CtrlK
BlogDocsLog inGet started
Tessl Logo

deal-with-security-advisory

Handle confidential GitHub Security Advisory response for Paperclip. Use when coordinating advisory triage, private-fork fixes, CVE/publication steps, and immediate security releases.

70

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced security response runbook with copy-paste-ready `gh`/`git` commands and explicit pre-publish and post-publish validation. Its weaknesses are minor: a handful of leftover fragmentary sentences that should be cleaned up, and missing error-recovery guidance for failure points in the publish sequence.

Suggestions

Add brief error-recovery guidance at the fragile points of the workflow — e.g., what to do if the private fork already exists, if local tests fail after the patch, or if the advisory PATCH/publish call fails partway through Step 6 — to close the feedback-loop gap in workflow_clarity.

Clean up the fragmentary or conversational sentences ('Give your human this template, but still continue', 'Proceed', 'Below we use `gh` tools - you do have access and credentials outside of your sandbox, so use them.') into complete instructions, which would also tighten conciseness.

Consolidate the confidentiality rules repeated across the opening warning and the Step 2 TIPS into one authoritative checklist to reduce redundancy.

DimensionReasoningScore

Conciseness

Efficient overall — commands paired with short, pointed directives that assume Claude's competence ('Write the patch. Same content standards as any PR'). A few trimmable artifacts: repeated confidentiality warnings, the inline example '(e.g. GHSA-x8hx-rhr2-9rf7)', and fragmentary sentences like 'Give your human this template, but still continue' and 'Below we use `gh` tools - you do have access and credentials outside of your sandbox, so use them.' Fits 4 (minor trimming possible) rather than 5's every-token-earns-its-place.

4 / 5

Actionability

Fully executable: complete `gh api` commands including heredoc JSON payloads for the PATCH operations, git commands for the private-fork workflow, and a full release-notes template. Placeholders ({{ghsaId}}, {{patchedVersion}}) are clearly templated. Not 4 — there are no gaps in concrete guidance for the common cases.

5 / 5

Workflow Clarity

Steps 0–7 are clearly sequenced with explicit checkpoints: reproduce-first and run-tests-locally guidance in Step 3, Step 6a verifying reporter credit *before* publishing, and Step 7 post-publication verification with concrete `--jq` checks. Falls short of 5 because there are no error-recovery feedback loops (nothing on what to do if fork creation, local tests, or a publish sub-step fails) — only the CVE-propagation tolerance note.

4 / 5

Progressive Disclosure

No bundle files exist, and none are needed: this is a cohesive single-file runbook with clear numbered steps and section headers, nothing inlined that belongs in a separate file. Good structure with minor organization gaps (occasionally dense TIPS lists, the Step 2 workspace setup interleaved with clone commands) — fits 4 rather than 5's fully polished, well-signaled navigation.

4 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concise, with an explicit 'Use when...' clause naming concrete workflow stages. The only improvement space is broader natural-language synonym coverage (e.g., 'vulnerability disclosure', 'GHSA') and slightly fuller enumeration of what the skill does.

DimensionReasoningScore

Specificity

Lists several concrete actions — 'coordinating advisory triage, private-fork fixes, CVE/publication steps, and immediate security releases' — but stops short of comprehensive coverage (e.g., no mention of reporter coordination or release publication mechanics). Fits the 4 anchor (several specific actions, minor gaps) rather than 5's comprehensive coverage.

4 / 5

Completeness

Explicitly answers both: what ('Handle confidential GitHub Security Advisory response for Paperclip') and when ('Use when coordinating advisory triage, private-fork fixes, CVE/publication steps, and immediate security releases') with concrete trigger phrases. Not 4, since the 'when' clause is explicit and specific rather than merely present.

5 / 5

Trigger Term Quality

Good natural keywords: 'Security Advisory', 'CVE', 'security release', 'private fork'. A few natural variants users might say are missing ('vulnerability disclosure', 'responsible disclosure', 'GHSA'), so it fits 4 rather than 5's comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

A clear niche — confidential GitHub Security Advisory response workflow with CVE/publication steps — with distinct, domain-specific triggers; minimal conflict risk with generic security or release skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
paperclipai/paperclip
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.