CtrlK
BlogDocsLog inGet started
Tessl Logo

soc-operations

Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst tiering, and shift handoffs. Use when the user mentions 'SOC,' 'security operations,' 'SOC analyst,' 'alert triage workflow,' 'runbook,' 'escalation,' 'on-call,' 'SOC tiering,' 'tier 1 / tier 2,' 'MTTD,' 'MTTR,' 'alert fatigue,' 'alert tuning,' 'shift handoff,' 'SOAR,' or wants to design or improve a security operations team.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable body organized around three clear modes, with concrete templates, thresholds, and decision rules rather than abstract advice. Its main gaps are the absence of any bundle files (all detail is inlined in SKILL.md) and a missing verification step in the Build workflow.

Suggestions

Move the runbook template and the standards/book reference list into references/ files (e.g., references/runbook-template.md, references/further-reading.md) to keep SKILL.md a leaner overview with one-level-deep pointers.

Add an explicit validation step to Build mode — e.g., 'Before declaring the SOC operational, fire a test alert through the full path and confirm it reaches Tier 2 within the target SLA.'

Trim editorial asides ('Senior, expensive,' 'Slack is for chatter') that add tone but no instruction.

DimensionReasoningScore

Conciseness

The body is dense and operational — nearly every line carries a specific number, threshold, or criterion (staffing math, KPI targets, escalation timings) — but occasional editorial flavor ('Senior, expensive, the ones building the SOC's capability'; 'Slack is for chatter; the audit trail is in the ticket') could be trimmed. Not 3, since there is no padded explanation of concepts Claude already knows; not 5, since the flavor commentary costs tokens without adding instruction.

4 / 5

Actionability

Fully concrete guidance throughout: a complete runbook template with placeholder structure, an escalation table with exact timings and conditions, KPI targets with numbers ('> 30% TP rate,' '< 25 alerts per analyst per shift,' 'MTTD < 5 min'), a tuning loop with a retire-vs-tune decision rule, and an output-format template. For an instruction-only skill this is copy-paste-ready coverage of the common cases.

5 / 5

Workflow Clarity

The three modes (Build / Run / Improve) are clearly sequenced, and the tuning loop is a numbered workflow with an explicit decision checkpoint ('if TP rate < 30%, tune or retire'); the handoff checklist adds a feedback mechanism. Not a destructive/batch skill, so no validation cap applies; not 5 because Build mode lacks a verify step (e.g., testing the escalation path with a simulated alert before declaring the SOC operational).

4 / 5

Progressive Disclosure

Well-organized sections with clear mode-based structure and clearly signaled cross-references to sibling skills, but the entire ~210-line body is inlined with no bundle files — the runbook template and the book/standards reference list are candidates for separate reference files. Not 5 because this is not a thin overview pointing to one-level-deep reference files; not 3 because the inlined content is well-sectioned and the structure is easy to navigate.

4 / 5

Total

17

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that explicitly answers what the skill does and when to use it, with comprehensive, natural trigger terms. The only weakness is that a few generic terms (escalation, on-call, runbook) could also fire for adjacent incident-response or detection-engineering skills.

Suggestions

Disambiguate the generic trigger terms by scoping them (e.g., 'SOC escalation policy' instead of bare 'escalation') to reduce overlap with incident-triage and siem-detection skills.

Clarify 'fidelity KPIs' — an unusual term that doesn't obviously map to a user utterance; consider 'alert fidelity / true-positive rate KPIs' instead.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete capabilities — 'alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst tiering, and shift handoffs' — giving comprehensive rather than minor-gap coverage of the domain.

5 / 5

Completeness

Both halves are explicit: the 'what' ('Build, run, and improve a Security Operations Center' with enumerated sub-capabilities) and the 'when' ('Use when the user mentions ... or wants to design or improve a security operations team'), matching the top anchor exactly.

5 / 5

Trigger Term Quality

Trigger list covers natural phrasings and synonyms comprehensively: 'SOC,' 'security operations,' 'SOC analyst,' 'alert triage workflow,' 'runbook,' 'escalation,' 'on-call,' 'MTTD,' 'MTTR,' 'alert fatigue,' 'alert tuning,' 'shift handoff,' 'SOAR,' plus the paraphrase 'wants to design or improve a security operations team.'

5 / 5

Distinctiveness Conflict Risk

The SOC niche is clear and mostly distinct, but generic trigger terms like 'escalation,' 'on-call,' and 'runbook' also apply to closely related sibling skills (incident-triage, siem-detection), creating minor overlap risk rather than minimal conflict.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.