CtrlK
BlogDocsLog inGet started
Tessl Logo

audit-skills

Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).

36

Quality

33%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

—

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./skills/audit-skills/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

0%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is a verbose, catalog-style listing of security threat patterns that lacks actionable audit procedures, executable code, structured output formats, or clear workflows. It reads more like a security awareness document than an operational skill. The content would benefit enormously from being restructured into a concise overview with concrete audit steps, a defined output schema, and threat pattern details moved to a separate reference file.

Suggestions

Add a concrete, executable audit workflow: define exactly how to traverse bundle files, what patterns to grep/search for, and provide actual regex or code snippets for detection rather than just listing command names.

Define a structured output format (e.g., JSON schema or markdown template) for the security report, including how the 0-10 score is calculated with specific criteria and thresholds.

Move the extensive threat catalog (sections 1-9) into a separate THREATS.md reference file and keep only a concise summary with cross-references in the main SKILL.md.

Remove redundant sections ('When to Use', 'Common Pitfalls', 'Best Practices') that restate obvious points, and replace the vague examples with a complete input/output example showing a real skill snippet being audited with the expected report output.

DimensionReasoningScore

Conciseness

Extremely verbose. The overview repeats the description verbatim. 'When to Use' and 'Best Practices' sections restate obvious points. The massive threat catalog (sections 1-9) reads like a reference document dumped inline rather than concise, actionable guidance. Many items are lists of commands Claude already knows about, with no novel insight added.

1 / 3

Actionability

Despite listing many command patterns, the skill never provides concrete, executable audit procedures. There's no actual code for performing static analysis, no regex patterns to search for, no script to run, no structured output format. The 'Examples' section shows only vague prompts ('Perform a security audit on this skill bundle') with no expected output or step-by-step execution. The reporting step mentions a 0-10 score but never defines the scoring criteria or output template.

1 / 3

Workflow Clarity

The three 'steps' (Static Analysis, Platform-Specific Threat Detection, Reporting) are vague labels without clear sequencing, validation checkpoints, or feedback loops. There's no guidance on how to actually traverse files in a bundle, what order to check things, when to stop, or how to handle ambiguous findings. For a security audit skill involving potentially destructive assessments, the lack of validation steps is a significant gap.

1 / 3

Progressive Disclosure

The content is a monolithic wall of text with no references to external files despite the massive threat catalog being a perfect candidate for a separate reference document. There are no bundle files to support the skill. The reference to 'CATALOG.md' in section 9 is unexplained and unlinked. All content is dumped inline with no layered structure.

1 / 3

Total

4

/

12

Passed

Description

67%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong in specificity and distinctiveness, clearly defining a unique niche of security auditing for AI Skills and Bundles with concrete actions listed. However, it lacks an explicit 'Use when...' clause and relies on somewhat technical jargon that users may not naturally use when requesting this type of analysis.

Suggestions

Add an explicit 'Use when...' clause, e.g., 'Use when the user asks to review, audit, or check the safety of a skill or bundle, or mentions concerns about malicious code, security risks, or untrusted plugins.'

Include more natural trigger terms that users would say, such as 'is this safe', 'check for malware', 'review this skill', 'scan for security issues', or 'trust check'.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions: 'non-intrusive static analysis', 'identify malicious patterns', 'data leaks', 'system stability risks', 'obfuscated payloads'. Also specifies the target domain ('AI Skills and Bundles') and platforms covered.

3 / 3

Completeness

Clearly answers 'what does this do' (performs static analysis to identify various security risks), but lacks an explicit 'Use when...' clause. The 'when' is only implied by the nature of the skill. Per rubric guidelines, a missing 'Use when...' clause caps completeness at 2.

2 / 3

Trigger Term Quality

Includes some relevant terms like 'security audit', 'malicious patterns', 'data leaks', 'static analysis', but uses more technical/professional jargon. Missing natural user phrases like 'is this skill safe', 'check for malware', 'review this plugin', or 'scan for threats'. A user might not naturally say 'obfuscated payloads'.

2 / 3

Distinctiveness Conflict Risk

Very distinct niche: security auditing specifically for 'AI Skills and Bundles' with static analysis focus. This is unlikely to conflict with general code review, testing, or other security-adjacent skills due to its narrow and well-defined scope.

3 / 3

Total

10

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.