CtrlK
BlogDocsLog inGet started
Tessl Logo

openclaw-ghsa-maintainer

Maintainer workflow for OpenClaw GitHub Security Advisories (GHSA). Use when Codex needs to inspect, patch, validate, or publish a repo advisory, verify private-fork state, prepare advisory Markdown or JSON payloads safely, handle GHSA API-specific publish constraints, or confirm advisory publish success.

69

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A focused, executable GHSA maintainer workflow with clear sequencing and built-in validation checkpoints plus a footguns section. Minor tightening and replacing placeholder patterns with one fully concrete worked example would push it to the top.

DimensionReasoningScore

Conciseness

Lean, instruction-first prose with executable snippets and almost no concept padding; only a few phrases (e.g., the guardrail bullets) could be tightened further.

4 / 5

Actionability

Provides concrete, copy-pasteable `gh api`, `jq`, and heredoc commands with explicit sequencing rules, though a few snippets are shaped as patterns with placeholders rather than fully executable examples.

4 / 5

Workflow Clarity

Clear sequenced sections (inspect -> verify private fork -> prepare payloads -> PATCH -> publish -> verify success) with explicit validation checkpoints ('PR list must be empty before publish', re-fetch and confirm state=published), matching the top anchor.

5 / 5

Progressive Disclosure

Under 50 lines, single-purpose, with well-organized sections and no bundle files needed; per the simple-skill exception this earns a top score.

5 / 5

Total

18

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-crafted description that clearly states both the capability and the trigger conditions, scoped tightly to GHSA advisory maintenance. Trigger-term naturalness could be broadened with more user-synonyms, but it is otherwise strong.

Suggestions

Add user-facing synonyms (e.g., 'security advisory', 'vulnerability report', 'CVE') so the description triggers on more natural phrasings a user might say.

Consider phrasing triggers in third-person voice consistently; the current 'Use when Codex needs to...' is borderline second-person framing.

DimensionReasoningScore

Specificity

Lists several concrete actions ('inspect, patch, validate, or publish a repo advisory', 'verify private-fork state', 'prepare advisory Markdown or JSON payloads', 'confirm advisory publish success') with only minor gaps in coverage.

4 / 5

Completeness

Explicitly answers 'what' (maintainer workflow for OpenClaw GHSAs) and 'when' (a concrete 'Use when...' clause listing several trigger scenarios), matching the top anchor.

5 / 5

Trigger Term Quality

Includes natural trigger phrases ('Use when Codex needs to...') with relevant keywords (GHSA, advisory, private-fork, publish), though it leans on internal jargon rather than varied synonyms a user would naturally say.

4 / 5

Distinctiveness Conflict Risk

Carves a clear GHSA-only niche with distinct triggers and explicit boundary against release work, with only minor overlap risk with sibling maintainer skills.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
qsimeon/openclaw-engaging
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.