CtrlK
BlogDocsLog inGet started
Tessl Logo

ark-pentest-issue-resolver

Resolve common penetration testing issues in Ark. Use when fixing security vulnerabilities from pentest reports, security audits, or OWASP Top 10 issues.

72

1.04x
Quality

60%

Does it follow best practices?

Impact

96%

1.04x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/pentest-issue-resolver/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

52%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable and anchored by a clear, well-gated workflow, but it functions as a monolithic encyclopedia: ~900 lines of standard OWASP mitigation patterns Claude already knows, with no progressive disclosure to offload the 15-category catalog into reference files. The Ark-specific pointers — the skill's real value — are diluted one-liners inside generic content.

Suggestions

Split the 15 vulnerability categories into reference files (e.g., references/sql-injection.md, references/xss.md) and keep SKILL.md as an overview with the workflow, the keyword→category mapping table, and one-level-deep links to each category.

Trim each category to the Ark-specific detection greps and the recommended mitigation, cutting the generic "what is SQL injection"-style knowledge and multi-language boilerplate Claude already knows.

Add an explicit validation feedback loop to Step 6 ("run `make test`; if security checks fail, fix and re-run before proceeding to the PR") and correct the non-executable snippets (gorilla/csrf `Validate`, Go rate-limiter math) so examples are copy-paste ready.

DimensionReasoningScore

Conciseness

The ~1000-line body extensively restates standard OWASP knowledge Claude already has — parameterized queries, CSRF tokens, `defusedxml`, `yaml.safe_load`, DOMPurify, non-root Docker users, security headers — with only sparse Ark-specific pointers ("Check Python services: `services/ark-api/`") adding new information. This is noticeably verbose with several unnecessary sections (anchor 2), though the code-dominant format avoids the padded prose of anchor 1.

2 / 5

Actionability

Guidance is overwhelmingly concrete: executable Python/Go/JavaScript/YAML mitigations, grep/ripgrep search commands, bandit/gosec/trivy tooling, and a manual testing checklist. Not 5 because a few snippets are not executable as written — `csrf.Validate(token, session)` is not a real gorilla/csrf API, and `rate.Every(time.Minute/5)` contradicts its "5 requests per minute" comment.

4 / 5

Workflow Clarity

The 7-step resolution workflow (identify category → grep for patterns → analyze Ark impact → present options with an explicit "Wait for user approval" gate → implement → test → create PR) is clearly sequenced with key checkpoints present. Not 5 because the test step lacks a feedback loop — there is no "if tests fail, fix and re-run" recovery guidance, and the security-specific tests are left as comments.

4 / 5

Progressive Disclosure

There are no bundle files at all: all 15 vulnerability categories with full code catalogs, the workflow, Ark-specific considerations, and testing checklists are inlined into a single monolithic 1000-line SKILL.md. This is precisely anchor 2 ("content that clearly belongs in separate files is inlined"); it avoids anchor 1 only because section headers make it navigable.

2 / 5

Total

12

/

20

Passed

Description

68%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit and well-targeted "Use when..." clause with solid natural keywords and a distinct niche, but the capability statement is generic — a single "Resolve" verb where the skill actually provides detection patterns, mitigation strategies, and fixes. Strengthening the "what" half would lift it from good to excellent.

Suggestions

Replace the generic "Resolve common penetration testing issues in Ark" with the skill's concrete capabilities, e.g., "Detect vulnerable code patterns and apply mitigations for common penetration testing issues (SQL injection, XSS, CSRF, SSRF, etc.) in the Ark platform."

Add one or two natural trigger phrases users actually say when reporting findings, such as "security findings", "vulnerability report", or named vulns like "XSS" or "SQL injection".

Optionally note the CVE-detection boundary (this skill handles non-CVE findings; CVEs route elsewhere) to sharpen distinctiveness against adjacent security skills.

DimensionReasoningScore

Specificity

"Resolve common penetration testing issues in Ark" names the domain but offers only the single generic action "Resolve" — it does not list the concrete capabilities the body actually provides (detection patterns, mitigation strategies, fixes). This matches anchor 2 ("Names the domain but actions are minimal or generic") rather than 3, which requires 1-2 concrete named actions.

2 / 5

Completeness

It has both an explicit trigger clause ("Use when fixing security vulnerabilities from pentest reports, security audits, or OWASP Top 10 issues") and a "what" ("Resolve common penetration testing issues in Ark"), but the "what" is thin and generic rather than enumerating concrete actions. Anchor 4 ("both 'what' and 'when'; 'when' could be more explicit or specific") fits; anchor 5 requires a concrete, comprehensive statement of both.

4 / 5

Trigger Term Quality

"penetration testing", "pentest reports", "security audits", "OWASP Top 10", and "security vulnerabilities" give good natural keyword coverage a user would plausibly say. Not 5 because common variations users actually report — specific vuln names like "XSS", "SQL injection", or synonyms like "security findings" — are absent from the description.

4 / 5

Distinctiveness Conflict Risk

"Ark" plus the pentest-report/audit/OWASP framing carves out a clear niche with distinct trigger terms, unlikely to fire for unrelated skills. Matches anchor 5 ("Clear niche with distinct triggers; minimal conflict risk").

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (1013 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
mckinsey/agents-at-scale-ark
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.