CtrlK
BlogDocsLog inGet started
Tessl Logo

identity-firewall

The L2 Channel Separation and Prompt Firewall defense mechanisms to prevent injection attacks and Helpful Assistant regression.

34

Quality

30%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/identity-firewall/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

26%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is too sparse to be useful: it restates the description and points to an audit file that is absent from the bundle. There are no executable instructions or workflow steps a reader can follow.

Suggestions

Either add the missing audits/channel-separation.md file with the detailed guidance, or inline the essential content directly.

Provide concrete, executable steps (e.g., specific checks or commands) for applying the firewall rather than only a description.

Add a validation or verification step so Claude can confirm the firewall is correctly applied.

DimensionReasoningScore

Conciseness

The body is extremely lean with no over-explanation, mostly respecting token budget, though it is so thin it re-states the description with little added value; this sits above the midpoint of efficient-but-could-be-tightened.

4 / 5

Actionability

The only guidance is a pointer to 'audits/channel-separation.md', which does not exist in the bundle; there is no concrete code, command, or specific instruction, matching the entirely-vague anchor.

1 / 5

Workflow Clarity

There is no multi-step sequence and no validation checkpoints, and the single referenced file is missing, so steps are effectively absent.

1 / 5

Progressive Disclosure

A single one-level reference is signaled, but the referenced file (audits/channel-separation.md) does not exist and no other bundle files are present, leaving navigation broken and structure minimal.

2 / 5

Total

8

/

20

Passed

Description

33%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description names a recognizable security niche but relies on insider jargon and provides no trigger guidance, leaving a reader unsure when to invoke it. It answers 'what' only vaguely and never 'when'.

Suggestions

Add an explicit 'Use when...' clause naming natural triggers (e.g., 'Use when defending against prompt injection or resisting adversarial role overrides').

Replace insider terms ('L2 Channel Separation', 'Helpful Assistant regression') with or alongside plain-language phrases a user would actually say.

State concrete actions the skill performs rather than just naming the defense mechanisms.

DimensionReasoningScore

Specificity

Names the domain ('L2 Channel Separation and Prompt Firewall defense mechanisms') and a concrete purpose ('prevent injection attacks and Helpful Assistant regression'), but describes mechanisms rather than concrete actions Claude performs, matching the score-3 anchor of domain plus 1-2 actions but not comprehensive.

3 / 5

Completeness

The 'what' is vague and there is no 'Use when...' or equivalent trigger guidance, so it answers neither 'what' nor 'when' clearly; the missing trigger clause caps completeness below the midpoint.

2 / 5

Trigger Term Quality

Aside from 'injection attacks', the terms ('L2 Channel Separation', 'Prompt Firewall', 'Helpful Assistant regression') are insider jargon users would rarely say naturally, and common synonyms/variations are absent, fitting below the score-3 anchor.

2 / 5

Distinctiveness Conflict Risk

The 'Identity Firewall' niche is somewhat specific and unlikely to collide with unrelated skills, but the jargon-heavy framing could still overlap with general prompt-injection defense skills, matching the score-3 anchor.

3 / 5

Total

10

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
neomjs/neo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.