CtrlK
BlogDocsLog inGet started
Tessl Logo

attack-tree-construction

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-organized instruction skill with a clear sequenced workflow and good scope/safety guidance. The main defect is a broken progressive-disclosure reference: the body points to `resources/implementation-playbook.md` which is not present in the bundle.

Suggestions

Add the missing `resources/implementation-playbook.md` file to the bundle, or change the reference path to match an actual bundle file under references/.

Include one small inline attack-tree example (root node, AND/OR sub-goals, annotated leaf) so the output format is unambiguous without relying on the external file.

Add an explicit validation/review checkpoint (e.g., 'Verify every root-to-leaf path has at least one mitigation or accepted residual risk') before the prioritize step.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — terse bullets with no padding and no explanation of concepts Claude already knows; every line earns its place.

5 / 5

Actionability

Concrete procedural guidance ("Confirm scope, assets, and the attacker goal for the root node", "Decompose into sub-goals with AND/OR structure", "Annotate leaves with cost, skill, time, and detectability") is specific and actionable, though no inline example or template illustrates the output.

4 / 5

Workflow Clarity

A clear sequence runs from scoping through decomposition, annotation, mitigation mapping, to prioritization, with prioritization acting as a review step; minor validation gaps but the skill is analytical rather than destructive so the destructive-cap does not apply.

4 / 5

Progressive Disclosure

Structure is clean and the reference to `resources/implementation-playbook.md` is clearly signaled in both Instructions and Resources, but no bundle directory (references/scripts/assets/resources) exists, so the referenced file is a dangling path and navigation leads nowhere.

3 / 5

Total

16

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, well-structured description that clearly answers both what the skill does and when to use it, with a distinct security niche. Its only weakness is specificity: it names one core action rather than enumerating several concrete capabilities.

DimensionReasoningScore

Specificity

"Build comprehensive attack trees to visualize threat paths" names the domain and one core action (build/visualize), but does not enumerate multiple distinct concrete actions, matching the '1-2 concrete actions' anchor rather than the multi-action 4 or 5.

3 / 5

Completeness

It explicitly states both what ("Build comprehensive attack trees to visualize threat paths") and when ("Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders") with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Natural terms a security user would say appear — "attack trees", "attack scenarios", "defense gaps", "security risks", "stakeholders" — giving good coverage, though a few common synonyms or phrasings are missing.

4 / 5

Distinctiveness Conflict Risk

"Attack tree construction" is a clear, niche security concept with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.