CtrlK
BlogDocsLog inGet started
Tessl Logo

game-supply-chain-security

Assess game build, launcher, update, distribution, and mod/plugin trust. Use to connect repository CI resources, editor acquisition, hot-patch runtimes, asset specifications, and parsers to release credentials, isolation, provenance, SBOMs, update freshness, ingestion boundaries, and recovery. Distinguish a build tool or script bridge from release authorization, and format acceptance from safe loading; report exact artifact, dependency version, channel, publisher, and verification policy.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/game-supply-chain-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actionable review framework with concrete guidance, named references, and a clear topical workflow. Its weakest area is conciseness, where version-pinned spec details and a lengthy Data Source section add tokens that could be trimmed or externalized.

Suggestions

Move the version-pinned specification details (TUF 1.0.36, SLSA 1.2 links) and the 'Primary sources reviewed' date into the reference file or a dedicated versioning note, keeping only the directive to verify the implementation's chosen version inline.

Condense the Data Source section — which currently repeats local and raw-URL paths for wiki, README, description, and archive — into a compact table or a single pointer to the resource guide.

Add one or two explicit validation feedback loops (e.g. 'if provenance binding fails verification, record which compromised component it would detect before proceeding') to raise workflow clarity.

DimensionReasoningScore

Conciseness

The body is dense and avoids explaining concepts Claude already knows, but contains time-sensitive detail — version pins ('TUF specification 1.0.36', 'SLSA 1.2') and 'Primary sources reviewed: 2026-09-09' — plus a lengthy Data Source section that could be tightened, matching 'mostly efficient but could be tightened'. It is not 4 because the version-pinned references and multi-path Data Source listing add tokens that could be trimmed, and not 2 because there is no padding or explanation of basics.

3 / 5

Actionability

Concrete review guidance with named specs/tools (SteamPipe, TUF, SLSA, CycloneDX, Workshop, OWASP) and specific checks ('Bind provenance to the actual artifact digest and verify its trusted builder, canonical source, build type'), covering common cases with minor gaps. It is not 5 because, as an instruction-only skill, it lacks copy-paste-ready commands/examples, and not 3 because the guidance is concrete and specific rather than pseudocode-level.

4 / 5

Workflow Clarity

A clear topical sequence (Map Release Authority → Threat Objectives → Update Verification → Build Provenance → Released Components → Review Output) with a pipeline map and a verify-oriented 'Choose and Verify the Source' sequence, plus a reporting checklist. It is not 5 because explicit validate→fix→retry feedback loops are implicit rather than staged, and not 3 because checkpoints (verify, record, distinguish, separate conclusions) are largely present.

4 / 5

Progressive Disclosure

One real, clearly-signaled one-level reference (references/repository-resources.md) with well-organized section headers and easy navigation; the bulk review guidance is appropriately inline. It is not 5 because the long inline Data Source section could arguably live in its own reference, leaving a minor organization gap, and not 3 because structure and signaling are clearly present.

4 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is highly specific and distinctive, naming concrete review areas and a clear niche with low conflict risk. Its main weakness is the absence of an explicit 'Use when…' trigger clause, leaving the activation condition only weakly implied and capping completeness at 3.

Suggestions

Add an explicit 'Use when…' trigger clause naming concrete situations (e.g. reviewing a game's release pipeline, mod/plugin trust, or update freshness) so the 'when' is stated, not implied.

Include a few more natural synonyms users might say ('patch', 'DLC', 'content trust', 'launcher update') to round out trigger-term coverage.

Keep the precise reporting fields ('artifact, dependency version, channel, publisher, and verification policy') but consider trimming the long connector list to the most load-bearing terms to sharpen the 'what'.

DimensionReasoningScore

Specificity

Names the domain and many concrete review actions and areas — 'Assess game build, launcher, update, distribution, and mod/plugin trust' plus 'connect repository CI resources, editor acquisition, hot-patch runtimes, asset specifications, and parsers to release credentials, isolation, provenance, SBOMs, update freshness, ingestion boundaries, and recovery' — giving comprehensive, specific coverage. It is not score 4 because the action list is broad and concrete rather than having only minor gaps.

5 / 5

Completeness

A clear 'what' is present ('Assess game build, launcher, update, distribution, and mod/plugin trust') but 'when' is only weakly implied via 'Use to connect…', which describes capability rather than an explicit trigger; per the guideline a missing 'Use when…' clause caps completeness at 3. It is not 4 because no explicit trigger condition is stated, and not 2 because the 'what' is clear and concrete.

3 / 5

Trigger Term Quality

Good natural keywords users would say — 'game build', 'launcher', 'update', 'distribution', 'mod/plugin' — matching the anchor for good coverage with a few natural terms missing. It is not 5 because common synonyms/extensions (e.g. 'patch', 'DLC', 'Steam', 'content trust') are absent, and not 3 because the core terms are natural rather than generic.

4 / 5

Distinctiveness Conflict Risk

A clear niche (game supply-chain trust) with distinct triggers and explicit boundary routing to sibling skills, yielding minimal conflict risk. It is not 4 because the domain and triggers are sharply specific rather than merely 'mostly distinct'.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 8 suspicious

Warning

Total

15

/

16

Passed

Repository
gmh5225/awesome-game-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.