CtrlK
BlogDocsLog inGet started
Tessl Logo

codebase-cleanup-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

49

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/codebase-cleanup-deps-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

35%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized and reasonably concise, but its instructions are abstract rather than executable, the workflow lacks validation checkpoints, and the single referenced resource file does not exist in the bundle.

Suggestions

Add concrete, executable tooling (e.g., 'npm audit --audit-level=high', 'pip-audit', 'osv-scanner .') instead of abstract directives like 'Run vulnerability and license scans'.

Add explicit validation checkpoints to the workflow (e.g., 'After proposing upgrades, run the test suite; only recommend upgrades that pass').

Either create resources/implementation-playbook.md or remove the reference to it, so the signaled progressive-disclosure path actually resolves.

DimensionReasoningScore

Conciseness

Sections are short and unpadded, but the opening sentence duplicates the frontmatter description verbatim and '$ARGUMENTS' under Requirements is an empty placeholder, so not every token earns its place.

2 / 3

Actionability

Instructions are abstract directives ('Inventory direct and transitive dependencies', 'Run vulnerability and license scans') with no concrete commands, tool names, or executable examples — it describes rather than instructs.

1 / 3

Workflow Clarity

Steps are sequenced (inventory → scan → prioritize → propose upgrades) and the Safety section mentions verifying upgrades in staging, but the main workflow lacks explicit validation checkpoints or fix→retry feedback loops for these batch/risky operations, which caps the score at 2.

2 / 3

Progressive Disclosure

The body signals a one-level-deep reference ('open resources/implementation-playbook.md') which is good structure, but no resources/ directory or bundle file exists, so the referenced path is a broken pointer and navigation fails.

2 / 3

Total

7

/

12

Passed

Description

72%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description names a clear, distinctive niche with good natural trigger terms, but it omits any explicit 'Use when' guidance and uses second-person voice, which caps completeness and lowers specificity.

Suggestions

Add an explicit 'Use when...' clause naming concrete triggers (e.g., 'Use when auditing dependencies for vulnerabilities, checking license compliance, or planning package upgrades').

Rewrite in third person ('Analyzes project dependencies...') instead of second person ('You are... Analyze...') to avoid the specificity penalty.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions ('vulnerability scanning, license compliance, and supply chain security'; 'Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages'), which would be a 3, but the second-person voice ('You are a dependency security expert... Analyze project dependencies') triggers the rubric's -1 specificity penalty.

2 / 3

Completeness

Clearly answers 'what' (vulnerability scanning, license compliance, supply chain security) but has no 'Use when...' clause or equivalent explicit trigger guidance, which the rubric caps at 2.

2 / 3

Trigger Term Quality

Covers natural terms users would actually say — 'dependencies', 'vulnerabilities', 'license compliance', 'outdated packages' — giving good coverage of common phrasings a user would use when requesting this skill.

3 / 3

Distinctiveness Conflict Risk

Targets a clear niche (dependency security auditing) with distinct triggers ('vulnerabilities', 'license compliance', 'supply chain') that are unlikely to collide with other skills.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/antigravity-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.