CtrlK
BlogDocsLog inGet started
Tessl Logo

plugin-scanner

Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An actionable, well-structured scanning workflow with executable commands and a real, clearly-signaled bundled reference. Conciseness and workflow clarity are strong but have minor room to tighten.

Suggestions

Trim the product-packaging disambiguation sentences to the minimum needed to avoid confusion with hol-guard.

Consider an explicit validation/exit-state checkpoint after the scan (e.g. 'if the scan errors, re-run with --format json to inspect') to strengthen the workflow feedback loop.

DimensionReasoningScore

Conciseness

Lean and mostly efficient with no padding of concepts Claude already knows; only minor product-disambiguation prose ('intentionally packaged separately from the hol-guard runtime CLI') could be trimmed.

4 / 5

Actionability

Provides copy-paste-ready executable commands with real flags across scan, lint, and verify covering the common cases, e.g. 'plugin-scanner scan PATH --config "$TRUSTED_SCANNER_CONFIG" --profile strict-security --format markdown'.

5 / 5

Workflow Clarity

A clear four-step sequence with a readiness check in step 1 and structured interpretation in step 4; no validate→fix→retry loop, but scanning is read-only so the destructive-cap does not apply.

4 / 5

Progressive Disclosure

Well-sectioned body with a single one-level-deep reference (references/trusted-scanner.toml, confirmed present and clearly signaled via absolute-path resolution); minor organization gaps keep it just below a 5.

4 / 5

Total

17

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, distinctive security-scanning description with strong trigger terms, weakened only by the lack of an explicit 'Use when…' trigger clause. Adding concrete user-facing trigger phrases would lift completeness.

Suggestions

Append an explicit trigger clause such as 'Use when the user asks to scan, audit, or check a skill/plugin/MCP server before installing or trusting it.'

Add common synonyms users say ('audit', 'check', 'verify') to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Names concrete scan targets (skills, plugins, MCP servers, agent tooling) and multiple specific risk categories (prompt injection, unsafe commands, secret exposure, supply-chain risks), giving comprehensive coverage of actions.

5 / 5

Completeness

The 'what' is clear, but the 'when' is only a condition ('before installing or trusting them') with no explicit 'Use when…' trigger phrase, so per the rubric cap completeness stays at 3.

3 / 5

Trigger Term Quality

Good natural-keyword coverage ('skills', 'plugins', 'MCP servers', 'prompt injection'), but common user synonyms such as 'audit', 'check', or 'verify' are absent, leaving a few natural terms missing.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear pre-install security-scanning niche with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
iflytek/skillhub
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.