CtrlK
BlogDocsLog inGet started
Tessl Logo

codebase-cleanup-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

25

Quality

16%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-awesome-skills/skills/codebase-cleanup-deps-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

0%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is essentially a high-level abstract outline with no actionable content. It provides no concrete tools, commands, code examples, or specific workflows — everything is vague direction like 'run vulnerability scans' without saying how. The referenced implementation playbook doesn't exist in the bundle, leaving the skill entirely hollow.

Suggestions

Add concrete, executable commands for specific ecosystems (e.g., `npm audit --json`, `pip-audit`, `trivy fs .`, `license-checker`) with example output parsing.

Define a clear multi-step workflow with validation checkpoints, e.g.: 1. Detect package manager → 2. Run specific scan tool → 3. Parse results → 4. Validate proposed upgrades don't break compatibility → 5. Generate report.

Either include the referenced `resources/implementation-playbook.md` in the bundle or inline the essential tooling details directly in the SKILL.md.

Remove boilerplate sections (Context, Use/Do not use, Limitations) that restate obvious information and replace with specific, actionable content like example scan outputs and remediation templates.

DimensionReasoningScore

Conciseness

The content is verbose and padded with information Claude already knows. It repeats the description in the body, includes unnecessary 'Context' and 'Use this skill when/Do not use this skill when' sections that restate obvious things, and the 'Limitations' section contains generic boilerplate advice Claude doesn't need to be told.

1 / 3

Actionability

The instructions are entirely vague and abstract — 'Inventory direct and transitive dependencies', 'Run vulnerability and license scans' — with no concrete commands, tools, code snippets, or executable guidance. There is nothing copy-paste ready or specific enough to act on.

1 / 3

Workflow Clarity

The instructions list high-level steps without clear sequencing, no validation checkpoints, no feedback loops, and no error recovery guidance. For a security audit workflow involving potentially destructive upgrades, this lacks the necessary rigor.

1 / 3

Progressive Disclosure

The skill references `resources/implementation-playbook.md` for detailed tooling and templates, but no bundle files are provided, making this a dead reference. The SKILL.md itself contains no substantive content — it's all deferred to a non-existent file, creating a hollow structure.

1 / 3

Total

4

/

12

Passed

Description

32%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a clear domain (dependency security) and lists several relevant capabilities, but it uses first/second person framing ('You are...') which violates the voice guidelines, and critically lacks any 'Use when...' clause to guide skill selection. The trigger terms are reasonable but not comprehensive enough to cover the natural language users would employ when needing this skill.

Suggestions

Add an explicit 'Use when...' clause with trigger scenarios, e.g., 'Use when the user asks about dependency vulnerabilities, CVEs, npm audit, outdated packages, license compliance, or supply chain security.'

Rewrite in third person voice (e.g., 'Analyzes project dependencies for known vulnerabilities...') instead of the current second person 'You are...' framing.

Include more natural user-facing trigger terms like 'CVE', 'npm audit', 'pip audit', 'SBOM', 'dependabot', 'security advisory', and specific package manager names to improve matching.

DimensionReasoningScore

Specificity

Names the domain (dependency security) and some actions (vulnerability scanning, license compliance, supply chain security, analyze dependencies), but uses broad terms rather than listing multiple concrete discrete actions like 'scan lockfiles', 'check CVE databases', 'generate SBOM'.

2 / 3

Completeness

Describes what it does (analyze dependencies for vulnerabilities, licensing issues, etc.) but completely lacks a 'Use when...' clause or any explicit trigger guidance for when Claude should select this skill. Per rubric guidelines, a missing 'Use when...' clause caps completeness at 2, and the 'when' is entirely absent here, warranting a 1.

1 / 3

Trigger Term Quality

Includes some relevant keywords like 'vulnerability scanning', 'license compliance', 'supply chain security', 'outdated packages', and 'remediation', but misses common user-facing terms like 'npm audit', 'CVE', 'dependabot', 'security advisory', 'package.json', 'lockfile', or specific ecosystem terms users would naturally say.

2 / 3

Distinctiveness Conflict Risk

The focus on dependency security is somewhat specific and distinguishes it from general code review or document skills, but terms like 'vulnerability scanning' and 'security' could overlap with broader security-focused skills. The lack of explicit triggers increases conflict risk.

2 / 3

Total

7

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.