CtrlK
BlogDocsLog inGet started
Tessl Logo

attack-tree-construction

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/attack-tree-construction/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is concise and well-structured with a clear use/do-not-use framing and a sensible step sequence. It loses points for lacking inline concrete examples, missing validation checkpoints, and referencing a playbook file that is not actually present in the bundle.

Suggestions

Include a small inline attack-tree example (root goal with one AND and one OR branch plus annotated leaves) so the core guidance is actionable without the external file.

Add an explicit validation checkpoint, e.g., 'Review each branch for completeness and confirm every leaf has cost/skill/time/detectability before prioritizing paths'.

Either create resources/implementation-playbook.md with the promised templates and examples, or remove the reference to avoid a broken navigation link.

DimensionReasoningScore

Conciseness

The body is lean and sectioned with no concept re-explanation or padding (e.g., "Decompose into sub-goals with AND/OR structure"), assuming Claude's competence so that every token earns its place, matching the level-3 anchor.

3 / 3

Actionability

Instructions give specific direction ("Annotate leaves with cost, skill, time, and detectability") but no inline concrete example or template of an attack tree, and the promised detail lives in a referenced file, fitting the level-2 "some concrete guidance but incomplete" anchor rather than copy-paste-ready level 3.

2 / 3

Workflow Clarity

Steps are sequenced (confirm scope, decompose, annotate, map mitigations) but there are no explicit validation checkpoints or feedback loops for the modeling process, matching the level-2 "steps listed but validation gaps" anchor; it is not level 1 because the sequence is clear, and not level 3 because checkpoints are absent.

2 / 3

Progressive Disclosure

Sections are well organized and the reference to resources/implementation-playbook.md is clearly signaled one level deep, but that referenced file does not exist in the bundle (no resources/ directory), so navigation is broken, which pulls an otherwise level-3 structure down to level 2.

2 / 3

Total

9

/

12

Passed

Description

75%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description cleanly answers both what the skill does and when to use it with a distinct, on-niche trigger clause in correct third-person voice. It is held back from a top score only by limited action breadth and incomplete trigger-term variation coverage.

Suggestions

Expand the action list beyond 'build' and 'visualize' to concrete operations like 'decompose goals into AND/OR nodes, annotate leaf costs, and map mitigations' to lift specificity to level 3.

Add common user phrasings such as 'threat modeling', 'attack paths', or 'attack surface analysis' to the Use-when clause to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Quotes "Build comprehensive attack trees to visualize threat paths" name the domain and two concrete actions (build trees, visualize paths), but the action set is not comprehensive and "comprehensive" is mild padding, matching the level-2 anchor rather than the multi-action level-3 example.

2 / 3

Completeness

It states what ("Build comprehensive attack trees to visualize threat paths") and gives an explicit when ("Use when mapping attack scenarios..."), matching the level-3 anchor that requires both an explicit what and an explicit Use-when trigger; it is not level 2 because the when clause is explicit rather than implied.

3 / 3

Trigger Term Quality

Phrases like "mapping attack scenarios, identifying defense gaps, or communicating security risks" are relevant natural terms, but coverage misses common variations a user might say (e.g., threat modeling, attack paths), fitting the level-2 "some relevant keywords but missing common variations" anchor.

2 / 3

Distinctiveness Conflict Risk

The attack-tree / threat-path niche with triggers like "attack scenarios" and "defense gaps" is a clear, distinct domain unlikely to fire for unrelated skills, matching the level-3 "clear niche with distinct triggers" anchor.

3 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.