CtrlK
BlogDocsLog inGet started
Tessl Logo

gog-drive-audit

Read-only Google Drive sharing and permission audits with gog.

64

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/gog-drive-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exemplar of lean, actionable skill writing: bounded executable commands, concrete classification categories and output fields, and a strict read-only safety rule with a dry-run gate for any remediation. The only gaps are minor — no error/truncation handling for the bounded batch commands, and prerequisite references that sit outside the bundle.

DimensionReasoningScore

Conciseness

"Run bounded, read-only inventory commands" followed directly by the commands, then "Classify ... separately. Include file ID, name, owner, permission, and evidence." — lean, assumes Claude's competence, no padding or over-explanation. Every token earns its place.

5 / 5

Actionability

Three fully executable copy-paste-ready gog commands cover the common cases (sharing audit, internal-domain variant, per-user audit), and the output requirements are concrete (file ID, name, owner, permission, evidence). Matches the 'copy-paste ready, specific examples cover the common cases' anchor.

5 / 5

Workflow Clarity

Clear sequence — read prerequisite skills, run bounded read-only commands, classify findings, report with evidence — and the one risky path (remediation) has an explicit validation gate: "present a separate, reviewable plan and use each mutation's --dry-run before any approved write". Not 5 because there is no checkpoint for audit-level issues such as results hitting the --max 200 bound or command errors.

4 / 5

Progressive Disclosure

The short body is well organized with clearly signaled, one-level-deep references ("Read `../gog/SKILL.md` and `../gog-drive/SKILL.md` first.") and no content that should be split out. Not 5 because the referenced sibling skill paths lie outside this skill's bundle and could not be verified to resolve, leaving navigation partially unconfirmed.

4 / 5

Total

18

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, third-person, and specific about the domain and tool, but it omits any explicit "when to use" trigger clause, which both caps completeness and weakens its value for skill selection. Trigger vocabulary covers the core terms but misses common user phrasings like "shared links" or "who has access".

Suggestions

Add an explicit trigger clause, e.g. "Use when the user asks to audit Drive sharing, check who has access to files, or review Google Drive permissions."

Broaden trigger vocabulary with natural synonyms such as "shared links", "external access", and "Drive".

Optionally name the concrete audit outputs (public links, external-domain grants, stale grants) to sharpen the "what".

DimensionReasoningScore

Specificity

"Read-only Google Drive sharing and permission audits with gog" names the domain and the single action "audits" with qualifiers (sharing, permission, read-only), but does not enumerate several concrete actions, matching the 'names domain and 1-2 concrete actions, not comprehensive' anchor. Not 4 because it lacks a list of several specific capabilities.

3 / 5

Completeness

The "what" is clear (read-only Google Drive sharing and permission audits using gog), but there is no "Use when..." clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric guidelines.

3 / 5

Trigger Term Quality

Natural terms users would say are present — "Google Drive", "sharing", "permission", "audits" — giving good keyword coverage. Not 5 because common variations like "Drive", "shared links", "access", or "who can see" are missing.

4 / 5

Distinctiveness Conflict Risk

A clear niche — Drive permission/sharing auditing, further distinguished by the tool name "gog" — with minimal conflict risk against unrelated skills. Not 5 because it could overlap with a broader gog or Drive-management skill (the body itself defers to sibling gog skills).

4 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openclaw/gogcli
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.