CtrlK
BlogDocsLog inGet started
Tessl Logo

oma-deepsec

Set up and run Deepsec vulnerability scans, triage, and CI gates. Use for Deepsec work or an explicitly requested agent-powered vulnerability scan.

62

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/oma-deepsec/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a highly actionable, operationally rigorous skill: concrete commands, real cost figures, explicit validation gates, and genuine error-recovery loops for an expensive batch process. Its main costs are repetition of the same calibration and agent-choice rules across four-plus sections, and a progressive-disclosure posture that inlines guardrail/failure detail while pointing at resource files that are not present in the bundle.

Suggestions

De-duplicate the calibration recommendation and the ask-agent-choice rule: state each once (e.g. in the canonical workflow and guardrails respectively) and cross-reference instead of restating them in Goal, Expected outputs, Entry, Transitions, and multiple guardrails.

Move the full failure-and-recovery table and the detailed guardrail prose into the referenced resources/ files, keeping a short summary plus pointers in SKILL.md to cut its token footprint.

Ensure the referenced bundle files (resources/setup.md, scanning.md, pr-review.md, matchers.md, triage.md, config.md, and ../_shared/core/*.md) actually ship with the skill — the body relies on them but none are present in this bundle.

DimensionReasoningScore

Conciseness

The body is dense with genuinely non-obvious operational detail (cost bands, failure-recovery table, two-job CI pattern), but the calibration recommendation "--limit 50 --concurrency 5" is repeated in at least four sections, the ask-agent-choice rule appears twice (Entry step 5 and Guardrail 13), and "Intent signature" largely duplicates "When to use", fitting the mostly-efficient-but-could-be-tightened anchor.

3 / 5

Actionability

Every workflow ships copy-paste-ready commands (bunx deepsec process --limit 50 --concurrency 5, export --format md-dir, the process --diff PR invocation), concrete dollar cost bands, matcher hit-rate targets, and a specific failure-to-remediation table — fully executable guidance covering the common cases.

5 / 5

Workflow Clarity

The sequence (Entry → Bootstrap → Calibrate → Full pass → PR mode → matchers → Resume) is explicit and includes real validation checkpoints for a costly batch operation: mandatory calibration before unbounded runs, cost extrapolation with explicit user go-ahead, quota-stop resume semantics, refusal handling, and revalidate-based verdicts — matching the clear-sequence-with-explicit-validation-and-recovery anchor.

5 / 5

Progressive Disclosure

References are well-signaled and one level deep (a scoped References section, "loaded only when the scenario requires them"), but the referenced resources/*.md and ../_shared/core/*.md files are absent from the bundle, and substantial detail (13 guardrails, the full failure table, the resource-scope table) is inlined that belongs in those files — between the some-structure and good-structure anchors, held at 3 by the unverifiable references.

3 / 5

Total

16

/

20

Passed

Description

67%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly communicates what the skill does and anchors triggering to the Deepsec tool name, keeping conflict risk low. Its weaknesses are a thin set of natural trigger phrases ("Deepsec work" is generic and synonyms like security scan or triage are absent) and capability coverage that omits several core workflows the body delivers. It sits comfortably above the midpoint but well short of the exemplary examples.

Suggestions

Replace the generic "Use for Deepsec work" with concrete triggers users would actually say, e.g. "Use when the user mentions Deepsec, asks to run a security or vulnerability scan on a repo, wants findings triaged or false positives cut, or asks for a Deepsec PR/CI security gate".

Add natural synonyms and related keywords — "security scan", "CVE scan", "triage findings", "false-positive rate" — so the description triggers on phrasings that never name the tool.

Consider naming one or two more capabilities (revalidation verdicts, custom matcher authoring) to round out the what-side coverage toward the top anchor.

DimensionReasoningScore

Specificity

"Set up and run Deepsec vulnerability scans, triage, and CI gates" names four concrete actions tied to a specific tool, matching the several-specific-actions-with-minor-gaps anchor; it stops short of comprehensive coverage by omitting revalidation, export, matchers, and cost calibration that the body treats as core.

4 / 5

Completeness

Both a clear what ("Set up and run Deepsec vulnerability scans, triage, and CI gates") and an explicit when ("Use for Deepsec work or an explicitly requested agent-powered vulnerability scan") are present, but the when-clause is loose ("Deepsec work") rather than concrete trigger phrases, matching the both-present-but-when-could-be-more-explicit anchor.

4 / 5

Trigger Term Quality

"Deepsec", "vulnerability scan", and "agent-powered" are relevant keywords, but "Use for Deepsec work" is generic and common user phrasings like "security scan", "CVE", "triage findings", or "PR security gate" are missing, fitting the some-keywords-missing-variants anchor rather than good coverage.

3 / 5

Distinctiveness Conflict Risk

The Deepsec tool name and "agent-powered" carve a clear niche with distinct triggers, but bare "vulnerability scan" phrasing overlaps generic security-review skills (the body itself routes those to oma-qa), fitting the mostly-distinct-minor-overlap anchor.

4 / 5

Total

15

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
first-fluke/oh-my-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.