CtrlK
BlogDocsLog inGet started
Tessl Logo

eicar-test

Test skill containing EICAR test file for malware detection

65

1.17x
Quality

46%

Does it follow best practices?

Impact

100%

1.17x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./evals/test_skills/malicious/eicar-test/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

40%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a brief, organized overview but lacks actionable guidance and a defined workflow — it describes the file rather than instructing how to use it. Progressive disclosure is adequate for such a simple skill.

Suggestions

Add concrete steps or a command showing how the EICAR file is used to trigger the VirusTotal scanner integration.

Trim the explanatory sentence about EICAR not being a virus, or move it to a brief aside, to improve token efficiency.

Specify what Claude should do when this skill is invoked (e.g. where to find the file and how to submit it for scanning).

DimensionReasoningScore

Conciseness

The body is short but spends a sentence explaining what the EICAR file is and that it is 'NOT a virus', which is concept explanation that could be trimmed.

3 / 5

Actionability

It points to the assets folder and states the purpose, but gives no concrete steps, commands, or instructions on what to do with the file — high-level hints only.

2 / 5

Workflow Clarity

A purpose is stated ('used to test the VirusTotal binary file scanner integration') but no steps or sequence are defined; the intended action for Claude is poorly specified.

2 / 5

Progressive Disclosure

For a sub-50-line single-purpose skill, the content is organized into clear sections and references the assets folder where the binary lives; minor organization gaps only.

4 / 5

Total

11

/

20

Passed

Description

52%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a distinct, niche purpose but is terse and lacks a 'when to use' trigger clause. Specificity is low because it describes content rather than actions.

Suggestions

Add a 'Use when...' clause stating when Claude should invoke this skill (e.g. testing antivirus or file-scanner integrations).

Replace 'containing' with a concrete action verb describing what the skill does (e.g. 'Provides the EICAR test file for validating malware-detection integrations').

Include natural synonyms like 'antivirus' or 'AV test' alongside 'malware detection' to broaden trigger coverage.

DimensionReasoningScore

Specificity

It names the domain ('EICAR test file', 'malware detection') but the only action verb is 'containing', which is minimal and generic rather than a concrete capability.

2 / 5

Completeness

It states a clear 'what' (contains an EICAR test file for malware detection) but has no 'Use when...' clause or equivalent trigger guidance, which caps completeness at 3.

3 / 5

Trigger Term Quality

'EICAR test file' and 'malware detection' are relevant natural terms for this niche, but common variations or synonyms (e.g. antivirus, AV test) are missing.

3 / 5

Distinctiveness Conflict Risk

The EICAR test file niche is highly specific and unique; no other skill would reasonably trigger on these terms, so conflict risk is minimal.

5 / 5

Total

13

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.