and a Resources section, but the referenced file `resources/implementation-playbook.md` does not exist in the bundle — there is no `resources/` directory at all — so the one-level-deep disclosure chain is broken. This is below anchor 4 ("references mostly clear" and functional) and matches anchor 3: structure present, but the reference does not resolve.

3 / 5

Total

12

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-formed description: third-person, concise, with an explicit 'Use when' clause covering multiple concrete triggers. Its main weakness is that the capability list stops at build/visualize and misses the analysis activities (decompose, annotate, map mitigations) that define the skill, and it lacks common synonyms like 'threat modeling'.

Suggestions

Expand the capability list beyond 'build' and 'visualize' to cover the skill's actual actions, e.g. 'Build attack trees, decompose attacker goals into AND/OR sub-goals, annotate paths with cost and detectability, and map mitigations to identify defense gaps.'

Add natural trigger synonyms such as 'threat modeling', 'threat analysis', or 'risk assessment' to the 'Use when' clause so users phrasing the need those ways still trigger the skill.

DimensionReasoningScore

Specificity

"Build comprehensive attack trees to visualize threat paths" names the domain and two concrete actions (build, visualize), but stops there — it omits the decomposition, annotation, and mitigation-mapping work the body actually covers. This matches anchor 3 ("names domain and 1-2 concrete actions, but not comprehensive") rather than anchor 4, which expects a list of several specific actions with only minor gaps.

3 / 5

Completeness

It explicitly answers both: what ("Build comprehensive attack trees to visualize threat paths") and when ("Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders") with concrete trigger phrases. This matches anchor 5; anchor 4 would require the 'when' clause to be less explicit or specific, which it is not.

5 / 5

Trigger Term Quality

"mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders" gives good natural keyword coverage ("attack scenarios", "defense gaps", "security risks", "stakeholders"), but misses common variations a user would say such as "threat modeling", "threat analysis", or "risk assessment". Anchor 4 ("good keyword coverage; a few natural terms missing") fits better than 3, since several natural phrases are present, and better than 5, since synonyms are absent.

4 / 5

Distinctiveness Conflict Risk

Attack-tree/threat-path construction is a clear niche with distinct triggers ("attack trees", "attack scenarios", "defense gaps") that no generic skill would claim, matching anchor 5's "clear niche with distinct triggers; minimal conflict risk". It is far more differentiated than anchor 4's "minor overlap risk with closely related skills".

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.