CtrlK
BlogDocsLog inGet started
Tessl Logo

interpolated-database-query

Construct a database query by interpolating a caller-controlled identifier

43

Quality

54%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./evals/skills/sql-injection/database-query/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

33%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is maximally concise but substantively empty: it describes a helper file that is not present in the bundle and provides no instructions, steps, or validation for the work it names. As written it offers context trivia rather than actionable guidance.

Suggestions

Add explicit instructions for the single action this skill performs (e.g., how to run static analysis over query.py, with the exact command), which would lift actionability and workflow clarity.

Ship query.py in the bundle (e.g., under scripts/) or remove the broken link, so the one reference in the body resolves.

Include a validation/verification checkpoint appropriate to database-query analysis so the workflow is not just a bare description.

DimensionReasoningScore

Conciseness

The body is three lean lines with zero padding and no explanation of concepts Claude already knows — 'The inert helper query.py preserves the historical unsafe string construction. Static analysis only; no database is contacted.' Every token is informational, matching 'Lean and efficient; assumes Claude's competence'.

5 / 5

Actionability

The body only describes what query.py is ('preserves the historical unsafe string construction'); it gives no code, commands, or steps for what to actually do, matching 'Entirely vague or abstract; only describes rather than instructs'. It is not 2 because there are not even high-level hints toward executable steps, and the referenced helper file does not exist in the bundle.

1 / 5

Workflow Clarity

No sequence of steps exists at all — no analysis procedure, no commands, no validation checkpoints — matching 'Steps missing or incoherent; no sequence; no validation for risky operations'. The simple-skill exception does not apply because the single action (what to do with query.py) is never stated; even for a database-context skill, the content falls at the bottom anchor rather than the feedback-loop cap of 3.

1 / 5

Progressive Disclosure

The body's sole link '[query.py](query.py)' is a dangling reference — no query.py exists alongside SKILL.md and no references/, scripts/, or assets/ directories are present, so navigation fails entirely. This fits 'Minimal structure; ... references are buried' (broken navigation) rather than 1, since the body is not a monolithic wall of text; it cannot reach the simple-skill 5 because the one reference it makes does not resolve.

2 / 5

Total

9

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description states one clear, specific action in third person but provides no trigger guidance ('Use when...') and few natural search terms — 'caller-controlled identifier' is jargon rather than user language. It is distinct within its niche yet incomplete for triggering purposes.

Suggestions

Add an explicit 'when' clause, e.g. 'Use when reviewing or analyzing code that builds SQL queries by interpolating user input.'

Include natural trigger synonyms users would actually say, such as 'SQL injection', 'unsafe query construction', or 'string interpolation in queries'.

Expand beyond a single action to name what the skill does with the interpolated query (e.g., analyze, review, or report on it).

DimensionReasoningScore

Specificity

The description names a domain ('database query') and one concrete action ('interpolating a caller-controlled identifier'), which matches the anchor 'Names domain and 1-2 concrete actions, but not comprehensive'. It does not list several specific actions, so 4 is too high; the action described is concrete rather than generic, so 2 is too low.

3 / 5

Completeness

The 'what' is clear ('Construct a database query by interpolating a caller-controlled identifier') but there is no 'Use when...' clause or any trigger guidance, which per the guidelines caps completeness at 3. It is not 2 because the 'what' is specific rather than vague, and not 4 because the 'when' is entirely absent rather than weakly present.

3 / 5

Trigger Term Quality

'database query' is a natural phrase a user might say, but 'interpolating a caller-controlled identifier' is technical jargon, and common variations users would actually say (SQL, SQL injection, unsafe query, identifier injection) are missing. This sits at 'Some relevant keywords but missing common variations or synonyms', above the one-generic-keyword level of 2.

3 / 5

Distinctiveness Conflict Risk

'interpolating a caller-controlled identifier' is a narrow, distinctive niche — minimal overlap risk, though it could collide with general SQL/query-building skills. Fits 'Mostly distinct; minor overlap risk with closely related skills' better than the broader overlap of 3.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.