CtrlK
BlogDocsLog inGet started
Tessl Logo

propose-security-hardening

Develop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code, or a completed Codex Security scan. Use when a user asks for systemic improvements, alternatives beyond per-finding patches, before-and-after security architecture views, engineering tradeoff analysis, or an implementation-ready plan for a selected hardening option. Also use automatically after a Codex Security scan with reportable findings when the top-level scan workflow requests final-report hardening guidance.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

73%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, well-sequenced hardening-analysis skill with concrete artifact contracts, controlled vocabularies, and strong validation/feedback loops in its workflow. Its main weaknesses are repetition of voice and opaque-ID guidance across multiple sections and one referenced path (scan-artifacts.md) that is not present in the bundle.

Suggestions

Consolidate the first-person voice guidance and the opaque-evidence-ID rule into a single authoritative statement instead of restating them in the Objective, Workflow step 9, and Quality Bar.

Resolve the ../../references/scan-artifacts.md reference on line 49 — either point to a file that exists in the bundle or describe the scan-artifact contract inline so the path is not dangling.

Trim the Quality Bar section, which largely restates criteria already embedded in the Workflow steps, to reduce length without losing the acceptance standard.

DimensionReasoningScore

Conciseness

The body assumes Claude's intelligence (no elementary concept explanations) but is lengthy at ~240 lines and repeats the same guidance in multiple places — the first-person voice rules appear in the Objective, Workflow step 9, and Quality Bar, and the opaque-evidence-ID rule is restated three times — which could be consolidated into one authoritative statement.

3 / 5

Actionability

Highly concrete for an instruction-only skill: it specifies exact output files (hardening.json, hardening.md, proposals/<opportunity-id>.md, diagrams/*.mmd, implementation/<option-id>.md), a tool call (get_codex_security_scan_context), reference paths, a stable analysis id (hardening_final), and controlled vocabularies (Observed/Inferred/Proposed; measured/source-derived/analogous/hypothetical; addresses/mitigates/unaffected/unknown), with only the lack of a worked proposal example keeping it from fully copy-paste ready.

4 / 5

Workflow Clarity

A clearly sequenced 10-step workflow with explicit validation checkpoints: step 9 is a validation checklist (parse hardening.json, ID/cross-reference agreement, link containment, per-opportunity proposals and diagrams, all tradeoff dimensions covered, lint checks) with a feedback loop, and step 10 adds a drift re-check loop before implementation.

5 / 5

Progressive Disclosure

Good structure with the bulk of the format spec correctly offloaded to a real, well-signaled one-level-deep reference (references/proposal-format.md, 'Read completely before drafting'), but the body is still fairly long and the path ../../references/scan-artifacts.md referenced on line 49 does not exist in this skill's bundle, a minor navigation gap.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-structured description that explicitly covers both capability and trigger conditions with concrete, domain-appropriate phrases and a clear niche. It is slightly formal in its trigger vocabulary and frames several deliverable variants around a single core action, which keeps specificity just short of fully comprehensive.

DimensionReasoningScore

Specificity

Names the domain and several concrete deliverable actions ('structural and architectural security hardening proposals', 'before-and-after security architecture views', 'engineering tradeoff analysis', 'implementation-ready plan'), though they are variants of one core capability rather than a broad action set, leaving minor coverage gaps versus a fully comprehensive list.

4 / 5

Completeness

Clearly and explicitly answers both what ('Develop evidence-backed structural and architectural security hardening proposals from...') and when ('Use when a user asks for... Also use automatically after a Codex Security scan...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Good keyword coverage with concrete trigger phrases a security engineer would naturally say ('systemic improvements', 'alternatives beyond per-finding patches', 'before-and-after security architecture views', 'engineering tradeoff analysis', 'implementation-ready plan'), though the language is somewhat formal and lacks simpler synonyms or file extensions.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (structural/architectural hardening proposals from vulnerability disclosures or Codex Security scans) with distinct triggers and an explicit auto-invocation hook tied to a specific scan workflow, minimizing conflict with adjacent security skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openai/plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.