CtrlK
BlogDocsLog inGet started
Tessl Logo

vuln-research

Research a specific CVE or vulnerability disclosure end-to-end — what version is affected, is your code reachable, is there a public PoC, is there a patch, what's the exposure window, what's the mitigation if you can't patch immediately. Use when the user mentions 'CVE,' 'vulnerability research,' 'is this CVE relevant,' 'zero-day,' 'CISA KEV,' 'GitHub Security Advisory,' 'reachability analysis,' 'patch analysis,' 'exploit availability,' 'EPSS,' 'CVSS,' or 'should we drop everything and patch this.'

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, highly actionable research workflow: concrete commands, explicit sources, decision branches, and a closing verification step, with no filler explaining concepts Claude already knows. The main gap is structural — a ~190-line monolithic body with no bundle files, where the output template, traps catalog, and reference links could be split into one-level-deep reference files to keep SKILL.md a lean overview.

Suggestions

Move the Output Format template and the 'Common research traps' catalog into a reference file (e.g. references/output-format.md and references/traps.md) and link them from the body, keeping SKILL.md as a lean workflow overview.

Trim editorial flavor text such as 'the high-leverage step', 'patch but don't panic', and 'Future-you will want to revisit' to tighten token usage without losing guidance.

Replace the generic tail References list (NVD, CISA, GitHub, MITRE, Project Zero) with only the links actually used in the workflow steps, since the step-1 section already contains the canonical URLs.

DimensionReasoningScore

Conciseness

The body is efficient and assumes Claude's competence (no explaining what a CVE or lockfile is), but carries minor trimmable flavor — 'the high-leverage step', 'patch but don't panic', 'Future-you will want to revisit' — plus a tail References list of mostly generic pointers. This fits 'efficient; minor instances of over-explanation that could be trimmed' rather than 5, where every token would earn its place.

4 / 5

Actionability

Guidance is fully executable: canonical URLs for NVD/GHSA/CISA/EPSS, copy-paste commands ('npm ls <package>', 'git tag --contains <commit>', lockfile greps), an EPSS interpretation table with thresholds, a complete output-format template, and trap-specific remedies. It matches 'fully executable; copy-paste ready code or commands; specific examples cover the common cases'.

5 / 5

Workflow Clarity

Seven explicitly numbered steps with clear sequencing, decision branches (patch / mitigate / accept), evidence requirements ('Don't write "not reachable" without showing the work'), a four-outcome reachability taxonomy including 'Unknown', and an explicit verification checkpoint ('confirm via npm ls / lockfile that the patched version is actually deployed'). This matches 'clear sequence with explicit validation steps' and feedback/checkpoint guidance.

5 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are absent), and the ~190-line body inlines everything — the output-format template, the 'Common research traps' catalog, and the References list are candidates for one-level-deep reference files. Section structure itself is good and navigation is easy, so this is 'good structure; most content is appropriately placed' (4) rather than 5, which requires content appropriately split into well-signaled reference files.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary skill description: comprehensive and specific about capabilities, with an explicit 'Use when...' clause containing a rich set of natural trigger phrases, synonyms, and acronyms. It uses third person, avoids fluff, and carves out a distinct niche that is unlikely to collide with related skills.

DimensionReasoningScore

Specificity

The description enumerates the concrete deliverables of the research — 'what version is affected, is your code reachable, is there a public PoC, is there a patch, what's the exposure window, what's the mitigation' — giving comprehensive coverage of the workflow in third-person voice with no vague padding. It fits the anchor 'lists multiple specific concrete actions; comprehensive coverage' rather than 4, since no meaningful capability of a CVE deep-dive is missing.

5 / 5

Completeness

It explicitly answers both 'what' ('Research a specific CVE or vulnerability disclosure end-to-end' plus the enumerated outputs) and 'when' (a full 'Use when the user mentions...' clause with concrete trigger phrases). This is a textbook match for the anchor 'clearly and explicitly answers both what AND when with concrete trigger phrases'.

5 / 5

Trigger Term Quality

Trigger coverage includes natural user phrasing ('is this CVE relevant', 'should we drop everything and patch this'), synonyms ('zero-day', 'vulnerability research'), and domain acronyms/jargon users actually say ('CISA KEV', 'EPSS', 'CVSS', 'GitHub Security Advisory'). This matches the anchor for comprehensive natural-term coverage including synonyms.

5 / 5

Distinctiveness Conflict Risk

The niche is a per-CVE applicability deep-dive, clearly distinguishable from general security-audit or dependency-surfacing skills, with distinctive triggers like 'CISA KEV', 'reachability analysis', and 'EPSS'. Conflict risk is minimal, matching the 'clear niche with distinct triggers' anchor.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.