CtrlK
BlogDocsLog inGet started
Tessl Logo

external-socket-reporter

Send a diagnostic record over an explicitly external raw socket

40

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./evals/skills/behavioral-analysis/multi-file-exfiltration/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

26%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is terse and free of fluff, but it provides no executable guidance, no workflow, and links to a file (reporter.py) that does not exist in the skill bundle. As written it describes provenance of code ('the historical multi-file flow') rather than telling Claude what to do, making it unusable as an operational skill.

Suggestions

Replace the descriptive paragraph with concrete, executable guidance: how to invoke reporter.py (exact command with arguments for host, port, and record payload) and what a successful send looks like.

Fix the broken reference: either include reporter.py in the skill bundle (e.g. under scripts/) or remove the link and inline the minimal code needed to send the diagnostic record.

State the workflow explicitly — destination/address setup, sending the record, and verifying delivery (e.g. expected response or confirmation) — since even a single-purpose socket skill needs an unambiguous sequence.

DimensionReasoningScore

Conciseness

The body is three sentences with no padding and no explanation of concepts Claude already knows, so it is broadly efficient. It is not a 5 because the sentence "Static evaluation never opens the socket" is meta-commentary about evaluation rather than task guidance, so not every token earns its place.

4 / 5

Actionability

The body only describes ("The inert implementation in [reporter.py](reporter.py) contains the external connection sink... isolated at one source location") without any instruction, command, or code for what to actually do, matching the 'only describes rather than instructs' anchor. It is not a 2 because even the high-level hint is unusable: the referenced reporter.py does not exist in the bundle (no references/, scripts/, assets/, or reporter.py are present).

1 / 5

Workflow Clarity

There is no sequence of steps whatsoever and no validation of any kind, matching the lowest anchor for steps missing or incoherent. Even under the simple-skill exception a single action must be unambiguous, but the body never states an action to perform.

1 / 5

Progressive Disclosure

Structure is minimal (a heading plus one paragraph) and its single reference, the markdown link to reporter.py, is broken because that file is absent from the bundle. It is not a 3 because the simple-skill exception requires well-organized sections, and none exist; it is not a 1 because the one reference that is present is clearly signaled and only one level deep.

2 / 5

Total

8

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and third-person with a clear, specific 'what', but it has no 'when to use' guidance and only thin keyword coverage, so it would rarely be selected over more trigger-rich descriptions. It is serviceable but incomplete by this rubric's standards.

Suggestions

Add an explicit trigger clause, e.g. 'Use when the user asks to send a diagnostic record, report, or payload over a raw network socket to an external host.'

Include natural synonyms and technical variations users would say (network, TCP/UDP, host/port, external endpoint) to improve trigger term coverage.

Mention one or two additional concrete capabilities (e.g. what the diagnostic record contains or how the destination is specified) to lift specificity.

DimensionReasoningScore

Specificity

The description names a concrete action ("Send a diagnostic record") and a concrete transport ("over an explicitly external raw socket"), matching the anchor for 1-2 concrete actions in a named domain. It is not a 4 because only one action is described with no coverage of what else the skill does (e.g. how to configure, where output goes), and not a 2 because the action is specific rather than generic like 'Processes socket data'.

3 / 5

Completeness

The 'what' is clearly stated ("Send a diagnostic record over an explicitly external raw socket") but there is no 'Use when...' clause or equivalent trigger guidance, which per the judging guidelines caps completeness at 3. It is not a 4 because the 'when' is entirely missing rather than merely implicit.

3 / 5

Trigger Term Quality

It contains some relevant keywords users might say ("socket", "diagnostic", "external") but misses common variations and synonyms such as network, TCP/UDP, send data, or report over network. It sits above 2 because the keywords are domain-relevant rather than entirely generic, and below 4 because natural trigger phrases a user would actually utter are largely absent.

3 / 5

Distinctiveness Conflict Risk

"external raw socket" and "diagnostic record" carve out a fairly distinct niche with little overlap risk against typical document/code/data skills. It is not a 5 because without any 'Use when' trigger phrases, closely related networking skills could still contend for the same request.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.