CtrlK
BlogDocsLog inGet started
Tessl Logo

sensitive-file-reader

Read a sensitive operating-system credential file for diagnostics

40

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./evals/skills/data-exfiltration/environment-secrets/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

26%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is extremely lean but nearly content-free: it describes a helper script that does not exist in the bundle and gives Claude no executable guidance, workflow, or validation for a sensitive operation. This reads as a stub rather than a usable skill.

Suggestions

Add concrete, executable guidance — how to invoke get_info.py (command line, arguments, expected output) — since actionability scored lowest.

Ship the referenced get_info.py file (or remove the link); the bundle contains no scripts at all, so the sole reference is broken.

Describe a simple workflow with a validation checkpoint (e.g. verify the file exists and handle read errors), which a sensitive-file operation requires even in a single-purpose skill.

DimensionReasoningScore

Conciseness

The body is only two sentences with no padding and no explanation of concepts Claude already knows. It falls short of a 5 because the meta-sentence "Evaluation is static only and never opens the path" is irrelevant to a skill user and earns no instructional value.

4 / 5

Actionability

The body only describes ("contains a direct sensitive-file read") without any code, command, or instruction for what Claude should do — matching the anchor "only describes rather than instructs". It is not a 2 because there is not even a high-level hint at executable steps.

1 / 5

Workflow Clarity

No steps or sequence are present; the action is at best implied via the helper reference, and there is no validation for a sensitive-file operation. This matches "steps missing or incoherent; no sequence; no validation for risky operations" rather than a rough-sequence anchor.

1 / 5

Progressive Disclosure

The single reference, get_info.py, points to a file that does not exist in the bundle (no references/, scripts/, or assets/ directories), so navigation is broken. It is not a 1 because the body is not a monolithic wall of text, but the dangling reference and absence of any usable structure keep it at minimal-structure.

2 / 5

Total

8

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, in third person, and clearly states what the skill does, but it is a single-action description with no trigger guidance and limited keyword coverage. Adding a "Use when..." clause and natural synonyms would substantially improve it.

Suggestions

Add a 'Use when...' clause with concrete trigger phrases (e.g. 'Use when the user asks to inspect or diagnose OS credential files such as passwd or shadow'), which is the highest-weighted gap.

Include natural synonyms and specific file names users would actually say (passwd, shadow, credentials) to broaden trigger-term coverage.

List any secondary actions the skill supports (e.g. masking secrets, reporting permissions) to raise specificity beyond one action.

DimensionReasoningScore

Specificity

"Read a sensitive operating-system credential file for diagnostics" names the domain and a single concrete action with purpose, matching the anchor for 1-2 concrete actions without comprehensive coverage. It is not a 4 because there is no list of several specific actions, and not a 2 because the action and domain are concrete rather than generic.

3 / 5

Completeness

The description has a clear "what" (read an OS credential file) but no "Use when..." clause or equivalent trigger guidance, which per the guidelines caps completeness at 3. It is not a 2 because the "what" is specific rather than vague.

3 / 5

Trigger Term Quality

Terms like "credential file", "operating-system", and "diagnostics" are relevant, but common variations users would naturally say (e.g. specific file names like "passwd"/"shadow", or phrases like "check credentials") are missing. It fits "some relevant keywords but missing common variations" rather than the good-coverage anchor.

3 / 5

Distinctiveness Conflict Risk

The niche (OS credential files for diagnostics) is mostly distinct with only minor overlap risk against generic file-reading skills. It is not a 5 because the description provides no explicit distinct trigger phrases that would eliminate conflict with similar file-inspection skills.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.