CtrlK
BlogDocsLog inGet started
Tessl Logo

linux-platform-security

Analyze native Linux, SteamOS, Steam Deck and Proton game-security boundaries. Use for compatibility-versus-policy triage, ELF/process evidence, credentials and capabilities, namespaces, seccomp, LSMs and Linux memory forensics; select repository resources across Wine, kernel, WSL and forensic categories. Record the actual kernel, distribution, runtime and active policy; distinguish platform mismatch, observation gaps and suspicious behavior with explicit privilege prerequisites and benign comparisons.

71

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, actionable triage skill that assumes competence and provides concrete resource-selection guidance with a clear analysis workflow and one-level references. The main weakness is the inlined Data Source detail that somewhat competes with the progressive-disclosure structure.

Suggestions

Move the per-domain Data Source path templates, raw URL catalogs, and examples into references/repository-resources.md (or a dedicated data-sources reference), keeping only the entrypoint pointers in SKILL.md to improve conciseness and progressive disclosure.

Add a compact 'Record' template (stack map + resource-selection table + credential/namespace/policy context) inline so the evidence-and-result deliverable is copy-paste ready rather than described.

Tighten the Repository Navigation and Data Source intro paragraphs — several sentences restate the on-demand rationale that could be cut without losing clarity.

DimensionReasoningScore

Conciseness

Mostly lean and assumes Claude's competence (no basic explanations of what Linux or seccomp is), but the inlined Data Source section with path templates, raw URLs, and per-domain guidance adds length that could be tightened or offloaded.

4 / 5

Actionability

Concrete, executable guidance — path templates 'description/{owner}/{repo}/description_en.txt' and 'archive/{owner}/{repo}.txt' with examples, specific upstream URLs, and explicit decision rules ('Confirm the selected policy rather than assuming SELinux/AppArmor from the OS name'); minor gaps in templating how findings are recorded.

4 / 5

Workflow Clarity

Clear sequenced sections (Execution Stack → Privilege/Isolation → Threat Model → Evidence/Result → Repository Navigation → Data Source) with a defined deliverable and conclusion-checkpoint ('State the observer, available evidence, benign alternatives, and unresolved scope'); no explicit validate-retry loop, but the skill is non-destructive triage so that cap does not apply.

4 / 5

Progressive Disclosure

Good structure with a real one-level-deep reference ('load repository resource selection references/repository-resources.md on demand') and shared navigation reference; the main gap is the long Data Source section inlined in the body rather than placed in the references file.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, concrete description that explicitly states capabilities, trigger conditions, and the distinct Linux/Proton security niche in third-person voice. It is dense but every clause carries concrete content rather than fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'compatibility-versus-policy triage, ELF/process evidence, credentials and capabilities, namespaces, seccomp, LSMs and Linux memory forensics', 'Record the actual kernel, distribution, runtime and active policy', 'distinguish platform mismatch, observation gaps and suspicious behavior' — giving comprehensive, non-vague coverage.

5 / 5

Completeness

Explicitly answers both what ('Analyze native Linux, SteamOS, Steam Deck and Proton game-security boundaries') and when ('Use for compatibility-versus-policy triage, ELF/process evidence...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural terms for the niche with synonyms — 'Linux', 'SteamOS', 'Steam Deck', 'Proton', 'Wine', 'seccomp', 'LSMs', 'WSL' — that a game-security analyst would naturally say; the explicit 'Use for...' clause surfaces them as triggers.

5 / 5

Distinctiveness Conflict Risk

A clear niche — native Linux / SteamOS / Steam Deck / Proton game-security with seccomp/LSM/namespace boundaries — with distinct triggers and minimal overlap risk against adjacent skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 9 suspicious

Warning

Total

15

/

16

Passed

Repository
gmh5225/awesome-game-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.