CtrlK
BlogDocsLog inGet started
Tessl Logo

triage-validation

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/triage-validation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced validation skill anchored by a concrete 7-question gate and runnable examples. Its weaknesses are length from repeated engagement narratives and a monolithic single-file structure with no progressive disclosure to bundle files.

Suggestions

Move the CVSS 3.1 quick reference and the NEVER SUBMIT / chain tables into separate reference files under references/ and link to them one level deep, keeping SKILL.md as an overview.

Trim the 'Lesson from an authorized engagement' war stories and the Operator Notes section to the single non-redundant insight each adds, reducing token cost without losing actionability.

DimensionReasoningScore

Conciseness

The body is mostly efficient checklists and tables, but the repeated 'Lesson from an authorized engagement' narratives and the Operator Notes section restate concepts already covered by the 7Q gate and gates, adding length that could be tightened without losing guidance.

3 / 5

Actionability

Guidance is fully executable and copy-paste ready: the Q1 fill-in template, runnable curl commands showing malformed vs well-formed bodies, the NEVER SUBMIT list, the chain table, CVSS vector tables, and the 60-second checklist all give concrete, specific instruction.

5 / 5

Workflow Clarity

The 7-Question Gate is an explicitly ordered sequence with kill/downgrade checkpoints, and the 4 pre-submission gates run in sequence with all-must-pass validation; however, multiple overlapping frameworks (7Q, 4 gates, Pre-Severity Gate, Kill Fast Rules) create minor ambiguity about which runs when.

4 / 5

Progressive Disclosure

Section headers give clear structure, but the file is a ~420-line monolith with no bundle files in references/scripts/assets; reference-grade content (CVSS quick reference, NEVER SUBMIT list, chain table) is inlined rather than split into one-level-deep referenced files.

3 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that explicitly covers both what the skill does and when to use it, with a concrete 'Use BEFORE writing any report' trigger. The main weakness is a reliance on internal jargon terms over naturally-spoken trigger phrases.

Suggestions

Swap one or two internal labels (e.g. '7-Question Gate', 'N/A ratio') for natural user phrasing like 'validate a finding before reporting' or 'decide if a bug is worth submitting'.

Lead with a verb-action framing ('Validates findings before report submission…') so the capability reads as an action rather than an artifact inventory.

DimensionReasoningScore

Specificity

Names the domain ('Finding validation before writing any report') and lists several concrete components — '7-Question Gate (all 7 questions)', '4 pre-submission gates', 'always-rejected list', 'conditionally valid with chain table', 'CVSS 3.1 quick reference', 'severity decision guide', 'report title formula', '60-second pre-submit checklist' — but these are artifacts rather than distinct verb-actions, leaving it just shy of the comprehensive-actions anchor.

4 / 5

Completeness

It explicitly answers both what ('Finding validation before writing any report' plus the full component inventory) and when ('Use BEFORE writing any report.'), with a concrete explicit trigger clause, matching the anchor that requires both.

5 / 5

Trigger Term Quality

Natural phrases a user would say are present ('Finding validation', 'before writing any report', 'pre-submit checklist', 'kill the finding'), but several terms are internal jargon ('N/A ratio', 'conditionally valid with chain table', '7-Question Gate') that a user is less likely to utter verbatim.

4 / 5

Distinctiveness Conflict Risk

It carves a clear niche (pre-report finding triage/validation) with distinct triggers, but overlaps slightly with adjacent report-writing and severity-scoring skills referenced in the body, so it is mostly distinct with minor overlap risk rather than minimal.

4 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.