CtrlK
BlogDocsLog inGet started
Tessl Logo

dependency-management-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

53

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/dependency-management-deps-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is reasonably structured and concise but stays at an abstract instruction level: no executable tooling/commands, no explicit validation feedback loops, and a reference to a missing playbook file.

Suggestions

Add concrete executable tooling/commands (e.g. npm audit, pip-audit, osv-scanner, grype) so the guidance is copy-paste ready rather than abstract.

Insert an explicit validate->fix->retry checkpoint (e.g. re-scan after each upgrade and only proceed when no new vulnerabilities surface) given the batch/upgrade nature of the task.

Create the referenced resources/implementation-playbook.md (or remove/correct the dangling reference) so the progressive-disclosure pointer resolves.

DimensionReasoningScore

Conciseness

The body is lean and free of concept over-explanation, but the 'Context' section restates purpose that the Instructions already convey, fitting 'mostly efficient but could be tightened.'

2 / 3

Actionability

It names a concrete action sequence (inventory, scan, prioritize, propose upgrades) but provides no executable commands or named tools, matching 'some concrete guidance but incomplete; missing key details.'

2 / 3

Workflow Clarity

Steps are sequenced but validation checkpoints are only implicit (one safety note about staging), and for batch/upgrade operations the missing validate->fix->retry loop caps clarity at 2.

2 / 3

Progressive Disclosure

Sections are well organized and the playbook reference is clearly signaled at one level deep, but the referenced file resources/implementation-playbook.md does not exist, undermining navigation.

2 / 3

Total

8

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and occupies a clear niche, but it omits an explicit 'Use when...' trigger and lacks some common user-facing terms (CVE, audit), capping completeness and trigger-term quality at 2.

Suggestions

Add an explicit 'Use when...' trigger clause naming natural phrasings users would say, e.g. 'Use when auditing dependencies, checking for CVEs, or scanning for vulnerable/outdated packages.'

Surface common trigger terms like 'CVE', 'npm audit', 'pip-audit', or 'dependabot' to broaden natural keyword coverage.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — vulnerability scanning, license compliance, identifying outdated packages, and remediation strategies — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Clearly states what the skill does but lacks any 'Use when...' or equivalent explicit trigger clause, so per the judging guidelines completeness is capped at 2.

2 / 3

Trigger Term Quality

Contains relevant plain terms like 'vulnerabilities', 'dependencies', and 'packages' but omits common natural phrasings users would say (e.g. 'audit my dependencies', 'check for CVEs'), fitting the 'some relevant keywords but missing common variations' anchor.

2 / 3

Distinctiveness Conflict Risk

The dependency-security / supply-chain niche is distinct and unlikely to conflict with unrelated skills, matching the 'clear niche with distinct triggers' anchor.

3 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.