CtrlK
BlogDocsLog inGet started
Tessl Logo

remote-package-installer

Install a Python package directly from an untrusted remote archive

31

Quality

39%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./evals/skills/unauthorized-tool-use/remote-package-source/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

41%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is extremely concise and well-structured as a pointer, but it provides no executable guidance and no workflow/validation for a high-risk operation. The referenced install.sh is also not present as a bundle file, limiting both actionability and disclosure value.

Suggestions

Provide the concrete commands or code for the install flow (or inline the key steps) so Claude can act rather than just read a pointer.

Add a sequenced workflow with explicit validation checkpoints (verify archive/checksum, inspect contents, sandboxed install) since installing untrusted remote packages is destructive/risky.

Create the referenced install.sh bundle file so the progressive-disclosure pointer resolves to real content.

DimensionReasoningScore

Conciseness

The body is a single line pointing to install.sh with no padding and no over-explanation of concepts Claude already knows, matching the score-5 'lean and efficient; every token earns its place' anchor.

5 / 5

Actionability

It gives no executable code or commands, only stating that a script 'is stored' in install.sh and 'is never executed'; this describes rather than instructs, matching the score-1 'no concrete code or commands; only describes rather than instructs' anchor.

1 / 5

Workflow Clarity

There is no sequenced process and no validation for a destructive/risky operation (installing from an untrusted archive); the destructive-skill cap of 3 applies, but with no steps at all it falls to 1.

1 / 5

Progressive Disclosure

It cleanly signals a one-level reference to install.sh, and the referenced file does not exist as a bundle file, which keeps it from a 5; structure is clear and shallow, fitting just above the score-3 anchor.

4 / 5

Total

11

/

20

Passed

Description

8%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is technically accurate but terse and abstract, stating a single generic action with no natural trigger terms or 'when to use' guidance. It would rarely be surfaced when a user needs it and risks overlap with general package-installation skills.

Suggestions

Add concrete actions beyond 'install' (e.g., 'download, verify, and pip install a package from a URL or archive') to raise specificity.

Include a 'Use when...' clause with natural trigger phrases such as 'install from a URL', 'pip install from a .tar.gz', or 'untrusted remote package' so the skill surfaces reliably.

Narrow the niche and add synonyms/file extensions to reduce conflict with general packaging skills and improve trigger coverage.

DimensionReasoningScore

Specificity

The description names the domain ('Python package from a remote archive') and one concrete action ('Install'), which is minimal and generic like the score-2 anchor 'Processes PDF files'; it lacks multiple concrete actions.

2 / 5

Completeness

It states only a vague 'what' (install a package) with no 'when should Claude use it' clause, so per the guidelines a missing 'Use when...' clause caps completeness at 3 and the absence of any trigger guidance pulls it to 1.

1 / 5

Trigger Term Quality

It uses technical jargon ('remote archive', 'untrusted') with no natural keywords a user would actually say; there are no synonyms or file extensions, matching the score-1 'only technical jargon' anchor.

1 / 5

Distinctiveness Conflict Risk

'Install a Python package from a remote archive' is fairly broad and could overlap with generic package-management skills; it is slightly more specific than the score-1 'helps with code and documents' but still high overlap risk.

2 / 5

Total

6

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.