CtrlK
BlogDocsLog inGet started
Tessl Logo

triage-validation

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio.

65

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/triage-validation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable and well-sequenced with strong validation gates, templates, and decision rules. Its weaknesses are the monolithic single-file structure (no progressive disclosure via bundle files) and narrative prose in the Operator Notes and lesson sections that adds tokens beyond what Claude needs.

Suggestions

Move the CVSS 3.1 Quick Reference, NEVER SUBMIT list, and Conditionally Valid chain table into one-level-deep reference files (e.g., references/cvss-reference.md, references/never-submit.md) referenced from the body, reducing SKILL.md footprint.

Tighten the Operator Notes and the 'Lesson from an authorized engagement' narratives into concise rule statements, dropping the engagement storytelling that Claude does not need.

Add a short 'Quick start' overview near the top that points to the deeper sections, so the entry point is a concise overview rather than immediately diving into the 7-Question Gate.

DimensionReasoningScore

Conciseness

The body is largely lean directives, tables, checklists, and templates, but the Operator Notes, Pre-Severity Gate lesson narrative, and RETRACTION DISCIPLINE prose add explanatory storytelling that could be tightened, matching the 'mostly efficient but could be tightened' anchor.

2 / 3

Actionability

Provides copy-paste-ready artifacts — the Q1 step template with exact HTTP fields, Gate 0-3 checklists, CVSS vectors with scores, the retraction entry template, and concrete KILL/DOWNGRADE decision rules — fully executable guidance matching the highest anchor.

3 / 3

Workflow Clarity

Sequences a clear multi-step process ('Ask IN ORDER', the 4 pre-submission gates 'run in sequence, ALL 4 must PASS') with explicit validation checkpoints ('If you CANNOT write step 2 → KILL IT', revalidate after fixes), matching the clear-sequence-with-explicit-validation anchor.

3 / 3

Progressive Disclosure

The skill is a single monolithic SKILL.md (~360 lines) with no bundle files in references/, scripts/, or assets/; sizable reference material (CVSS quick reference, NEVER SUBMIT list, chain table) is inline rather than split into one-level-deep referenced files, matching the 'some structure but content that should be separate is inline' anchor.

2 / 3

Total

10

/

12

Passed

Description

77%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and complete, clearly naming the validation components and the 'use before writing any report' trigger. It is held back by jargon-heavy trigger phrasing and an odd 'Saves N/A ratio' clause that weakens natural keyword coverage and distinctiveness.

Suggestions

Add natural user-facing trigger terms such as 'bug bounty', 'report submission', or 'should I report this finding' so the description matches phrases a user would actually say.

Replace or clarify 'Saves N/A ratio' — it reads as internal jargon; consider 'reduces N/A and Informative rejections' or drop it in favor of clearer impact phrasing.

Soften 'One wrong answer = kill the finding and move on' into a third-person capability statement (e.g., 'Kills individual findings that fail any gate') to align with the preferred third-person voice.

DimensionReasoningScore

Specificity

Lists multiple concrete components — '7-Question Gate (all 7 questions)', '4 pre-submission gates', 'always-rejected list', 'conditionally valid with chain table', 'CVSS 3.1 quick reference', 'report title formula', '60-second pre-submit checklist' — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Explicitly answers what (the validation gates, lists, and references) and when ('Use BEFORE writing any report.'), matching the anchor for clearly answering both with explicit triggers.

3 / 3

Trigger Term Quality

Includes some natural terms ('Finding validation', 'before writing any report', 'N/A ratio') but leans on skill-internal jargon ('7-Question Gate', 'kill the finding', 'Saves N/A ratio') and omits common user phrasings like 'bug bounty' or 'should I report this'.

2 / 3

Distinctiveness Conflict Risk

The pre-report validation niche is reasonably distinct, but the jargon-heavy phrasing ('Saves N/A ratio', 'kill the finding') and lack of a clear broader-domain keyword keep it from the unambiguous, conflict-free anchor at 3.

2 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.