CtrlK
BlogDocsLog inGet started
Tessl Logo

codebase-cleanup-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

48

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./docs/v19.7/configuration/agent/skills_external/antigravity-awesome-skills-main/skills/codebase-cleanup-deps-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

42%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is well-structured and brief, but it reads as an outline rather than an executable playbook: every instruction is a generic directive with no commands or examples, the persona paragraph duplicates the description, and its one external reference is a broken path. Claude following it would know the shape of the task but not how to perform any step concretely.

Suggestions

Replace generic directives with concrete commands, e.g. 'npm audit --json' / 'pip-audit --format json' / 'osv-scanner --lockfile=...' and a sample remediation-table format.

Fix or remove the 'resources/implementation-playbook.md' references — the file does not exist in the bundle; either ship it or inline the essential tooling notes.

Delete the verbatim persona/Context duplication of the description and add an explicit validation checkpoint (e.g. re-run the scan after each upgrade and confirm the vulnerability is resolved).

DimensionReasoningScore

Conciseness

The body is short and avoids explaining known concepts, but the opening line repeats the frontmatter description verbatim ('You are a dependency security expert specializing in...') and the Context section is vague padding ('The user needs comprehensive dependency analysis to identify...'), so it could be tightened.

3 / 5

Actionability

Instructions are high-level directives ('Inventory direct and transitive dependencies', 'Run vulnerability and license scans', 'Prioritize fixes by severity and exposure') with no concrete commands, tool names, or examples — no npm audit, pip-audit, or osv-scanner — and the referenced playbook that would supply the detail does not exist in the bundle.

2 / 5

Workflow Clarity

The instructions form a coherent sequence (inventory, scan, prioritize, propose upgrades) but validation checkpoints are implicit at best; 'Verify upgrades in staging before production rollout' is a bare mention with no validate-fix-retry loop for what are batch dependency changes, which caps workflow clarity at 3.

3 / 5

Progressive Disclosure

The body is under 50 lines and well-sectioned, but both mentions of 'resources/implementation-playbook.md' point to a file that does not exist anywhere in the bundle, so the only external reference dead-ends and the promised tooling/templates are unavailable.

3 / 5

Total

11

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a clear capability set in a recognizable niche, but it reads as a persona prompt rather than a skill description: second-person voice, no third-person framing, and no 'Use when...' trigger guidance. Adding explicit trigger conditions and natural synonyms would lift both completeness and trigger-term quality.

Suggestions

Add a 'Use when...' clause naming concrete triggers, e.g. 'Use when the user mentions dependency audits, vulnerable packages, CVEs/advisories, license compliance, or outdated dependencies.'

Rewrite in third person ('Analyzes project dependencies...') and drop the 'You are a dependency security expert' persona sentence, which duplicates the body and violates the voice guideline.

Include natural trigger synonyms users actually say — 'CVE', 'security advisory', 'npm audit', 'pip-audit', 'lockfile' — to improve trigger term coverage.

DimensionReasoningScore

Specificity

The description lists several concrete actions ('Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies') which would merit a 4, but the second-person opening 'You are a dependency security expert' violates the third-person voice rule, reducing the score by 1.

3 / 5

Completeness

The 'what' is clear (vulnerability, license, and outdated-package analysis with remediation), but there is no 'Use when...' clause or equivalent trigger guidance anywhere, which caps completeness at 3.

3 / 5

Trigger Term Quality

Good coverage of natural user terms ('vulnerabilities', 'license compliance', 'outdated packages', 'dependencies', 'supply chain'), though common variations like 'CVE', 'advisories', or ecosystem tool names (npm audit, pip-audit) are missing.

4 / 5

Distinctiveness Conflict Risk

The dependency-audit niche with license compliance, supply chain, and outdated-package triggers is mostly distinct, with only minor overlap risk against general security-review skills.

4 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
duclm1x1/Dive-Ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.