CtrlK
BlogDocsLog inGet started
Tessl Logo

deal-with-security-advisory

Handle confidential GitHub Security Advisory response for Paperclip. Use when coordinating advisory triage, private-fork fixes, CVE/publication steps, and immediate security releases.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced security response workflow with executable commands and strong validation checkpoints. Minor gains possible by trimming rationale prose and optionally splitting templates into a reference file.

DimensionReasoningScore

Conciseness

Mostly lean and command-driven with prose limited to security-specific cautions Claude would not inherently know (e.g., CI not running on private forks, CVE propagation delay); a few rationale sentences could be trimmed but the bulk earns its place.

4 / 5

Actionability

Fully executable copy-paste-ready `gh api` and git commands with templated placeholders ({{ghsaId}}, {{patchedVersion}}), plus ready-to-use comment templates covering the common cases.

5 / 5

Workflow Clarity

Clear Step 0–7 sequence with explicit validation checkpoints (reproduce then confirm patch, run tests locally, verify reporter credit pre-publish, verify publication/CVE post-publish), feedback notes (CVE delay is normal), and flagged human steps.

5 / 5

Progressive Disclosure

Well-organized into labeled steps and TIPS checklists as a self-contained sequential workflow with no external references; over 50 lines so it does not qualify for the simple-skill 5, and some inline templates could live in a separate file.

4 / 5

Total

18

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A clear, well-structured description that answers both what and when with concrete trigger phrases and a distinct niche. Minor room to tighten action verbs and add common synonyms like 'vulnerability' or 'disclosure'.

DimensionReasoningScore

Specificity

Lists several concrete actions — 'coordinating advisory triage, private-fork fixes, CVE/publication steps, and immediate security releases' — but the verbs are somewhat abstract ('coordinating', 'steps') rather than crisp, keeping it just below the comprehensive anchor 5.

4 / 5

Completeness

Explicitly states the what ('Handle confidential GitHub Security Advisory response for Paperclip') and the when ('Use when coordinating advisory triage, private-fork fixes, CVE/publication steps, and immediate security releases') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural terms ('GitHub Security Advisory', 'CVE', 'security releases', 'advisory triage') a user would say, but common synonyms like 'vulnerability', 'disclosure', and 'GHSA' are absent.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (confidential GitHub Security Advisory response for Paperclip) with distinct triggers and minimal overlap risk with general skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
paperclipai/paperclip
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.