CtrlK
BlogDocsLog inGet started
Tessl Logo

fix-finding

Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/codex-security/skills/fix-finding/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

73%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly rigorous remediation methodology whose standout strength is workflow clarity with explicit ordered validation gates and feedback loops. Its main weakness is conciseness: scope-broadening prohibitions and boundary-concept enumerations recur across several sections.

Suggestions

Consolidate the repeated 'do not broaden into unrelated cleanup/sibling findings/redesign' rule into one authoritative statement in Hard Rules, and reference it from other sections instead of restating it.

Deduplicate the shared-boundary / source-to-sink inspection language that recurs across Patch Contract, Pre-Patch Investigation, and Patch Candidate Review into a single defined procedure each section points to.

Consider moving the Workbench Remediation Stages (Generate/Apply/Verify) into a separate reference file, keeping SKILL.md as the overview and reducing inline token weight.

DimensionReasoningScore

Conciseness

The body is dense and assumes Claude's security competence (no basic concept explanations), but the scope-broadening prohibition is restated across Objective, Implementation Workflow, Candidate Review, and Hard Rules, and several boundary-concept enumerations repeat across sections, so it could be tightened.

3 / 5

Actionability

Concrete and specific throughout—exact delegation parameters ("fork_turns: none"), exact outcome tokens (fixed/no_change/blocked, generated/applied/verified/failed), ordered verification gates, and a real referenced path—but some passages remain abstract methodology ("identify the shared enforcement boundary") rather than fully executable steps.

4 / 5

Workflow Clarity

An explicit ordered judging criteria (1-6), a numbered Implementation Workflow with ordered verification sub-gates, feedback loops ("revise the implementation if either exists", rerun verification after confirmed fixes), and hard-rule validation checkpoints give it a clear sequence with explicit validation and error recovery.

5 / 5

Progressive Disclosure

Clean section structure (Objective through Hard Rules) with a single clearly-signaled one-level reference (../../references/scan-artifacts.md); the Workbench Remediation Stages block is fairly heavy inline content that could be split out, and no bundle files exist to verify against.

4 / 5

Total

16

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-bounded trigger description that clearly states both capability and activation conditions while explicitly disambiguating itself from broader security-scan skills. The only mild gap is that it lists just one or two concrete actions rather than enumerating several.

DimensionReasoningScore

Specificity

The description names the security-finding domain and two concrete actions ("fix and verify a validated or plausible security finding"), but stops at 1-2 actions rather than listing several, matching the anchor for naming a domain with 1-2 concrete actions.

3 / 5

Completeness

It explicitly answers both what ("fix and verify a validated or plausible security finding") and when ("Use when the user explicitly asks to fix and verify..."), with concrete trigger phrases and explicit negative boundary guidance.

5 / 5

Trigger Term Quality

Natural user phrasing is well covered ("fix", "verify", "security finding", "validated or plausible"), matching the good-coverage anchor; a few common synonyms like "remediate", "patch", or "vulnerability" are absent, keeping it just below comprehensive.

4 / 5

Distinctiveness Conflict Risk

It occupies a clear niche (fixing validated findings) and the explicit "Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans" clause minimizes conflict with broader scan skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openai/plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.