CtrlK
BlogDocsLog inGet started
Tessl Logo

breach-patterns

Learn from public breach disclosures — extract the audit question each one implies and check your own stack. Capital One IMDS abuse, LastPass vault exfiltration, Okta Lapsus$, Snowflake credential reuse, MOVEit, SolarWinds, Equifax, Target POS, Codecov, Uber, Twilio — what would you check now if your boss said 'could that happen to us?' Use when the user mentions 'breach analysis,' 'lessons learned,' 'security postmortem,' 'breach patterns,' 'breach lessons,' 'has this happened to us,' 'apply breach lessons,' 'preempt breaches,' 'security retrospective,' 'real-world security incidents,' or wants to harden against known attacker playbooks.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable instruction-only skill that earns its length through ten concrete breach patterns with specific audit checks. Scores are uniformly strong with only minor room for tightening and deeper workflow validation guidance.

Suggestions

Add a short validation/review checkpoint to the 'How to use' workflow (e.g. re-confirm each Gap row has an owner and date) to push workflow_clarity toward 5.

Consider extracting the per-pattern 'What happened' narratives into a single references file, keeping only the audit questions and checks inline, to tighten conciseness and improve progressive disclosure.

DimensionReasoningScore

Conciseness

Tight breach summaries that assume Claude's knowledge of IMDS, SSRF, and MFA; minimal padding, with only minor narrative sections that could be trimmed. Not a 5 because the per-pattern 'What happened' paragraphs add some length beyond the essential pattern.

4 / 5

Actionability

Each pattern ends in a concrete 'Check:' list with specific controls (e.g. 'MetadataOptions.HttpTokens: required', metadata endpoints) and cross-references to audit skills; instruction-only but actionable. Not a 5 because guidance is checklist-style rather than copy-paste executable commands.

4 / 5

Workflow Clarity

A clear 4-step sequence (Read, Ask, Map, Decide) with an explicit output format and disposition options; this is an assessment task, so the destructive/batch validation cap does not apply. Minor checkpoint gaps keep it below 5.

4 / 5

Progressive Disclosure

Well-organized into distinct sections with external reading cleanly separated into a References block and no bundle files to navigate. Not a 5 because it exceeds the 50-line simple-skill exception and the 10 inline patterns could conceivably live in reference files.

4 / 5

Total

16

/

20

Passed

Description

90%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, highly specific description with excellent trigger phrase coverage and a clear what/when structure. The only weakness is the second-person voice, which lowers the specificity score per rubric guidelines.

Suggestions

Rewrite in third person ('Extracts the audit question... and checks the organization's stack') to avoid the specificity penalty for second-person voice.

DimensionReasoningScore

Specificity

Names concrete actions ('extract the audit question each one implies and check your own stack') and specific breaches, but uses second person ('check your own stack', 'what would you check'), triggering the mandated -1 penalty from a base of 4.

3 / 5

Completeness

Explicitly answers both 'what' (extract audit questions from breach disclosures and check your stack) and 'when' (a 'Use when...' clause listing concrete trigger phrases), matching the top anchor.

5 / 5

Trigger Term Quality

Comprehensive coverage of natural trigger phrases ('breach analysis', 'lessons learned', 'security postmortem', 'has this happened to us', 'preempt breaches', 'security retrospective') plus synonyms, matching the top anchor.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (preemptive hardening from public breach disclosures) with distinct triggers and minimal overlap risk with other audit skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.