CtrlK
BlogDocsLog inGet started
Tessl Logo

secops-triage

Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.

55

Quality

69%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./extensions/google-secops/skills/triage/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is concise, highly actionable, and well-structured with concrete tool mappings and a classification table. Its main weakness is the absence of explicit validation/verification checkpoints before destructive batch actions like bulk-closing cases, which caps workflow clarity.

Suggestions

Add an explicit verification checkpoint before closing/bulk-closing cases, e.g. 'Confirm ${KEY_ENTITIES} match across alerts before execute_bulk_close_case' and re-check status after closure.

Provide a concrete worked example with real-ish values (alert type, entity, query) rather than only ${PLACEHOLDER} tokens to lift actionability toward copy-paste ready.

Clarify the escalation path — 'refer to relevant Skills' is vague; name the specific skills or link them so the reference is one level and resolvable.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence (no explanations of SIEM/IOC/UDM); the duplicated Remote/Local paths per step add functional but trimmable bulk, keeping it just below anchor 5.

4 / 5

Actionability

Concrete tool names, exact query filters, a classification table, and explicit close-case parameters make it mostly executable; variable placeholders like ${KEY_ENTITIES} are a minor gap versus literal examples.

4 / 5

Workflow Clarity

The 7-step sequence with an explicit STOP at duplicate detection is clear, but destructive/batch operations (execute_bulk_close_case, case closure) lack a verification checkpoint before execution, capping this at 3 per the rubric.

3 / 5

Progressive Disclosure

A single self-contained, well-sectioned file with one-level references (TOOL_MAPPING.md, relevant Skills) and no nesting; the referenced external mapping file is not bundled here, a minor gap below anchor 5.

4 / 5

Total

15

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has a clear, concrete trigger clause and a distinct niche, but its 'what' is vague — it offers 'guidance' rather than naming the concrete triage actions (gather, enrich, classify, close/escalate) the skill performs. Tightening the capability statement would raise specificity and completeness.

Suggestions

Replace 'Expert guidance for security alert triage' with the concrete actions performed, e.g. 'Gather alert context, enrich entities, search SIEM events, and classify alerts as FP/BTP/TP.'

Add trigger synonyms a user might naturally say, e.g. '...when the user asks to triage, investigate, or review a security alert or case.'

DimensionReasoningScore

Specificity

It names the domain ("security alert triage") but describes no concrete actions — only "Expert guidance" — so it sits below anchor 3 which requires 1-2 named actions.

2 / 5

Completeness

Both a 'what' ("Expert guidance for security alert triage") and an explicit, concrete 'when' ("Use this when the user asks to "triage" an alert or case") are present; the 'when' is strong, the 'what' is vague, landing above the midpoint.

4 / 5

Trigger Term Quality

The natural trigger "triage" plus "alert or case" are present and would be said by a SOC user, but synonyms (investigate, review) and common variations are missing.

3 / 5

Distinctiveness Conflict Risk

The niche (security alert triage) and the distinct verb "triage" make it mostly distinguishable with only minor overlap risk against general security investigation skills.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
google/mcp-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.