CtrlK
BlogDocsLog inGet started
Tessl Logo

finding-triage

Triage a single security finding — from a scanner, audit, advisory, or report — to a defensible disposition with a mitigation plan, false-positive justification, or accepted-risk writeup. Use when the user mentions 'triage this finding,' 'is this a real vulnerability,' 'mitigation plan,' 'false positive,' 'accept this risk,' 'compensating controls,' 'risk justification,' 'security ticket,' 'CVSS this,' 'should we fix this,' 'disposition,' 'sign off on,' or has a single security finding and needs to decide what to do.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a strong, actionable triage workflow: concrete templates with required fields, decision tables, an explicit validation step, and escalation/boundary guidance. It is well-structured for a single-file skill, with only minor conciseness and organization room for improvement.

Suggestions

Tighten the editorial prose in Steps 2–4 (e.g. the 'risk-laundering' and false-positive-volume commentary) to lean imperative guidance, trimming tokens without losing the decision logic.

Consider extracting the four disposition templates into a referenced file (e.g. templates.md) if the skill grows further, keeping SKILL.md as an overview that signals the templates one level deep.

DimensionReasoningScore

Conciseness

The body is mostly efficient — decision tables and copy-paste templates earn their tokens — but a few prose passages (e.g. 'Half of automated-scanner findings are false positives by volume,' 'risk-laundering' commentary) could be trimmed without losing guidance, sitting just below the lean-and-efficient anchor.

4 / 5

Actionability

Provides four fully-specified disposition templates with concrete required fields plus decision tables for false-positive checks and severity adjustment; the guidance is copy-paste ready and covers the common cases, matching the top anchor for an instruction-only skill.

5 / 5

Workflow Clarity

A clear six-step sequence (Restate → Is it true → Severity → Disposition → Writeup → Validate) with an explicit validation checklist (Step 6), an escalation section, and boundary guidance provides the explicit checkpoints and feedback loops the top anchor asks for.

5 / 5

Progressive Disclosure

A single well-organized file with clear section headers; templates are appropriately inline as core output and the References section points one level deep to external standards, with only minor organization gaps versus the ideal overview-plus-references split.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it names the domain, lists concrete disposition outputs, and provides an exhaustive set of natural trigger phrases in an explicit 'Use when' clause, all in third person. It is clearly distinguishable from sibling security skills that generate rather than close out findings.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'mitigation plan,' 'false-positive justification,' 'accepted-risk writeup,' and 'defensible disposition' — for a clearly named domain (triaging a single security finding), matching the comprehensive-coverage anchor.

5 / 5

Completeness

Explicitly answers both what (triage a single finding to a disposition with mitigation/FP/accept-risk writeup) and when (a 'Use when...' clause with many concrete trigger phrases), matching the top anchor.

5 / 5

Trigger Term Quality

Quoted natural triggers span the full user vocabulary ('triage this finding,' 'is this a real vulnerability,' 'false positive,' 'accept this risk,' 'compensating controls,' 'CVSS this,' 'should we fix this,' 'sign off on') including synonyms, matching the comprehensive-coverage anchor.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche — single-finding disposition triage — explicitly contrasted with finding-generating skills, with distinct triggers and minimal overlap risk.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.