CtrlK
BlogDocsLog inGet started
Tessl Logo

audit-skills

Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/audit-skills/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body's core value — a dense, concrete, cross-platform catalog of malicious patterns — is strong and specific, but it is undermined by template debris, verbatim duplication of the description, and a thin three-step workflow with no validation checkpoints or scoring criteria. Tightening the boilerplate sections and defining how findings produce the 0-10 report score would make it substantially more executable.

Suggestions

Delete the leftover template artifact ("2-4 sentences is perfect.") and replace the verbatim Overview/Best Practices/Common Pitfalls duplication with a single concise summary.

Define validation for the reporting step: explicit criteria mapping flagged patterns to the 0-10 score, and what to do when a finding is ambiguous (e.g., check context, flag as informational).

Add executable scan guidance, such as example grep patterns or the specific file types/paths to inspect in a bundle, so the analysis procedure is concrete rather than implied.

DimensionReasoningScore

Conciseness

The 9-category threat catalog earns its tokens with dense, specific patterns, but the Overview restates the description verbatim, line 18 contains a leaked template artifact ("2-4 sentences is perfect."), and Best Practices / Common Pitfalls restate the same three points twice. This matches "mostly efficient but includes some unnecessary explanation or could be tightened" rather than the minor-trim level of 4.

3 / 5

Actionability

Concrete, grep-able detection targets appear throughout (`sudo`, `icacls`, `schtasks`, `chmod 000`, `atob()`, `AndroidManifest.xml`, `Invoke-WebRequest`), giving Claude specific things to search for. It falls short of 5 because there are no executable scan commands, no procedure for which files to inspect, and no criteria for the "score (0-10)" the reporting step promises; it stays above 3 because the pattern lists are real and directly usable.

4 / 5

Workflow Clarity

"Step 1: Static Analysis → Step 2: Platform-Specific Threat Detection → Step 3: Reporting" provides a sequence, but the steps are shallow (Step 1 has no procedure) and there are no validation checkpoints or feedback loops (e.g., how findings map to the 0-10 score, or what to do on ambiguous results). The destructive/batch cap does not apply since the audit is read-only, but anchor 3 ("sequence present but checkpoints missing or implicit") is the best fit.

3 / 5

Progressive Disclosure

The single-file body (~120 lines) is well organized with clear section headers, numbered threat categories, and no nested references. It is not a 5 because the >50-line threat catalog could plausibly live in a references/ file, and the template artifact and duplicated sections are minor organization gaps; it is comfortably above 3 since structure and navigation are genuinely good.

4 / 5

Total

14

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and technically substantive with a clear niche, but it omits any "Use when..." trigger guidance, which caps completeness and weakens discoverability. Adding an explicit when-to-use clause with natural user phrasings (audit, scan, check if a skill is safe/malicious) would lift it substantially.

Suggestions

Append an explicit trigger clause, e.g. "Use when the user asks to audit, scan, or review an AI skill or bundle for safety, malicious code, or data leaks."

Include natural user phrasings and synonyms ("scan", "is this skill safe", "check for malware") so the description matches how users actually phrase audit requests.

Briefly mention the reporting output (score, flagged actions, mitigation recommendations) so the "what" covers the full capability.

DimensionReasoningScore

Specificity

"Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads" lists several concrete, third-person actions with explicit platform scope. It falls short of the 5 anchor because capabilities like reporting, scoring, and mitigation recommendations are not mentioned in the description.

4 / 5

Completeness

The "what" is clearly answered with concrete actions, but there is no "Use when..." clause or any explicit trigger guidance, even weakly implied. Per the judging guideline, a missing 'Use when' clause caps completeness at 3; it is not a 2 because the "what" half is concrete and specific.

3 / 5

Trigger Term Quality

Natural terms like "security auditor", "malicious patterns", "data leaks", and "AI Skills and Bundles" give good keyword coverage. Common user phrasings ("scan", "is this skill safe", "check for malware", "security review") are missing, and terms like "obfuscated payloads" and "system stability risks" lean technical, placing it between the 3 and 4 anchors but noticeably above the midpoint.

4 / 5

Distinctiveness Conflict Risk

"Expert security auditor for AI Skills and Bundles" carves a clear niche with mostly distinct triggers. It is not a 5 because the skill body itself references a related `@security-scanner` skill, and generic requests like "security review" could overlap with general security-analysis skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.