CtrlK
BlogDocsLog inGet started
Tessl Logo

building-soc-metrics-and-kpi-tracking

Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness.

64

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/building-soc-metrics-and-kpi-tracking/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-sequenced, highly actionable set of executable SPL queries for SOC metrics, weakened by padded reference-style sections, hardcoded time-sensitive example data, and complete failure to reference the existing bundle files (references/api-reference.md, scripts/agent.py). The biggest structural fix is linking the bundle files and trimming the concept/tool re-explanations and dated examples.

Suggestions

Link the existing bundle files from the body — e.g., under a "Tools & Systems" or new "Automation" section add "**Automated collection**: See [references/api-reference.md](references/api-reference.md) for the agent CLI and function reference; [scripts/agent.py](scripts/agent.py) collects these metrics via the Splunk REST API" — so progressive disclosure actually uses the bundle.

Remove or de-scope the padded sections: the Key Concepts definitions, the Tools & Systems descriptions of what Grafana/Power BI/ATT&CK Navigator are, and the fabricated values in the makeresults Security Posture Scorecard query.

Replace hardcoded dates ("March 2024" in the output template, 2024 dates in the initiatives CSV) with relative placeholders, and either document the required lookup CSV files' schemas or replace the `---` SPL comment style with valid Splunk comment syntax so the queries run as written.

DimensionReasoningScore

Conciseness

The SPL queries are dense and earn their tokens, but several sections pad the file: the Key Concepts table re-defines standard metrics, Tools & Systems explains what Grafana/Power BI are, and the Output Format and initiative CSV hardcode time-sensitive fabricated data ("March 2024", 2024 dates) outside any deprecated/old-patterns section, which the guidelines explicitly penalize. Mostly efficient overall with several unnecessary explanations — the 3 anchor rather than 2, since the core content is genuinely useful and non-trivial.

3 / 5

Actionability

Eleven concrete Splunk SPL queries with real field names and a report template provide mostly copy-paste-ready guidance. Not a 5: the lookup-based queries depend on unstated CSV files (detection_rules_attack_mapping.csv, attack_techniques_total.csv, expected_data_sources.csv, soc_improvement_initiatives.csv) with no setup guidance, and `---` is used as an SPL comment style, which is not valid Splunk syntax and would break execution.

4 / 5

Workflow Clarity

Six clearly sequenced steps (define metrics framework → measure MTTD/MTTR → alert quality/productivity → detection coverage → executive dashboard → continuous improvement) with well-defined outputs per step. The operations are read-only reporting, so the destructive/batch validation cap does not apply; still not a 5 because there are no explicit checkpoints or feedback loops (e.g., verifying data availability against the stated prerequisites).

4 / 5

Progressive Disclosure

The body is well-sectioned with clear headers, but bundle files exist (references/api-reference.md and scripts/agent.py) and are never referenced or linked anywhere in SKILL.md — grep confirms zero mentions. Content that belongs behind a one-level-deep reference (the automated agent and API details) is orphaned while the body inlines ~270 lines of query content. This matches the 3 anchor (references present but not clearly signaled; content that should be separate is inline) rather than 4, because the references are not signaled at all.

3 / 5

Total

14

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it explicitly states both what the skill does and when to use it, with specific, quantifiable capabilities and natural trigger phrases. The only weaknesses are a few missing keyword variations and slight overlap potential with adjacent SIEM/security-reporting skills.

DimensionReasoningScore

Specificity

"Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data" lists multiple specific concrete actions with comprehensive coverage of the domain's metric categories. It matches the 5 anchor (comprehensive coverage) rather than 4 (minor gaps), since the enumeration spans the full scope of SOC performance measurement.

5 / 5

Completeness

Both questions are explicitly answered: the "what" is "Builds SOC performance metrics and KPI tracking dashboards measuring [five named metric categories]", and the "when" is an explicit "Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness." Concrete trigger phrases match the 5 anchor; it does not fall to 4 because the when-clause is fully explicit rather than merely present.

5 / 5

Trigger Term Quality

Natural terms include "SOC leadership", "MTTD", "MTTR", "KPI tracking", "executive-level reporting", "operational visibility", and "SIEM data" — phrases a user needing this skill would plausibly say. Not a 5 because common variations such as "SOC performance", "security operations metrics", or "dashboard" are absent, leaving a few natural terms missing.

4 / 5

Distinctiveness Conflict Risk

The SOC-metrics/KPI-reporting niche with domain-specific triggers (MTTD, MTTR, alert quality ratios, SOC leadership) is mostly distinct with minimal conflict risk against unrelated skills. Not a 5 because there is minor overlap potential with broader SIEM analytics or general security-operations reporting skills.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.