CtrlK
BlogDocsLog inGet started
Tessl Logo

ark-vulnerability-fixer

CVE research and security patch workflow for Ark. Provides CVE API integration, mitigation strategies, and security-focused PR templates. Works with research, analysis, and setup skills for comprehensive vulnerability fixing.

77

1.01x
Quality

Does it follow best practices?

Impact

79%

1.01x

Average score across 3 eval scenarios

SecuritybySnyk

Advisory

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with a clear, well-gated workflow, but it is verbose and monolithic. Removing redundant sections and extracting the large templates into reference files would improve both conciseness and progressive disclosure.

Suggestions

Remove redundant sections: drop the "When to use" list (covered by the description) and consolidate "Ark Security Context" with the earlier impact-assessment content.

Extract the commit-message and PR templates into references/ files (e.g. references/pr-template.md) and link to them from the body.

Move the "Common Vulnerability Types" reference table into a separate reference file so the main body stays a lean overview.

DimensionReasoningScore

Conciseness

The body is mostly efficient but padded with redundancy: the "When to use" section echoes the description, "Ark Security Context" repeats the deployment model, and "Skill Composition" restates the workflow.

2 / 3

Actionability

It provides fully executable curl, grep, go get, npm, and gh pr create commands plus copy-paste-ready commit and PR templates.

3 / 3

Workflow Clarity

The research→analysis→mitigation→approval→clone→implement→test→PR sequence is explicit, with a mandatory "STOP AND WAIT" approval gate and verification steps (make test/build, grep for residual patterns).

3 / 3

Progressive Disclosure

The ~410-line body is monolithic with no bundle files in references/scripts/assets, and large commit/PR templates plus the vulnerability-types reference that could be split out are kept inline.

2 / 3

Total

10

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-scoped to a clear niche, but is missing an explicit "Use when..." trigger clause and richer natural-language trigger terms. Adding trigger guidance would lift the two dimensions currently capped at 2.

Suggestions

Add a "Use when the user mentions a CVE number, asks to patch a security vulnerability, or needs CVE database info" trigger clause to the description.

Expand trigger terms with natural user phrasings like "fix CVE", "patch a vulnerability", or "security advisory".

Trim the trailing skill-composition sentence, which describes relationships rather than capabilities.

DimensionReasoningScore

Specificity

"Provides CVE API integration, mitigation strategies, and security-focused PR templates" lists multiple concrete, distinct capabilities rather than vague language.

3 / 3

Completeness

It clearly states what the skill does, but offers no "Use when..." clause or equivalent explicit trigger guidance, which caps completeness at 2 per the rubric.

2 / 3

Trigger Term Quality

"CVE", "security patch", "vulnerability", and "mitigation" are relevant natural terms, but the description lacks a clause enumerating common user phrasings or variations.

2 / 3

Distinctiveness Conflict Risk

The Ark-specific CVE niche plus naming of complementary skills (research, analysis, setup) gives it a clear, low-conflict trigger surface.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
mckinsey/agents-at-scale-ark
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.