CtrlK
BlogDocsLog inGet started
Tessl Logo

stride-analysis-patterns

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

44

Quality

45%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/stride-analysis-patterns/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

22%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured but largely generic skeleton: it lacks concrete STRIDE guidance, a real sequenced workflow, and its single reference points to a missing file.

Suggestions

Replace generic Instruction bullets with concrete STRIDE steps, e.g. enumerate the six categories (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) and how to map each to system components.

Add a sequenced workflow with validation checkpoints (e.g., diagram the system → enumerate threats per category → prioritize → propose mitigations → review with stakeholders).

Either create the referenced `resources/implementation-playbook.md` or remove the dead reference so progressive disclosure navigation resolves.

DimensionReasoningScore

Conciseness

The body is short, but generic template lines such as "Apply relevant best practices and validate outcomes" and the tautological "Do not use" bullets add little domain-specific value and could be tightened.

2 / 3

Actionability

Instructions are abstract ("Clarify goals... Apply relevant best practices and validate outcomes") with no concrete STRIDE steps, no mention of the six threat categories, and no executable guidance.

1 / 3

Workflow Clarity

There is no sequenced STRIDE workflow with validation checkpoints; the four generic Instruction bullets describe rather than order a real multi-step threat-modeling process.

1 / 3

Progressive Disclosure

Sections are well organized and the playbook reference is clearly signaled in two places, but `resources/implementation-playbook.md` does not exist, so navigation to the deeper material is broken.

2 / 3

Total

6

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description cleanly answers both what and when with an explicit Use-when trigger, but its action list is narrow and the "system security" trigger leaves some overlap risk with general security skills.

Suggestions

Add more concrete actions beyond "identify threats" (e.g., "classify threats into the six STRIDE categories, map them to system components, and prioritize mitigations").

Include common trigger variations users would say, such as "threat model", "STRIDE analysis", or "security review".

Narrow the broad "analyzing system security" trigger to STRIDE-specific contexts to reduce conflict with general security skills.

DimensionReasoningScore

Specificity

"Apply STRIDE methodology to systematically identify threats" names the domain and one concrete action (threat identification), but does not list multiple specific actions, so it falls short of the comprehensive multi-action anchor.

2 / 3

Completeness

It states both what ("Apply STRIDE methodology to systematically identify threats") and when via an explicit "Use when..." clause, matching the anchor that requires both.

3 / 3

Trigger Term Quality

"analyzing system security, conducting threat modeling sessions, creating security documentation" are natural user phrases, but common variations (e.g. "threat model", "STRIDE analysis", "security review") are missing.

2 / 3

Distinctiveness Conflict Risk

STRIDE and threat modeling carve a niche, but the broad trigger "analyzing system security" could overlap with general security-analysis skills.

2 / 3

Total

9

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.