CtrlK
BlogDocsLog inGet started
Tessl Logo

secops-hunt

Expert guidance for proactive threat hunting. Use this when the user asks to "hunt" for threads, IOCs, or specific TTPs.

81

2.02x
Quality

72%

Does it follow best practices?

Impact

97%

2.02x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./extensions/google-secops/skills/hunt/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable threat-hunting skill with concrete UDM query templates and clear procedural workflows. Its weakest point is progressive disclosure: a referenced mapping file is not bundled, and validation gates are implicit rather than explicit.

Suggestions

Either bundle `extensions/google-secops/TOOL_MAPPING.md` under a references/ directory or inline the tool-mapping table so the reference resolves to a real file.

Add explicit validation checkpoints, e.g. 'Confirm IOC hits via get_ioc_match before running Phase 1 UDM searches' and 'Validate query results are non-empty and on-scope before escalating'.

Collapse the repeated Remote/Local tool pairs into a single mapping table to remove redundancy and tighten token efficiency.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's security knowledge, with no padding about what IOCs/UDM are; only minor redundancy from restating Remote vs. Local tool variants keeps it from a 5.

4 / 5

Actionability

Provides concrete, copy-paste-ready UDM query templates (e.g. `principal.ip = "IOC" OR target.ip = "IOC"...`) and specific tool names, but relies on `${...}` placeholders and conditional Remote/Local branching that leave minor gaps versus fully executable commands.

4 / 5

Workflow Clarity

Both procedures use clearly numbered, sequenced steps with an explicit refine/repeat feedback loop in the TTP hunt; missing one notch from 5 because validation checkpoints (e.g. confirming IOC hits before deep investigation) are implicit rather than explicit gates.

4 / 5

Progressive Disclosure

Sections are well-organized within a single SKILL.md, but it references `extensions/google-secops/TOOL_MAPPING.md` which is not present in the bundle (no references/, scripts/, or assets/ directories exist), leaving a dangling, unverifiable reference.

3 / 5

Total

15

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A compact, well-targeted description with an explicit trigger clause and a distinct niche. Its main weakness is a generic 'what' statement and a 'threads'/'threats' typo that slightly undercut specificity and trigger quality.

Suggestions

Replace the generic 'Expert guidance for proactive threat hunting' with concrete actions, e.g. 'Search SIEM/UDM for IOCs and TTPs, enrich suspicious entities, and document findings in SOAR cases or reports.'

Fix the typo 'threads' to 'threats' and add common synonyms (e.g. 'indicators of compromise', 'compromise') to broaden natural trigger coverage.

Tighten the trigger clause to cover both proactive hunting and reactive IOC-lookup phrasings users may naturally say.

DimensionReasoningScore

Specificity

Names the domain ("proactive threat hunting") and 1-2 concrete targets (IOCs, TTPs) but does not enumerate specific hunting actions, so it stops at the '1-2 concrete actions' anchor rather than comprehensive coverage.

3 / 5

Completeness

Both 'what' ("Expert guidance for proactive threat hunting") and 'when' (the explicit 'Use this when...' clause) are present, but the 'what' is generic rather than listing concrete actions, so it is not a fully explicit 5.

4 / 5

Trigger Term Quality

Includes a natural trigger phrase ("Use this when the user asks to 'hunt'...") plus domain terms IOCs and TTPs, but the typo 'threads' (for 'threats') and lack of synonyms like 'indicators' or 'compromise' keep it just below comprehensive.

4 / 5

Distinctiveness Conflict Risk

Threat hunting for IOCs/TTPs is a clear, narrow security niche with distinct triggers that are unlikely to fire for unrelated skills, matching the 'clear niche with distinct triggers; minimal conflict risk' anchor.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
google/mcp-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.