CtrlK
BlogDocsLog inGet started
Tessl Logo

siem-detection

Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. Use when the user mentions 'SIEM,' 'detection engineering,' 'detection rules,' 'Sigma,' 'KQL,' 'SPL,' 'Splunk,' 'Sentinel,' 'Elastic,' 'Wazuh,' 'Chronicle,' 'detection-as-code,' 'MITRE ATT&CK mapping,' 'log coverage,' 'alert tuning,' 'use case development,' or needs help building or improving security detections.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, practitioner-grade skill body: concrete code across four SIEM query languages, a genuine tuning lifecycle with feedback loops, and detection-as-code CI guidance. The main weaknesses are minor: placeholder values in the canonical Sigma example, an ES|QL example that doesn't quite work as written, light editorial padding, and no use of reference files for the per-language examples.

Suggestions

Make the Sigma example fully copy-paste ready by replacing the '<UUID>', '<name>', and bare 'date' placeholders with realistic values, and fix the ES|QL example so it actually expresses the create→attach sequence (e.g., a conditional STATS/sequence check rather than 'WHERE create_count > 0').

Trim editorial asides ('future-you will thank you,' the 'LookML' parenthetical) and the generic References tail list, keeping only resources that add information Claude cannot recall reliably.

Move the per-backend query examples (KQL, SPL, ES|QL) into a references/ file (e.g., references/query-languages.md) linked from Step 3, keeping SKILL.md focused on the workflow and the canonical Sigma pattern.

DimensionReasoningScore

Conciseness

The body is dense and mostly token-efficient — tables for log-source categorization and detection-model selection carry a lot of signal per line — but there is minor editorial padding ('future-you will thank you,' the stray 'LookML' parenthetical) and an unfocused tail 'References' list that could be trimmed or tightened. It sits above the 'some unnecessary explanation' anchor but short of 'every token earns its place.'

4 / 5

Actionability

Mostly executable guidance: full Sigma YAML, working KQL/SPL examples, concrete CI commands ('sigma-cli check,' 'sigma convert -t splunk') and a repo layout. Minor gaps keep it below fully copy-paste ready — placeholders like '<UUID>' and '<name>' in the Sigma example, and the ES|QL sample ('WHERE create_count > 0') doesn't actually express the create→attach sequence it parallels.

4 / 5

Workflow Clarity

Six clearly sequenced steps with an explicit feedback loop in the tuning lifecycle — deploy experimental, review every fire, narrow or allow-list, track the FP ratio, promote only when acceptable — plus a recovery path for never-fired rules (run a deliberate-test event). CI checks provide pre-deploy validation. This matches the top anchor including feedback loops and error recovery.

5 / 5

Progressive Disclosure

Well-organized single-file skill with clear section headers, a scoped 'This skill covers / does NOT cover' split, and a concrete output template. It sits between anchors: the per-language query examples (Sigma, KQL, SPL, ES|QL) are inline content that would naturally live in a references/ file, but each is short and the overall structure navigates easily — good structure with minor organization gaps rather than content that 'should be separate' dominating.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete capabilities, an explicit and comprehensive 'Use when' trigger clause covering tool names and activity synonyms, and a clearly bounded niche. Both 'what' and 'when' are answered with specific, non-buzzword language in third person.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows' — giving comprehensive coverage of the skill's capabilities, matching the top anchor rather than the 'minor gaps' anchor below it.

5 / 5

Completeness

It explicitly answers both 'what' (a concrete action list prefixed by 'Engineer and audit SIEM detection rules') and 'when' ('Use when the user mentions... or needs help building or improving security detections') with concrete trigger phrases, exactly matching the top anchor.

5 / 5

Trigger Term Quality

The 'Use when' clause enumerates a comprehensive set of natural terms users would say, including tool synonyms ('Sigma,' 'KQL,' 'SPL,' 'Splunk,' 'Sentinel,' 'Elastic,' 'Wazuh,' 'Chronicle') and activity phrases ('detection engineering,' 'alert tuning,' 'use case development'), matching the comprehensive-synonyms anchor.

5 / 5

Distinctiveness Conflict Risk

It carves out a clear niche — detection rule engineering — with tool-specific triggers and phrasing ('detection rules,' 'Sigma,' 'MITRE ATT&CK mapping') that adjacent skills like incident triage or threat hunting would not claim, so conflict risk is minimal.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.