CtrlK
BlogDocsLog inGet started
Tessl Logo

pivot-on-ioc

Explore GTI relationships for an IOC to discover related entities. Use to expand investigation by finding connected domains, IPs, files, or threat actors. Takes an IOC and relationship types to query.

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/pivot-on-ioc/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, mostly actionable skill body with clear tool and relationship tables. Its main weakness is the absence of validation/error-handling checkpoints in the batch relationship-query loop, which caps workflow clarity.

Suggestions

Add a validation/verification checkpoint in Step 2 (e.g., check each relationship query for errors, retry or report failures, and confirm RELATED_ENTITIES is non-empty before reporting PIVOT_STATUS).

Replace the placeholder call template with one fully copy-paste-ready example using literal values for at least one IOC type.

Tighten the 'Required Outputs' intro ('After completing this skill, you MUST report these outputs:') to a more concise framing.

DimensionReasoningScore

Conciseness

Lean, table-driven content that assumes Claude's competence without explaining what an IOC or GTI is, with only minor padding in the example-usage block and the output-table framing.

4 / 5

Actionability

Concrete tool names and a parameterized call template with named arguments provide mostly executable guidance, though the template uses placeholders ([selected_tool], relationship) rather than fully copy-paste-ready code.

4 / 5

Workflow Clarity

The two-step sequence is clearly defined, but the batch per-relationship query loop lacks any validation, error-handling, or verification checkpoint, which caps workflow clarity at 3 per the batch-operations feedback-loop rule.

3 / 5

Progressive Disclosure

A self-contained, well-organized single file with clear sections and no need for external references; marginally over the simple-skill line but appropriately structured.

4 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description that clearly states both capability and use-case with concrete entity types. It could reach the top tier by adding natural synonyms (indicator of compromise, pivot) and more explicit trigger phrasing.

DimensionReasoningScore

Specificity

Lists several concrete actions ('Explore GTI relationships', 'discover related entities', 'finding connected domains, IPs, files, or threat actors') with minor gaps in coverage, matching the 'lists several specific actions' anchor.

4 / 5

Completeness

Both 'what' ('Explore GTI relationships for an IOC to discover related entities') and 'when' ('Use to expand investigation by finding connected domains, IPs, files, or threat actors') are present and explicit, though the trigger phrasing could be more concrete.

4 / 5

Trigger Term Quality

Good natural keyword coverage (IOC, domains, IPs, files, threat actors, investigation) but missing common synonyms such as 'indicator of compromise', 'pivot', or file extensions, fitting the 'good coverage, a few terms missing' anchor.

4 / 5

Distinctiveness Conflict Risk

Clearly niched to GTI IOC pivoting with distinct, specific triggers and minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
dandye/ai-runbooks
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.