CtrlK
BlogDocsLog inGet started
Tessl Logo

codebase-cleanup-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

45

Quality

48%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/codebase-cleanup-deps-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

42%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is well-sectioned and brief, but its guidance is almost entirely abstract — no concrete tools, commands, or executable steps — and its single reference to a detailed playbook points to a file that does not exist in the bundle. As written, an agent following it would know the intent of a dependency audit but not how to perform one.

Suggestions

Add concrete, executable commands per ecosystem in the Instructions section (e.g., `npm audit --json`, `pip-audit -r requirements.txt`, `osv-scanner --lockfile=package-lock.json`, `npx license-checker --summary`) so the guidance is copy-paste ready instead of 'run vulnerability and license scans'.

Ship the referenced `resources/implementation-playbook.md` (or remove the reference) — the file is cited twice but does not exist in the bundle, breaking progressive disclosure entirely.

Tighten token efficiency: drop the duplicated persona paragraph (it repeats the frontmatter description verbatim), merge the generic Context/Limitations boilerplate into Safety, and add an explicit validation feedback loop (e.g., re-run the scan after each proposed upgrade and verify in staging before recommending rollout).

DimensionReasoningScore

Conciseness

The body is short and bulleted rather than padded, but it contains avoidable redundancy: the frontmatter description is repeated verbatim as the opening paragraph, the 'Context' section restates the description ('The user needs comprehensive dependency analysis...'), and the 'Limitations' section is generic boilerplate ('Do not treat the output as a substitute for... expert review'). This fits anchor 3 ('mostly efficient but includes some unnecessary explanation or could be tightened') rather than anchor 4, where only minor trimming would be needed.

3 / 5

Actionability

Every instruction is a high-level hint with no executable specifics: 'Run vulnerability and license scans', 'Inventory direct and transitive dependencies', 'Propose upgrades with compatibility notes' — no tool names, commands, or per-ecosystem guidance (e.g., npm audit, pip-audit, osv-scanner, license-checker). The only concrete pointer, 'open resources/implementation-playbook.md', targets a file that does not exist anywhere in the skill bundle, so the promised 'detailed tooling and templates' are unavailable. This matches anchor 2 ('minimal concrete guidance; high-level hints but missing the specific steps to execute') — not anchor 1 only because the instruction list does convey a coherent approach.

2 / 5

Workflow Clarity

Instructions give a recognizable sequence (inventory → scan → prioritize → propose upgrades) and Safety gestures at validation ('Verify upgrades in staging before production rollout'), but there are no explicit checkpoints or error-recovery loops — no verify-fix-retry step for the batch-style operation of upgrading dependencies. This matches anchor 3 ('steps listed but validation gaps; checkpoints missing or implicit'); the partial staging note keeps it above anchor 2, and the missing feedback loop keeps it below anchor 4.

3 / 5

Progressive Disclosure

The body has clean section structure and a clearly signaled one-level reference ('resources/implementation-playbook.md for detailed tooling and templates'), but the referenced file is absent from the bundle — no resources/, references/, scripts/, or assets/ directories exist — so the disclosure chain is broken and the skill's substantive detail is a dangling pointer. This fits anchor 3 ('some structure but could be better organized; references present but not [functional]') rather than 4, since a missing referenced file is a worse navigation failure than a minor organization gap.

3 / 5

Total

11

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a clear niche and a reasonably specific set of capabilities, but it is written in second person with persona boilerplate, lacks any 'Use when...' trigger clause, and misses natural trigger phrasing users would say. It reads more like a system-prompt persona than a skill description optimized for routing.

Suggestions

Rewrite in third-person imperative voice (e.g., 'Audits project dependencies for known vulnerabilities...') and drop the 'You are a dependency security expert' persona sentence, which the rubric penalizes and which adds no routing information.

Append an explicit trigger clause, e.g., 'Use when the user asks to audit dependencies, check for CVEs or vulnerable packages, review license compliance, or upgrade outdated packages in manifests like package-lock.json, requirements.txt, or Cargo.lock.'

Include natural synonyms and ecosystem terms users actually say — 'dependency audit', 'npm audit', 'CVE', 'lock file', 'supply chain attack' — to improve trigger-term coverage from anchor 3 to anchor 5.

DimensionReasoningScore

Specificity

The description lists several concrete actions — 'vulnerability scanning, license compliance, and supply chain security' and 'analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies' — which would rate a 4 ('several specific actions; minor gaps'), but it opens in second person ('You are a dependency security expert specializing in...'), which the judging guidelines penalize by reducing specificity by 1. It also repeats 'vulnerability' and 'license' framing across both sentences rather than broadening coverage.

3 / 5

Completeness

The 'what' is clear (analyze dependencies for vulnerabilities, licensing issues, outdated packages, remediation), but there is no 'Use when...' clause or equivalent explicit trigger guidance — the guidelines state a missing 'Use when' caps completeness at 3, matching anchor 3 ('clear what but when is missing or only weakly implied'). Not anchor 4, which requires both what and when.

3 / 5

Trigger Term Quality

Terms like 'vulnerability', 'license compliance', 'outdated packages', and 'supply chain security' are relevant, but common natural variations users would actually say — 'audit dependencies', 'CVE', 'lock file', ecosystem names like npm/pip/cargo — are missing. This matches anchor 3 ('some relevant keywords but missing common variations or synonyms') rather than anchor 4's 'good keyword coverage'.

3 / 5

Distinctiveness Conflict Risk

The dependency-audit niche ('vulnerability scanning, license compliance, and supply chain security') is mostly distinct with only minor overlap risk against closely related skills like general code review or security review. Not 5, because without explicit trigger phrases the boundary against broader 'security analysis' skills is less sharply drawn.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.