CtrlK
BlogDocsLog inGet started
Tessl Logo

building-role-mining-for-rbac-optimization

Apply bottom-up and top-down role mining techniques, including clustering algorithms and formal concept analysis, to discover optimal RBAC roles from existing user-permission assignments, consolidating overlapping roles and enforcing least privilege. Use when an identity program needs to reduce role explosion or redesign its RBAC role set from access data.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers genuinely executable guidance with a well-sequenced workflow and validation checklist, but it functions as a monolith: it inlines detailed workflow, algorithm, and standards content while a purpose-built reference/scripts bundle sits on disk completely unreferenced. Wiring the SKILL.md sections to the existing bundle files is the single highest-impact fix.

Suggestions

Link the existing bundle files from the body: point the Workflow section at references/workflows.md, the Core Concepts/Metrics material at references/api-reference.md and references/standards.md, and the code steps at scripts/process.py and scripts/agent.py instead of duplicating their content inline.

Trim the Overview paragraph's restatement of what role mining and role explosion are, keeping only the operational framing.

Add an explicit validation gate before role migration (e.g., 'only proceed when coverage > 95% and deviation < 5%, else refine and re-evaluate') and replace the exponential FCA enumeration in Step 3 with a bounded closed-itemset approach.

DimensionReasoningScore

Conciseness

The body is mostly lean — the bulk is executable code, comparison tables, and a checklist. The Overview paragraph re-explains what role mining and role explosion are, concepts Claude can largely infer, which is minor over-explanation that could be trimmed; this places it at anchor 4 rather than anchor 5.

4 / 5

Actionability

Steps 1-4 provide concrete, executable pandas/sklearn code (pivot_table UPA construction, AgglomerativeClustering with silhouette analysis, FCA concept mining, metric evaluation), not pseudocode. Minor gaps keep it below anchor 5: the FCA implementation is an exponential brute-force enumeration with a crude 'len(concepts) > 100' cutoff, and the per-role 'coverage' field is computed but never used.

4 / 5

Workflow Clarity

A clear 5-step sequence with checkpoints: Step 4 evaluates coverage/deviation metrics and Step 5 includes a feedback loop ('Refine roles based on feedback and re-evaluate metrics'), backed by a Validation Checklist. Below anchor 5 because the batch/destructive role-migration phase has no explicit validate-fail-retry gating or go/no-go criterion, leaving some checkpoints implicit.

4 / 5

Progressive Disclosure

The bundle contains references/workflows.md, references/api-reference.md, references/standards.md, scripts/agent.py, scripts/process.py, and assets/template.md, yet the body's 'References' section lists only external URLs and never links a single bundle file. Content that clearly belongs in those files (workflow detail, algorithm/API reference) is inlined instead, matching anchor 2 ('content that clearly belongs in separate files is inlined') rather than anchor 3, since the separation exists on disk but is never signaled.

2 / 5

Total

14

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states concrete capabilities in third person, includes specific named techniques (clustering, formal concept analysis), and closes with an explicit, natural 'Use when' trigger phrase targeted at role explosion and RBAC redesign. The only weakness is moderate keyword coverage — a few common synonyms (role engineering, entitlements, access review) are absent.

DimensionReasoningScore

Specificity

Names the domain plus multiple concrete actions: 'Apply bottom-up and top-down role mining techniques, including clustering algorithms and formal concept analysis', 'consolidating overlapping roles and enforcing least privilege'. Comprehensive coverage of concrete capabilities; no minor gaps, so it matches the anchor-5 example rather than anchor 4.

5 / 5

Completeness

Explicitly answers both questions: the 'what' ('discover optimal RBAC roles from existing user-permission assignments, consolidating overlapping roles') and a concrete 'Use when an identity program needs to reduce role explosion or redesign its RBAC role set' trigger. Structurally matches the anchor-5 good example; not anchor 4, whose 'when' is generic.

5 / 5

Trigger Term Quality

Good natural keywords users would say: 'role explosion', 'RBAC role set', 'identity program', 'access data', 'least privilege'. Falls between anchors 4 and 5: natural synonyms a user might say are missing ('role engineering', 'entitlements', 'access review'), so it lacks the anchor-5 comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

Clear niche (RBAC role mining) with distinct triggers like 'role explosion' and 'identity program'; unlikely to fire for adjacent skills such as generic access review or vulnerability scanning. Minimal conflict risk, matching anchor 5.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.