CtrlK
BlogDocsLog inGet started
Tessl Logo

talk-tal-skills-security

Defensive review of AI-agent skills, plugins, and tools using Liran Tal's security principles. Use when assessing provenance, permissions, data exposure, sandboxing, or approval boundaries before adoption.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actionable reference skill with a clear validated workflow and concrete review checklists. Its main weakness is that the referenced bundle files (outline.md, quote.md, transcript.md) are not present in the skill directory.

Suggestions

Ship the referenced bundle files (outline.md, quote.md, transcript.md) in references/ so the clearly-signaled links resolve; dangling references are the single largest content gap.

Consolidate the two review-checklist tables ("Review A Skill" and "Review a Repository") or explicitly cross-reference them to remove near-duplicate structure.

Fold the status-to-verdict mapping into the checklist section instead of a standalone paragraph to reduce repetition.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence without explaining basic concepts, but the two near-duplicate review-checklist tables and the status/verdict mapping detail could be tightened.

4 / 5

Actionability

As an instruction-only skill it gives highly actionable guidance: a concrete checklist table with explicit evidence lanes, fixed verdict/status vocabularies, explicit remediation requirements, and a worked example.

5 / 5

Workflow Clarity

The numbered 7-step workflow is clearly sequenced with explicit verification (step 3) and a fail-fast feedback loop (step 7, Validation, Failure Mode) at each required lane.

5 / 5

Progressive Disclosure

Sections are well-organized with clearly-signaled one-level-deep references (outline.md, quote.md, transcript.md), but those referenced files are absent from the bundle, leaving the navigation partially broken.

4 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description cleanly states both what the skill does and when to invoke it, anchored to a named security framework with a concrete, comprehensive list of review dimensions. Trigger keywords are strong but could add a few natural synonyms.

DimensionReasoningScore

Specificity

"assessing provenance, permissions, data exposure, sandboxing, or approval boundaries" lists multiple specific concrete review actions with comprehensive coverage of the security-review domain.

5 / 5

Completeness

"Defensive review of AI-agent skills, plugins, and tools using Liran Tal's security principles" states the what, and "Use when assessing provenance, permissions, data exposure, sandboxing, or approval boundaries before adoption" states the when with concrete trigger phrases.

5 / 5

Trigger Term Quality

"provenance, permissions, data exposure, sandboxing, approval boundaries" gives good keyword coverage a user would say, but lacks common synonyms or file-format variations, so it sits just below the comprehensive anchor.

4 / 5

Distinctiveness Conflict Risk

The named framework (Liran Tal) and the agent-skill/plugin security-review niche give a clear, distinct trigger with minimal overlap risk.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
jscraik/Agent-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.