CtrlK
BlogDocsLog inGet started
Tessl Logo

security-scanning-security-dependencies

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, assess risks, and recommend remediation.

49

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/security-scanning-security-dependencies/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

36%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and reasonably lean, but it offers almost no executable guidance — no concrete tools, commands, or code — and its single external reference points to a file that does not exist. It reads as a template skeleton rather than an operational skill.

Suggestions

Replace the abstract Instructions with concrete, executable steps naming real scanners (e.g., 'Run `osv-scanner --lockfile package-lock.json`', 'Generate SBOM with `syft dir:.` -o spdx-json`).

Either create resources/implementation-playbook.md with the promised patterns or remove the dangling reference from both the Instructions and Resources sections.

Add an explicit validate-then-proceed checkpoint for remediation (e.g., confirm CVE/severity, propose fix, run tests, re-scan) given the Safety note that dependency changes are release-impacting.

DimensionReasoningScore

Conciseness

Mostly efficient with clear sections, but the intro paragraph repeats the frontmatter description verbatim and the time-sensitive 'modern 2024/2025 tools' phrasing adds padding that could be trimmed.

3 / 5

Actionability

The Instructions are high-level abstractions ('Clarify goals', 'Apply relevant best practices', 'Provide actionable steps and verification') with no concrete code, scanner commands, or named tools (e.g., osv-scanner, trivy, syft, grype), and the referenced playbook for details does not exist.

2 / 5

Workflow Clarity

Only a rough, generic sequence is present with poorly defined steps and no validation checkpoints, and since dependency remediation is a batch/release-impacting operation the missing validation keeps it well below the cap of 3.

2 / 5

Progressive Disclosure

The body is short and sectioned and signals a one-level reference to resources/implementation-playbook.md, but no such file or resources/ directory exists, so the reference is a broken navigation link rather than a resolved bundle.

3 / 5

Total

10

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly conveys the skill's concrete capabilities and occupies a distinct niche, but it lacks an explicit 'Use when...' trigger clause and uses second-person voice, which caps completeness and reduces specificity. Adding trigger phrases and converting to third person would lift it into the top band.

Suggestions

Append a 'Use when...' clause naming concrete triggers (e.g., 'Use when auditing dependencies for CVEs, generating SBOMs, or remediating vulnerable/outdated packages').

Rewrite in third person to avoid the specificity penalty (e.g., 'Scans project dependencies... identifies vulnerabilities, assesses risks, and recommends remediation').

Add natural synonyms users actually say — CVEs, packages, lockfiles, npm/pip/cargo — to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Lists several concrete actions (vulnerability analysis, SBOM generation, scan dependencies, identify vulnerabilities, assess risks, recommend remediation) with comprehensive coverage, but the second-person voice ('You are a security expert', 'Scan') triggers the mandated 1-point specificity penalty from a base of 5.

4 / 5

Completeness

The 'what' is clear and concrete, but there is no 'Use when...' clause or equivalent explicit trigger guidance, which per the rubric caps completeness at 3.

3 / 5

Trigger Term Quality

Includes natural keywords users would say (dependencies, vulnerabilities, SBOM, supply chain security) but omits common synonyms and file/extension terms (CVE, packages, lockfile, outdated packages, .lock).

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (dependency vulnerability scanning / SBOM / supply chain security) with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.