CtrlK
BlogDocsLog inGet started
Tessl Logo

secure-homecore-plugin

Review native registration or external Wasm plugin trust boundaries.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./harness/homecore/.claude/skills/secure-plugin/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is lean, well-sequenced, and action-oriented with a concrete verification command and a destructive-operation rejection gate. Its main gap is the absence of an explicit error-recovery loop after verification, which keeps workflow clarity at 4.

Suggestions

Add an explicit feedback loop after step 3, e.g. 'If verify fails, read the report, fix the bounds/signatures/host-capabilities issue, and re-run before proceeding.'

Pin where the 'documented development override' lives (file/section) so step 4 is fully actionable instead of referencing an unlocated document.

Optionally show the expected pass/fail output of `homecore verify` so Claude can recognize a clean result.

DimensionReasoningScore

Conciseness

Five terse, well-chosen steps with no concept padding and no over-explanation; every line earns its place and assumes Claude's competence, matching the 5 anchor.

5 / 5

Actionability

Provides an executable command (homecore verify --profile wasm --repo <checkout>) and concrete review targets, but some steps are directives rather than runnable commands and a few details (e.g. where the development override is documented) are unresolved, fitting the 4 anchor.

4 / 5

Workflow Clarity

A clear numbered sequence with an explicit verification checkpoint (step 3), but it lacks an explicit error-recovery/feedback loop ('if verify fails, do X'), so it sits at 4 rather than 5.

4 / 5

Progressive Disclosure

Under 50 lines, single-purpose, with no need for external references and no bundle files present; the simple-skill exception applies and the single numbered list is well-organized, matching the 5 anchor.

5 / 5

Total

18

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and names a clear, distinctive domain, but it lacks an explicit 'when to use' trigger clause and broad natural keyword coverage. Adding a 'Use when...' sentence with natural trigger phrases would lift completeness and trigger-term quality.

Suggestions

Add an explicit 'Use when...' clause, e.g. 'Use when reviewing a Homecore plugin's registration, trust boundary, or Wasm package before granting it authority.'

Include natural trigger phrases and synonyms users would say, such as 'plugin review', 'Wasm plugin security', 'plugin signature verification', or 'homecore plugin'.

Spell out one or two more concrete review actions (e.g. 'Verify signatures, check host capabilities, and run homecore verify') to raise specificity.

DimensionReasoningScore

Specificity

Names the domain (native registration, external Wasm plugin trust boundaries) with a concrete review action, but does not enumerate several specific actions, so it stops at the 3 anchor.

3 / 5

Completeness

The 'what' is clear (review trust boundaries of native or external Wasm plugins), but there is no 'Use when...' or equivalent explicit 'when' guidance, which caps completeness at 3 per the guidelines.

3 / 5

Trigger Term Quality

Relevant domain terms like 'Wasm plugin', 'native registration', and 'trust boundaries' appear, but common natural variations or synonyms a user might say are missing, matching the 3 anchor.

3 / 5

Distinctiveness Conflict Risk

It targets a distinct niche (Homecore plugin trust-boundary review) with low overlap risk, but the trigger phrasing is not as comprehensive as the 5 anchor, so 4 fits best.

4 / 5

Total

13

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ruvnet/RuView
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.