CtrlK
BlogDocsLog inGet started
Tessl Logo

eicar-test

Test skill containing EICAR test file for malware detection

68

1.17x
Quality

60%

Does it follow best practices?

Impact

100%

1.17x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./evals/test_skills/malicious/eicar-test/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

47%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is brief and organized but describes rather than instructs: it explains what the EICAR file is (which Claude already knows) while omitting the one operational fact that matters — the path to the actual asset and how to use it to test the scanner. As a test-support skill it works, but a fresh agent would have to guess both the file and the procedure.

Suggestions

Name the actual asset path explicitly, e.g. 'The test payload is at assets/test-binary.bin', since the generic 'assets folder' reference leaves the concrete file ambiguous.

Replace the general explanation of what the EICAR file is with a concrete usage step, e.g. 'Submit assets/test-binary.bin to the scanner under test and expect it to be detected as malware.'

Add a short verification note (expected detection result / which scanner integration this exercises) so the single action is unambiguous and its success is checkable.

DimensionReasoningScore

Conciseness

The body is very short, but the sentence 'The EICAR test file is a standard file used to test anti-malware products' explains a concept Claude already knows — a minor instance of over-explanation that could be trimmed, matching 'Efficient; minor instances of over-explanation'. Not a 5 because that explanatory sentence does not earn its tokens.

4 / 5

Actionability

The body points at 'the assets folder' but never names the actual file (assets/test-binary.bin) or gives any instruction for how to use it to test the VirusTotal scanner — minimal concrete guidance with the specific steps missing, matching the score-2 anchor. Not a 3 because there is no executable instruction at all, only description.

2 / 5

Workflow Clarity

The stated purpose ('test the VirusTotal binary file scanner integration') implies a rough single task, but no steps, file path, or validation are given, so the action is not unambiguous — the simple-skill path to 5 requires an unambiguous single action. Not a 3 because there are no listed steps or checkpoints whatsoever, just an intent.

2 / 5

Progressive Disclosure

The under-50-line body is organized into clear sections (title, intro, Purpose) and references a real bundle location (the assets folder containing test-binary.bin), giving good structure with a minor gap — the asset reference does not name the specific file. Not a 5 because the unnamed asset leaves navigation slightly ambiguous.

4 / 5

Total

12

/

20

Passed

Description

52%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a specific, distinctive purpose (EICAR test file for malware detection) but reads as a label rather than an operational trigger: it has no capability verbs beyond 'containing' and no 'Use when...' guidance. It would rarely misfire but also rarely be selected by a natural user request.

Suggestions

Add an explicit trigger clause, e.g. 'Use when testing antivirus or malware-scanner integrations, or when a VirusTotal/scanner test payload is needed.'

Include natural synonyms users would say — 'antivirus', 'virus scanner', 'scanner test file' — alongside 'malware detection' to broaden trigger coverage.

State the concrete capability in the description itself (e.g. 'provides the EICAR test file as a safe malware-detection payload for testing scanner integrations') so the 'what' includes an action, not just containment.

DimensionReasoningScore

Specificity

The description names the domain ("EICAR test file", "malware detection") but the only action stated is "containing", matching the anchor 'Names the domain but actions are minimal or generic'. It is not a 3 because no concrete capability actions beyond containment are listed.

2 / 5

Completeness

The description has a clear 'what' (a skill containing the EICAR test file for malware detection) but no 'when to use it' guidance at all; the judging guidelines cap completeness at 3 for a missing 'Use when...' clause.

3 / 5

Trigger Term Quality

"EICAR test file" and "malware detection" are relevant keywords, but natural user variations such as "antivirus", "virus scanner", or "security testing" are absent, fitting 'Some relevant keywords but missing common variations or synonyms'. Not a 4 because keyword coverage is thin rather than merely missing a few terms.

3 / 5

Distinctiveness Conflict Risk

EICAR testing is a clear, highly specific niche with no realistic overlap with other skills, fitting 'Clear niche with distinct triggers; minimal conflict risk'. It is unambiguously distinguishable despite lacking trigger phrasing.

5 / 5

Total

13

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.