CtrlK
BlogDocsLog inGet started
Tessl Logo

ark-vulnerability-fixer

CVE research and security patch workflow for Ark. Provides CVE API integration, mitigation strategies, and security-focused PR templates. Works with research, analysis, and setup skills for comprehensive vulnerability fixing.

70

1.01x
Quality

61%

Does it follow best practices?

Impact

79%

1.01x

Average score across 3 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/vulnerability-fixer/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable skill body with executable CVE-research, dependency-scan, and PR-creation commands, plus a well-sequenced workflow gated by mandatory user approval. Its two weaknesses are noticeable redundancy — the workflow, skill composition, API details, and dependency guidance each appear twice — and a monolithic structure where the long PR templates and per-ecosystem details belong in reference files. Trimming duplicates and splitting templates into references would meaningfully improve it.

Suggestions

Remove the duplicated sections: delete 'Common Vulnerability Types' (restates Dependency Analysis + Implementation), merge 'Important Notes' CVE API/security-context details into their original sections, and state the complete workflow only once.

Move the commit-message and PR templates (~100 lines) into a references/ file (e.g., references/pr-templates.md) and point to it from the body, enabling progressive disclosure.

Add an error-recovery loop after verification (e.g., 'If make test fails: fix the breaking change, re-run, and note the failure in the PR Testing section') to strengthen workflow validation.

DimensionReasoningScore

Conciseness

Roughly a quarter of the ~410-line body is redundant padding: the workflow is listed twice ('When to use this skill' and 'Complete workflow example'), the skill composition appears twice, CVE API details repeat ('CVE API Integration' vs 'CVE API Usage'), the Ark security context repeats ('Assessing Impact' vs 'Ark Security Context'), and 'Common Vulnerability Types' restates the 'Dependency Analysis' and 'Implementation' commands almost verbatim. Not 3 because the duplication goes beyond minor tightening; not 1 because it never explains concepts Claude already knows and the commands themselves are concrete.

2 / 5

Actionability

Concrete, executable commands throughout — a real API call ('curl -s "https://cve.circl.lu/api/cve/CVE-2025-55183"'), 'go get package@v1.2.3 && go mod tidy', 'npm audit fix', 'gh pr create', and a working jq lockfile query. Not 5 because many blocks are placeholder templates ('[component]', 'CVE-YYYY-NNNNN', 'package-name') that are not copy-paste ready without the flexibility being explicitly justified; not 3 because the guidance is genuinely executable, not pseudocode.

4 / 5

Workflow Clarity

A clearly sequenced six-step workflow with an explicit '**STOP AND WAIT** for user approval' checkpoint, a CVE research checklist, verification steps ('make test', 'make build', 'grep -r'), and skip criteria for integration testing. Not 5 because error-recovery loops are thin — there is no guidance on what to do when tests or the build fail; not 3 because validation checkpoints for the risky git-clone/push operations are explicitly present.

4 / 5

Progressive Disclosure

The body is a single monolithic file with no bundle files at all (no references/, scripts/, or assets/ exist), yet ~100 lines of PR/commit message templates and per-ecosystem dependency detail are inlined — content that clearly belongs in separate reference files. Not 2 because the section headers make the file well-navigable and structured rather than minimally organized; not 4 because there are no one-level-deep references and content that should be separate is inline.

3 / 5

Total

13

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solidly specific, third-person description that names concrete CVE-patch capabilities and carves out a distinct niche for Ark. Its main defect is the complete absence of 'when to use' trigger guidance, which caps completeness and weakens trigger-term quality. Adding an explicit 'Use when...' sentence with natural phrases (e.g., 'Use when the user mentions a CVE number or asks to patch a security vulnerability') would lift it substantially.

Suggestions

Append an explicit trigger clause, e.g., 'Use when the user mentions a CVE number, reports a security vulnerability, or asks to patch/upgrade a vulnerable dependency in Ark.'

Replace the padded closing sentence ('Works with research, analysis, and setup skills for comprehensive vulnerability fixing') with concrete trigger terms like 'CVE number', 'security advisory', or 'vulnerability fix'.

Mention the concrete artifacts users get (e.g., 'commit and PR templates pre-filled with CVE details') to sharpen specificity.

DimensionReasoningScore

Specificity

The description lists several concrete capabilities — 'CVE research', 'CVE API integration', 'mitigation strategies', and 'security-focused PR templates' — with only minor gaps in coverage. It falls short of 5 because the closing phrase 'comprehensive vulnerability fixing' is padded filler and the actions are not exhaustively enumerated.

4 / 5

Completeness

The 'what' is clear and multi-part ('Provides CVE API integration, mitigation strategies, and security-focused PR templates'), but there is no 'Use when...' clause or equivalent explicit trigger guidance, capping completeness at 3 per the judging guidelines. Not 4 because the 'when' is entirely absent rather than merely imprecise.

3 / 5

Trigger Term Quality

It includes good natural keywords users would say — 'CVE', 'security patch', 'vulnerability' — but misses common phrasings like 'fix a CVE', 'security advisory', or 'exploit'. Not 3 because keyword coverage is solid rather than partial; not 5 because it lacks synonym breadth.

4 / 5

Distinctiveness Conflict Risk

CVE research and security patching scoped specifically 'for Ark' is a clear niche with distinct CVE/security-patch triggers, giving minimal conflict risk with unrelated skills. Not 5 because it still overlaps with generic security-fix or dependency-update skills, and the reference to 'research, analysis, and setup skills' blurs boundaries slightly.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
mckinsey/agents-at-scale-ark
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.