CtrlK
BlogDocsLog inGet started
Tessl Logo

identity-firewall

The L2 Channel Separation and Prompt Firewall defense mechanisms to prevent injection attacks and Helpful Assistant regression.

25

Quality

16%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/identity-firewall/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

15%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a near-empty stub: one abstract concept sentence and a dead link to a missing audit file. It offers no actionable guidance, no workflow, and broken progressive disclosure.

Suggestions

Replace the concept paragraph with concrete, actionable guidance (specific checks, rules, or prompts Claude should apply to resist injection and subservience).

Create the referenced audits/channel-separation.md (or remove the link) so progressive disclosure points to a real, one-level-deep file.

If the skill involves verification of resistance, add a short validation/verification step so the workflow has an explicit checkpoint.

DimensionReasoningScore

Conciseness

The body is lean and free of padding, but its few tokens do not all earn their place — the single substantive line is a pointer to a file that does not exist, so the brevity reflects missing content rather than efficient content.

2 / 3

Actionability

No concrete code, commands, or specific guidance appear; it describes a concept ("ensures that the agent retains its role") and points to a missing file rather than instructing what to do.

1 / 3

Workflow Clarity

There is no sequence of steps and no single unambiguous action — even for a simple skill, the body states a concept without telling Claude what to do or how to verify it.

1 / 3

Progressive Disclosure

The only reference, [Channel Separation Audit](audits/channel-separation.md), points to a non-existent file (no audits/ or other bundle directory is present), so navigation is broken rather than well-structured.

1 / 3

Total

5

/

12

Passed

Description

17%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a jargon-heavy noun phrase that names mechanisms and a goal but no concrete actions, and it lacks any explicit trigger guidance. It is somewhat distinctive in niche but weak on trigger terms and completeness.

Suggestions

Add an explicit 'Use when...' trigger clause naming natural user phrasings (e.g., prompt injection, jailbreak attempts, sycophancy/Helpful Assistant rollback).

Rewrite as a third-person action statement with concrete verbs (e.g., 'Detects and blocks prompt-injection attempts and restores the agent's peer role...').

Replace internal jargon ('L2 Channel Separation', 'Helpful Assistant regression') with terms a user would actually say, keeping the jargon as secondary keywords.

DimensionReasoningScore

Specificity

It names concrete mechanisms ("L2 Channel Separation", "Prompt Firewall") and a purpose ("prevent injection attacks and Helpful Assistant regression"), but states no action verbs describing what the skill actually does — only abstract mechanism names.

2 / 3

Completeness

It gives a weak, abstract "what" and entirely omits a "Use when..." trigger clause for "when", so both halves are weak or missing.

1 / 3

Trigger Term Quality

The dominant terms ("L2 Channel Separation", "Prompt Firewall", "Helpful Assistant regression") are internal jargon a user would not naturally say; only "injection attacks" resembles natural user phrasing.

1 / 3

Distinctiveness Conflict Risk

The niche (identity/prompt-firewall defense) is fairly specific, but the abstract framing could still overlap with other injection-defense or safety skills.

2 / 3

Total

6

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
neomjs/neo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.