CtrlK
BlogDocsLog inGet started
Tessl Logo

oma-deepsec

Set up and run Deepsec vulnerability scans, triage, and CI gates. Use for Deepsec work or an explicitly requested agent-powered vulnerability scan.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/oma-deepsec/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly operational, well-guarded skill body: every workflow step is executable, cost and safety checkpoints are explicit, and failures have concrete recovery paths. The chief weakness is redundancy — calibration defaults and agent-choice rules are stated repeatedly, and the schema-style meta sections restate each other — which inflates token cost without adding guidance.

Suggestions

State the calibration default ("--limit 50 --concurrency 5, defer to user-named values") once in the canonical workflow and reference it from Guardrails 1 and 13 instead of repeating it four times.

Consolidate the overlapping meta sections (Intent signature / When to use / Control-flow features / Preconditions / Effects) into a single compact routing-and-constraints block to cut duplicated tokens.

Rename the "Scheduling" top-level header to something accurate like "Scope and Routing" so the section tree matches its content.

DimensionReasoningScore

Conciseness

The body is dense and mostly token-earning (exact commands, cost bands, thresholds), but the calibration advice "--limit 50 --concurrency 5" is repeated in four places (Transitions, workflow step 2, Guardrails 1 and 13), the "ask agent choice before the first paid call" rule appears in both Entry and Guardrail 13, and the meta sections (Intent signature, Control-flow features, Resource scope, Preconditions, Effects) partially duplicate one another — matching the mostly-efficient-but-could-be-tightened anchor.

3 / 5

Actionability

Every phase has copy-paste-ready bash (init, scan, process with concrete flags, triage, revalidate, export, CI command), plus specific cost bands ("100 files ≈ $25-60, 500 ≈ $130-300, 2,000 ≈ $500-1,200"), matcher hit-rate targets, and exact file paths, fully matching the executable-and-covers-common-cases anchor.

5 / 5

Workflow Clarity

The canonical workflow is explicitly sequenced (bootstrap → calibrate → full pass → PR mode → matchers → resume) with genuine validation checkpoints and feedback loops: cost extrapolation plus user go-ahead before unbounded spend, quota stops with re-run-same-command resume, and an FP-rate loop (revalidate → tighten INFO.md → bias matchers precise), matching the explicit-validation anchor.

5 / 5

Progressive Disclosure

The References section clearly maps each intent to one-level-deep resource files (setup, scanning, pr-review, matchers, triage, config) with labeled purposes, satisfying good structure; it is not a 5 because the ~210-line body inlines substantial detail (guardrails, failure tables, matcher workflow) that could live in those resources, and the top-level "Scheduling" header mislabels its goal/intent content.

4 / 5

Total

17

/

20

Passed

Description

71%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that pairs concrete capabilities with an explicit use-when clause and is tightly bound to a distinct named tool. Its main weakness is thin trigger coverage: the when-clause repeats the product name instead of enumerating the natural phrases and scenarios (security scan, CVE, CI security gate, matcher authoring) that would help routing.

Suggestions

Broaden the trigger terms beyond the product name: add natural phrases such as "security scan", "find vulnerabilities or CVEs", "SAST", and "CI security gate" so users who don't know the Deepsec name still route here.

Make the when-clause cover the full scope the body handles, e.g. "Use when setting up or running Deepsec, triaging or revalidating findings, adding custom matchers, or gating PRs with a security check."

DimensionReasoningScore

Specificity

"Set up and run Deepsec vulnerability scans, triage, and CI gates" names the domain plus several concrete actions, matching the anchor for several specific actions with minor gaps; it is not a 5 because covered capabilities like revalidate, export, and custom matchers are absent from the description.

4 / 5

Completeness

Both what ("set up and run... scans, triage, and CI gates") and when ("Use for Deepsec work or an explicitly requested agent-powered vulnerability scan") are explicit, but the when-clause covers only two of the scenarios the skill actually handles (setup, CI gate, matchers, troubleshooting), so it falls short of the fully explicit 5 anchor.

4 / 5

Trigger Term Quality

The trigger clause offers only "Deepsec" (repeated twice) and "agent-powered vulnerability scan"; common natural variations a user would say — "security scan", "CVE", "find vulnerabilities", "SAST" — are missing, matching the some-keywords-but-missing-synonyms anchor.

3 / 5

Distinctiveness Conflict Risk

The description is anchored to a named niche tool (Deepsec) with a distinct trigger phrase ("agent-powered vulnerability scan"), giving it a clear niche with minimal conflict risk against other skills.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
first-fluke/oh-my-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.