Display and filter security findings from Endor Labs. Use when the user says "show findings", "list vulnerabilities", "what did the scan find", "endor findings", "show me critical reachable vulns", or wants to browse/filter results after a scan. Supports filtering by severity, reachability, category (vuln/sast/secrets/license). Do NOT use for running a new scan (/endor-scan) or explaining a specific CVE (/endor-explain).
100
100%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Passed
No known issues
Quality
Discovery
100%Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.
This is an excellent skill description that hits all the marks. It provides specific capabilities, abundant natural trigger terms, explicit 'Use when' and 'Do NOT use for' clauses, and clear boundaries distinguishing it from related skills. The negative boundary guidance is particularly valuable for a skill ecosystem where multiple Endor Labs skills coexist.
| Dimension | Reasoning | Score |
|---|---|---|
Specificity | Lists multiple concrete actions: display findings, filter by severity, reachability, category (vuln/sast/secrets/license). Also explicitly states what it does NOT do (running scans, explaining CVEs), which adds specificity. | 3 / 3 |
Completeness | Clearly answers both 'what' (display and filter security findings from Endor Labs with specific filter dimensions) and 'when' (explicit 'Use when' clause with multiple trigger phrases). Also includes negative boundaries with 'Do NOT use for' guidance. | 3 / 3 |
Trigger Term Quality | Excellent coverage of natural trigger phrases: 'show findings', 'list vulnerabilities', 'what did the scan find', 'endor findings', 'show me critical reachable vulns', plus domain terms like severity, reachability, and category types. | 3 / 3 |
Distinctiveness Conflict Risk | Highly distinctive with explicit negative boundaries referencing other skills (/endor-scan, /endor-explain), clear niche of browsing/filtering results, and specific product name (Endor Labs) that minimizes conflict risk. | 3 / 3 |
Total | 12 / 12 Passed |
Implementation
100%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This is an excellent skill file that is lean, actionable, and well-structured. The filter reference table provides high-value lookup data, the workflow covers multiple paths with clear steps, and supporting details are properly delegated to reference files. The priority ordering and output template give Claude unambiguous guidance on how to present results.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Every section earns its place — the filter reference table is pure lookup data Claude wouldn't know, the workflow is tightly structured, and there's no explanation of basic concepts. No wasted tokens. | 3 / 3 |
Actionability | Provides concrete API filter strings, executable CLI commands, exact markdown output templates, and specific error-to-action mappings. The filter reference table is copy-paste ready for building queries. | 3 / 3 |
Workflow Clarity | Clear 3-step sequence (Query → Interpret → Present) with multiple options for Step 1, explicit priority ordering for results, and error handling table that covers common failure modes with specific recovery actions. | 3 / 3 |
Progressive Disclosure | Main content is a concise overview with well-signaled one-level-deep references to supporting files (references/cli-parsing.md, references/reachability-tags.md, references/data-sources.md). Content is appropriately split between inline essentials and external details. | 3 / 3 |
Total | 12 / 12 Passed |
Validation
100%Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.
Validation — 11 / 11 Passed
Validation for skill structure
No warnings or errors.
344e7ff
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.