CtrlK
BlogDocsLog inGet started
Tessl Logo

building-patch-tuesday-response-process

Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within risk-based remediation SLAs, from advisory review through validation. Use when building or improving a monthly patch management workflow or prioritizing which CVEs to remediate first.

62

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/building-patch-tuesday-response-process/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

60%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The operational core is solid — a well-sequenced five-step workflow with ring-based deployment, SLA tables, checklists, monitoring, and a validation pass. The main defects are the orphaned bundle (six files never referenced from the body, with their content duplicated inline) and time-sensitive statistics embedded in the Overview rather than delegated to references/standards.md.

Suggestions

Add a 'References' or 'Resources' section that explicitly links the existing bundle files (e.g., '**MSRC/CVRF API fields**: See [references/api-reference.md](references/api-reference.md)', '**Report template**: See [assets/template.md](assets/template.md)', '**Automation**: See [scripts/process.py](scripts/process.py)) so the bundle is discoverable and one level deep.

Move the time-sensitive 2025 statistics ('1,129 vulnerabilities', '11.9% increase', '49%/34%/7%') out of the Overview and into references/standards.md (where they already exist), keeping the body evergreen.

Replace the non-executable scan pseudocode in Step 3 with a pointer to the runnable scripts/process.py (or fix the snippet's undefined 'patch_tuesday_date' and out-of-loop 'scan_id'), and cut the boilerplate 'When to Use' section that restates the description.

DimensionReasoningScore

Conciseness

Mostly efficient — tables and checklists carry real information — but the Overview inlines time-sensitive 2025 statistics ('patched over 1,129 vulnerabilities across the year -- an 11.9% increase... 49%... 34%... 7%') that duplicate references/standards.md and are not in an 'old patterns' section, and the 'When to Use' section is boilerplate padding that restates the description ('When deploying or configuring building patch tuesday response process capabilities in your environment'). This matches anchor 3 (mostly efficient with some unnecessary content that could be tightened) rather than 4, whose over-explanation would be only minor.

3 / 5

Actionability

Largely concrete: a preparation checklist, a 9-step triage process with real URLs (msrc.microsoft.com/update-guide, CISA KEV), CVSS/EPSS thresholds tied to SLAs, and ring definitions specifying scope, method, approval, and rollback. The Python scan snippet is illustrative rather than executable ('scanner_api' abstraction, and 'scan_id' is referenced outside the loop where it is defined, with undefined 'patch_tuesday_date'), which is the kind of minor gap anchor 4 describes; not 5 because no copy-paste-ready commands (e.g., PowerShell/SCCM) are given and the snippet would not run as written, not 3 because the operational guidance outside the snippet is specific and executable in substance.

4 / 5

Workflow Clarity

The five steps are clearly sequenced with a timeline table (T+0 through T+30) including owners, a pre-patch checklist, per-ring soak periods ('48-hour soak period, check for BSOD, app crashes'), monitoring, and a dedicated Step 5 validation pass ('Re-scan... Compare pre-patch and post-patch scan results'). This satisfies the batch-operation validation requirement, so no cap at 3 applies. It falls at anchor 4 rather than 5 because recovery is only partially a closed loop — 'Identify failed patches and investigate root causes' and 'Immediate rollback if service degradation' name the response but there is no explicit validate -> fix -> re-deploy -> re-scan feedback loop.

4 / 5

Progressive Disclosure

The bundle contains references/api-reference.md, references/standards.md, references/workflows.md, scripts/agent.py, scripts/process.py, and assets/template.md, yet the body never mentions or links to any of them (no 'See references/...' anywhere), leaving them undiscoverable. Worse, content that belongs in those files is inlined and duplicated: the 2025 statistics appear both in the Overview and in standards.md, and the T+0..T+30 timeline duplicates workflows.md's lifecycle. This matches anchor 2 (content that clearly belongs in separate files is inlined; references effectively buried) rather than 3, whose references would at least be present but weakly signaled.

2 / 5

Total

13

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete actions, named products and tooling, and an explicit 'Use when...' clause with realistic trigger phrases. The only weaknesses are a few missing natural synonyms and mild overlap in trigger wording with closely related patch-management skills.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions ('triaging, testing, and deploying') scoped to named products (Windows, Office, Exchange, SQL Server, Azure) via named tooling (WSUS/SCCM) with a concrete SLA framing ('risk-based remediation SLAs, from advisory review through validation'). Coverage of the workflow is comprehensive, matching the anchor for multiple specific concrete actions; not 4 because no meaningful capability is left unnamed.

5 / 5

Completeness

It explicitly answers 'what' (establish a repeatable process for triaging, testing, and deploying Microsoft Patch Tuesday updates within SLAs) and 'when' with a concrete 'Use when building or improving a monthly patch management workflow or prioritizing which CVEs to remediate first' clause. Both elements are explicit with concrete trigger phrases, matching the top anchor; not 4 because the 'when' clause is already specific rather than merely adequate.

5 / 5

Trigger Term Quality

Natural trigger terms are present ('Patch Tuesday', 'patch management workflow', 'CVEs', 'prioritizing which CVEs to remediate first'), which users would plausibly say. A few common variations are missing (e.g., 'Microsoft updates', 'Windows Update', 'WSUS patching', 'monthly patching cycle'), so it falls just short of the comprehensive-synonym anchor of 5 but clearly above anchor 3's partial coverage.

4 / 5

Distinctiveness Conflict Risk

The niche is clear (Microsoft Patch Tuesday via WSUS/SCCM with ring-based SLAs) with distinct triggers, but the 'when' clause ('building or improving a monthly patch management workflow') overlaps with closely related sibling skills like 'implementing-patch-management-workflow' and 'performing-cve-prioritization-with-kev-catalog'. Minor overlap risk with closely related skills matches anchor 4; not 5 because of that sibling-skill overlap, not 3 because the Microsoft/Patch-Tuesday scoping keeps it mostly distinct.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.