CtrlK
BlogDocsLog inGet started
Tessl Logo

building-detection-rule-with-splunk-spl

Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/building-detection-rule-with-splunk-spl/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable SPL throughout and a clear build workflow, but it underperforms on progressive disclosure: none of the provided bundle files (references, scripts, assets) are signaled or linked from the body.

Suggestions

Add a navigation section linking the bundle files, e.g. "API reference: see [references/api-reference.md]", "Full workflows: [references/workflows.md]", "Rule template: [assets/template.md]", "Generator/validator scripts: [scripts/process.py]".

Trim non-essential prose such as the "21% of MITRE ATT&CK" overview stat to tighten conciseness toward anchor 5.

Add an explicit validation feedback loop to the build steps (e.g. "run scripts/process.py to validate, fix SPL errors, re-validate") to lift workflow_clarity toward 5.

DimensionReasoningScore

Conciseness

The body is code-forward and assumes Claude's SPL competence, with only minor over-explanation (e.g. the "21% of MITRE ATT&CK" stat and threshold prose), fitting anchor 4 rather than 5's fully lean bar.

4 / 5

Actionability

Every section provides copy-paste-ready, executable SPL covering six detection patterns, a configuration template, enrichment lookups, performance tuning, and validation metrics, matching anchor 5's fully-executable comprehensive examples.

5 / 5

Workflow Clarity

An 8-step build process plus a dedicated testing/validation section gives a clear sequence, but there is no explicit validate→fix→retry feedback loop on rule construction, so it sits at anchor 4 rather than 5.

4 / 5

Progressive Disclosure

The body is well-sectioned, but the bundle files (references/api-reference.md, standards.md, workflows.md, scripts/agent.py, process.py, assets/template.md) are never referenced or linked from the body, so navigation to deeper material is absent rather than merely unclear.

3 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and domain-distinct with good natural trigger terms, but it omits an explicit "Use when..." clause, which caps its completeness and leaves the "when to use" guidance implicit.

Suggestions

Add an explicit trigger clause, e.g. "Use when building or tuning Splunk ES correlation searches, writing SPL detection rules, or mapping SOC alerts to MITRE ATT&CK techniques."

Include common synonyms users say ("SIEM rules," "Splunk alerts," "notable events") to broaden trigger-term coverage.

State 1-2 more concrete outcomes (e.g. "enrich events with asset and threat-intel context") to round out capability coverage toward a 5.

DimensionReasoningScore

Specificity

Names the domain and several concrete actions ("Build effective detection rules," "correlation searches," "identify security threats") with only minor coverage gaps, fitting anchor 4 rather than 3 (which requires just 1-2 actions) or 5 (which needs comprehensive coverage).

4 / 5

Completeness

The description gives a clear "what" but no "Use when..." trigger clause; per the rubric a missing explicit trigger caps completeness at 3, and it is not 4 because the "when" is entirely absent rather than merely weak.

3 / 5

Trigger Term Quality

Includes natural SOC terms ("Splunk," "SPL," "correlation searches," "detection rules," "SOC," "security threats") a user would say, but misses common synonyms like "SIEM rules" or "alerts," matching anchor 4 over anchor 5's comprehensive coverage.

4 / 5

Distinctiveness Conflict Risk

It targets a clear niche (Splunk SPL correlation searches for SOC detection) with minimal conflict risk, but lacks explicit trigger phrases to fully distinguish it from adjacent SIEM skills, landing at anchor 4 rather than 5.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.