CtrlK
BlogDocsLog inGet started
Tessl Logo

805-regulations-eu-cyber-resilience-act

Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls. Part of Plinth Toolkit

56

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/805-regulations-eu-cyber-resilience-act/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

52%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill has a sound architecture — clear five-step workflow with an explicit entry gate, and clean one-level-deep delegation to real reference and template files — but the body is heavily padded by the same control-area enumeration repeated six-plus times, and the workflow steps describe what to consider rather than concrete actions. Tightening the repetition and moving detail into the already-present references would raise both conciseness and actionability.

Suggestions

Deduplicate the recurring control-area enumeration: state the full list once (e.g., in Constraints) and refer to it elsewhere as 'the control areas above' — this alone would cut roughly a third of the body.

Make each workflow step concrete: replace 'Identify the product, component, remote data processing solution, Java module, intended purpose, ...' enumerations with a short instruction plus a pointer to the specific checklist section in the chapters-summary or examples reference.

Add an explicit validation checkpoint to the workflow (e.g., 'Cross-check the generated report against the template's required sections before handoff; fix gaps and re-check') and reference the report template only once instead of linking it in three places.

DimensionReasoningScore

Conciseness

The body is noticeably padded: the same enumeration of CRA control areas ('secure-by-design, vulnerability handling, update, dependency, SBOM, documentation, support-period, owner handoff') is recycled nearly verbatim in the intro, the review checklist, all nine Constraints bullets, Workflow steps 1, 4, and 5, and the scope lists. This repeated re-enumeration matches anchor 2 ('several unnecessary... padded sections') rather than the mostly-efficient anchor 3.

2 / 5

Actionability

The workflow gives real directives (read three named files in a fixed order, classify scope, produce a report from the named template), but step bodies are abstract mega-lists ('Identify the product, component, remote data processing solution, Java module, intended purpose, reasonably foreseeable use...') with no inline commands, concrete checks, or examples — the executable specifics are entirely delegated to the reference files, matching anchor 3 ('some concrete guidance but incomplete').

3 / 5

Workflow Clarity

A clear five-step sequence (read references → classify scope → review evidence → recommend controls → generate report) with an explicit gate in step 1 ('Do not start implementation review until the chapters summary, examples reference, and report template are understood'). Validation appears only as an output item of the report, not as an explicit verify/fix checkpoint inside the workflow, which keeps it at anchor 4 rather than 5.

4 / 5

Progressive Disclosure

The SKILL.md is an overview pointing to three real, verified, one-level-deep bundle files, clearly linked with descriptive labels both up front and in the Reference section. Minor gaps keep it below anchor 5: the reference links are duplicated (lines 25-29 and 103-104), and long inline enumerations (the six-item Scope list, nine Constraints bullets) could largely live in the references rather than the overview.

4 / 5

Total

13

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit, well-scoped trigger clause and domain-specific keywords that make it highly distinguishable from other skills. Its main weaknesses are the absence of a standalone 'what this skill does/outputs' statement and missing common synonyms (CRA, CE marking, Regulation 2024/2847).

Suggestions

Add a leading 'what' clause stating what the skill produces (e.g., 'Reviews Java products for EU Cyber Resilience Act gaps and generates an engineering review report with owner handoffs'), followed by the existing 'Use when...' trigger.

Include common user-side synonyms such as 'CRA', 'Regulation (EU) 2024/2847', 'CE marking', and 'cybersecurity compliance' among the trigger terms.

Drop the vague 'services' from the product list and the 'Part of Plinth Toolkit' trailer, which add overlap risk and no trigger value.

DimensionReasoningScore

Specificity

Names the domain (EU Cyber Resilience Act for Java enterprise products) and enumerates concrete control areas ('secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls'), but the actions ('reviewing, designing, or modifying') are generic and it never states what the skill produces, leaving minor coverage gaps versus the comprehensive anchor 5.

4 / 5

Completeness

The 'when' is explicit and strong ('Use when reviewing, designing, or modifying...'), but the 'what' is only interwoven into that trigger clause — there is no standalone statement of what the skill does or outputs, matching anchor 4 ('both what and when; when could be more explicit') rather than the fully explicit anchor 5.

4 / 5

Trigger Term Quality

Good natural keyword coverage ('Java', 'EU Cyber Resilience Act', 'SBOM', 'vulnerability handling', 'security update', 'release-readiness'), but common user-side synonyms like 'CRA', 'compliance', 'CE marking', or 'Regulation 2024/2847' are missing, so it falls short of the comprehensive synonym coverage of anchor 5.

4 / 5

Distinctiveness Conflict Risk

Clear niche with distinct triggers — 'EU Cyber Resilience Act', 'SBOM', 'products with digital elements' would not naturally fire a general Java or general security skill. 'Part of Plinth Toolkit' is harmless padding; it sits clearly at anchor 5.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 3 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
jabrena/plinth
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.