CtrlK
BlogDocsLog inGet started
Tessl Logo

security-scan

Resolve npm dependency vulnerabilities detected by security scans.

73

1.25x
Quality

60%

Does it follow best practices?

Impact

97%

1.25x

Average score across 3 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./frontend/.claude/skills/security-scan/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

60%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-sequenced body with concrete explore/verify commands, but its progressive disclosure is broken: the Fix step and Rules section defer to files that are missing from the bundle entirely. The skill reads as an index to a detail layer that does not exist, and the verify block includes a questionable 'bun i --yarn' command with no failure-recovery guidance.

Suggestions

Create the referenced rule files (e.g., rules/vuln-direct-deps.md, rules/vuln-transitive-deps.md) with the concrete fix patterns, or inline those patterns in SKILL.md — as written, the core 'Fix' step has no executable content.

Make reference paths consistent (the Quick Reference table cites bare filenames while the Rules section cites a 'rules/' directory) so navigation is unambiguous.

Verify the 'bun i --yarn' command is correct for the target project and add a feedback loop to the Verify step (e.g., 'if any check fails, fix and re-run before proceeding').

DimensionReasoningScore

Conciseness

The body is lean, assumes Claude's competence, and explains nothing Claude already knows. It is not 5 because the opening line ('Resolve npm dependency vulnerabilities detected by Snyk.io security scans.') largely duplicates the description, and the rules are pointed to three times (Quick Reference table, 'See rules for specific fix patterns', 'See `rules/` directory').

4 / 5

Actionability

Some concrete, executable guidance exists ('npm view <package> versions --json', the verify command block), but the core 'Fix' step contains only 'See rules for specific fix patterns' — and those rule files are absent from the bundle, so the key executable detail is missing. The verify block's 'bun i --yarn' is also a dubious command. Not 2 because Explore and Verify do give specific runnable commands.

3 / 5

Workflow Clarity

The Assess → Explore → Fix → Verify sequence is clearly staged with an explicit validation block ('All must pass'), and Explore's inputs are well enumerated. It is not 5 because there is no error-recovery feedback loop — what to do when type:check/lint/build/test fails is left implicit.

4 / 5

Progressive Disclosure

The structure is well intended (Quick Reference table mapping fix types to one-level-deep rule files), but the referenced files ('vuln-direct-deps.md', 'vuln-transitive-deps.md', the 'rules/' directory) do not exist anywhere in the bundle, leaving navigation dangling and the skill's core detail layer absent. Path references are also inconsistent (bare filenames vs. 'rules/ directory').

2 / 5

Total

13

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, adequately specific description with a clear 'what' but no 'when' trigger clause. It identifies the npm vulnerability-remediation niche well but omits the natural trigger terms (CVE, npm audit, Snyk) users most likely say and any 'Use when...' guidance.

Suggestions

Add an explicit trigger clause, e.g., 'Use when the user shares a Snyk or npm audit report, mentions CVEs/CWEs, or asks to fix security issues in npm dependencies.'

Include natural synonyms users actually say — CVE, npm audit, Snyk — to improve trigger term coverage.

Name the concrete remediation actions (e.g., upgrade direct deps, pin/override transitive deps) rather than the single generic verb 'Resolve'.

DimensionReasoningScore

Specificity

Names the domain ('npm dependency vulnerabilities', 'security scans') with one concrete action ('Resolve'), matching the 1-2-concrete-actions anchor. It is not 4 because no remediation actions (upgrade, pin, override) are enumerated, and not 2 because the domain is specific rather than generic.

3 / 5

Completeness

Has a clear 'what' ('Resolve npm dependency vulnerabilities detected by security scans') but no 'Use when...' clause or equivalent trigger guidance, which caps completeness at 3 per the judging guidelines. Not 2 because the 'what' is clear, not 4 because 'when' is entirely absent rather than merely implicit.

3 / 5

Trigger Term Quality

'npm', 'dependency', 'vulnerabilities', and 'security scans' are natural terms users would say, giving good keyword coverage. It is not 5 because common synonyms and trigger phrases users actually use — 'CVE', 'npm audit', 'Snyk' — are missing.

4 / 5

Distinctiveness Conflict Risk

The npm-security-remediation niche is mostly distinct from other skills with only minor overlap risk with general dependency-update or security-audit skills. Not 5 because 'security scans' is generic and the description does not name a specific scanner (e.g., Snyk) that would make the niche fully distinct.

4 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
redpanda-data/console
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.