CtrlK
BlogDocsLog inGet started
Tessl Logo

vulnerability-writeup

Turn vulnerability notes, disclosure reports, PoCs, source code, or Codex Security findings into self-contained, sceptically validated, natural-sounding vulnerability reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.

65

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/codex-security/skills/vulnerability-writeup/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced methodology skill with strong validation and feedback loops and a real one-level reference. Its main weakness is redundancy: core rules are repeated across several sections, inflating the token budget without adding new guidance.

Suggestions

Consolidate the repeated rules (evidence distinction, 'witness' prohibition, no local paths, actor naming) into one section and reference it from the drafting prompt and acceptance checklist instead of restating them.

Move the full single-finding drafting-prompt template and/or the acceptance checklist into `references/report-format.md` to slim the SKILL.md body and deepen the reference structure.

DimensionReasoningScore

Conciseness

The body is dense and avoids explaining basic concepts, but the same rules (no 'witness', distinguish evidence types, no local absolute paths, named actors) are restated near-verbatim across the rules, actors, drafting-prompt, and acceptance sections, so it could be tightened considerably.

3 / 5

Actionability

It provides a copy-paste fill-in drafting-prompt template, concrete commands like `git show REV:PATH`, exact actor/username conventions, and precise intake and acceptance checklists — fully actionable guidance for an instruction-only skill.

5 / 5

Workflow Clarity

The 10-step Campaign workflow is clearly sequenced with explicit validation (independent re-read against pinned source), feedback loops (reject and relaunch a fresh sub-agent with specific failures, retry once), and checklists for intake and acceptance.

5 / 5

Progressive Disclosure

It has clear section headers and a single, clearly-signaled one-level reference (`references/report-format.md`, which exists), but the body inlines a lot of operational detail — the full drafting prompt and long checklists — that could be split out, leaving minor organization gaps.

4 / 5

Total

17

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with a clear niche and explicit trigger guidance. Its main weakness is that the 'when' clause describes campaign scope rather than concrete user utterances, and the action list is effectively a single transform rather than multiple distinct actions.

Suggestions

Add concrete user-trigger phrasings to the 'Use for...' clause, e.g. 'Use when the user asks to write, draft, or clean up a vulnerability report or disclosure advisory'.

Expand the action beyond a single transform to name distinct steps (e.g. 'validate, scope affected versions, and draft') to lift specificity.

DimensionReasoningScore

Specificity

It names the domain and one core action — 'Turn vulnerability notes, disclosure reports, PoCs ... into ... vulnerability reports' — plus 'sceptically validated', but the listed items are mostly input types rather than several distinct concrete actions, so it is not comprehensive enough for a 4.

3 / 5

Completeness

It states a clear 'what' (turn inputs into validated vulnerability reports) and an explicit 'Use for one vulnerability or a disclosure campaign' trigger clause, but the 'when' describes scope rather than concrete user utterances, so it is not the fully-explicit 5.

4 / 5

Trigger Term Quality

It covers natural terms a security user would say — 'vulnerability notes', 'disclosure reports', 'PoCs', 'source code', 'Codex Security findings' — with useful synonyms, but a few common phrasings (e.g. 'write a CVE/advisory') are absent, stopping short of comprehensive 5-level coverage.

4 / 5

Distinctiveness Conflict Risk

The vulnerability-disclosure-report niche is highly specific with distinct triggers (PoCs, disclosure reports, Codex Security findings) and minimal overlap with other skills, matching the clear-niche anchor.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openai/plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.