CtrlK
BlogDocsLog inGet started
Tessl Logo

attack-tree-construction

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

55

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-awesome-skills-claude/skills/attack-tree-construction/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

35%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill provides a high-level framework for attack tree construction but lacks the concrete, actionable detail needed to be useful. The instructions read more like an abstract methodology description than executable guidance — there are no example attack trees, no output format specifications, no annotation templates, and no concrete examples of AND/OR decomposition. The referenced implementation playbook could address these gaps but is not provided in the bundle.

Suggestions

Add a concrete example showing a small attack tree with root goal, AND/OR decomposition, and leaf annotations (cost, skill, time, detectability) so Claude knows exactly what output format to produce.

Define the expected output format explicitly — e.g., a Mermaid diagram, markdown outline, or structured table — with a complete worked example.

Add validation checkpoints such as 'verify all leaf nodes have annotations' and 'confirm every path from root to leaf is realistic' to strengthen the workflow.

Either provide the referenced `resources/implementation-playbook.md` bundle file or inline the most critical templates and patterns directly in the skill body.

DimensionReasoningScore

Conciseness

The skill is relatively brief but includes some unnecessary sections like 'Do not use this skill when' and 'Limitations' that largely restate obvious constraints Claude already understands. The safety and limitations sections are somewhat boilerplate.

2 / 3

Actionability

The instructions are vague and abstract — 'Decompose into sub-goals with AND/OR structure' and 'Annotate leaves with cost, skill, time, and detectability' provide no concrete examples, templates, output formats, or executable steps. There are no example attack trees, no sample annotations, and no concrete guidance on what the output should look like.

1 / 3

Workflow Clarity

There is a sequential list of steps (confirm scope → decompose → annotate → map mitigations → prioritize), which provides some structure. However, there are no validation checkpoints, no feedback loops for verifying the tree's completeness or accuracy, and no criteria for when a decomposition is sufficient.

2 / 3

Progressive Disclosure

The skill references `resources/implementation-playbook.md` for detailed patterns and templates, which is good progressive disclosure structure. However, no bundle files were provided, so the referenced resource doesn't actually exist, making the reference a dead link that undermines the skill's utility.

2 / 3

Total

7

/

12

Passed

Description

89%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This is a well-structured description with a clear 'Use when...' clause and strong trigger terms specific to the attack tree domain. Its main weakness is that the 'what' portion could be more specific about the concrete actions performed beyond just 'build attack trees.' Overall it is a strong description that would perform well in skill selection.

Suggestions

Add more specific concrete actions to the 'what' portion, e.g., 'Build comprehensive attack trees, enumerate threat vectors, rank attack likelihood, and suggest mitigations to visualize threat paths.'

DimensionReasoningScore

Specificity

It names the domain (attack trees, threat paths) and a primary action (build comprehensive attack trees), but doesn't list multiple specific concrete actions like 'enumerate threat actors, rank risk severity, generate mitigation recommendations.' The additional phrases are more about use cases than distinct capabilities.

2 / 3

Completeness

Clearly answers both 'what' (build comprehensive attack trees to visualize threat paths) and 'when' (Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders) with an explicit 'Use when...' clause.

3 / 3

Trigger Term Quality

Includes strong natural keywords users would say: 'attack trees', 'threat paths', 'attack scenarios', 'defense gaps', 'security risks', 'stakeholders'. These cover the natural language a user would use when requesting this type of analysis.

3 / 3

Distinctiveness Conflict Risk

Attack trees are a very specific security modeling technique, making this clearly distinguishable from general security skills, threat modeling skills, or vulnerability scanning skills. The trigger terms are niche and unlikely to conflict with other skills.

3 / 3

Total

11

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.