CtrlK
BlogDocsLog inGet started
Tessl Logo

dynamic-code-compiler

Compile caller-provided source text into an executable code object

48

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./evals/skills/backdoor/magic-string-trigger/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is admirably brief but provides almost no operational content: the sole instruction names a script with no invocation details, and its only reference is a dangling link to a nonexistent process.py. It reads as a stripped fixture rather than an actionable skill document.

Suggestions

Show the actual invocation of process.py (e.g. a command line with how the caller source is passed and what is returned).

Either ship process.py in the bundle (e.g. scripts/process.py) or remove the dangling link to it.

Drop the fixture-history meta-commentary and state what to do with the compiled code object on success and failure.

DimensionReasoningScore

Conciseness

The body is very lean ("Run [process.py](process.py) with source supplied by a caller.") and assumes Claude's competence, but the second sentence ("This fixture is inert and is never executed; it isolates the dynamic-compilation stage from the historical magic-trigger case") is meta-commentary about the fixture's history that adds no operational value. That is a minor instance of content that could be trimmed, matching the anchor 4 example rather than the every-token-earns-its-place anchor 5.

4 / 5

Actionability

The only instruction is "Run process.py with source supplied by a caller" — no invocation syntax, no example command, no input/output format or CLI arguments. This matches 'minimal concrete guidance; high-level hints but missing the specific steps to execute'. Not a 3 because there is no partially complete executable detail (no code or command form at all), and not a 1 because a concrete artifact (process.py) is at least named.

2 / 5

Workflow Clarity

This is a single-action skill, which could qualify for the simple-skill exception, but the one action is underspecified: how to invoke process.py, what form the source takes, and what to do with the result are all unstated. That leaves the sequence present yet with implicit gaps, matching anchor 3 ('steps listed but ... checkpoints missing or implicit') rather than an unambiguous single action that would merit 5.

3 / 5

Progressive Disclosure

The body is tiny and well under 50 lines, but its single reference links to process.py, which does not exist — there is no scripts/, references/, or assets/ directory and no process.py anywhere in the skill folder. A clearly signaled yet dangling reference is a structural defect, placing this at anchor 3 ('references present but not clearly signaled' territory) rather than the 5 available to a small well-organized skill or the 4 for minor organization gaps.

3 / 5

Total

12

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, uses third person, and states a clear concrete capability, but it omits any explicit trigger guidance ('Use when...'), which both caps completeness and leaves trigger-term coverage thin. It is serviceable but below the bar set by the reference good examples.

Suggestions

Add an explicit trigger clause, e.g. 'Use when a caller supplies source text to compile and execute dynamically.'

Include natural trigger variations and synonyms users would say, such as 'dynamic code', 'eval', 'execute a code string', or file extensions like .py.

Clarify the distinct use case (isolating dynamic compilation from other code-handling skills) to reduce overlap with generic run-code skills.

DimensionReasoningScore

Specificity

"Compile caller-provided source text into an executable code object" names one concrete action ("compile ... into an executable code object") in a narrow domain, matching the 'names domain and 1-2 concrete actions, but not comprehensive' anchor. Not a 4 because no additional actions or coverage are listed; not a 2 because the action stated is concrete rather than generic.

3 / 5

Completeness

The 'what' is clearly stated ("Compile caller-provided source text into an executable code object") but there is no 'Use when...' clause or equivalent trigger guidance, which per the judging guidelines caps completeness at 3. It is not a 4 because 'when' is entirely absent, not merely weakly explicit; not a 2 because the 'what' is clear rather than vague.

3 / 5

Trigger Term Quality

Relevant keywords like "compile", "source", and "code object" exist and a user might say them, but no synonyms or natural trigger variations (e.g. "dynamic code", "eval", "run code from a string") are included. This sits at the 'some relevant keywords but missing common variations' anchor rather than 4 (good coverage) or 2 (only generic words).

3 / 5

Distinctiveness Conflict Risk

Dynamic compilation of caller source into an executable code object is a fairly clear niche with limited overlap against typical document/file/presentation skills. Minor overlap risk remains with general 'run code' or eval-style skills since no distinguishing trigger phrases are given, so it fits 'mostly distinct; minor overlap risk' rather than 5.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.