CtrlK
BlogDocsLog inGet started
Tessl Logo

cull

Scanning and eradicating supply-chain malware (Shai-Hulud/S1ngularity npm/PyPI worms): IoC scan, OS/IDE persistence, safe credential rotation. Not for SAST (Sentinel) or skill/MCP audit (Chain).

63

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.archive/cull/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

73%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, highly actionable security skill with an explicit phased workflow and validation gating appropriate to destructive operations. Its main weaknesses are redundancy (a duplicated capabilities summary and repeated rule restatements) and reference files that are cited but not bundled.

Suggestions

Remove or trim the CAPABILITIES_SUMMARY/COLLABORATION_PATTERNS HTML comment, which restates content already present in the body sections.

Consolidate the persistence-first-eradication rule to a single authoritative statement plus brief cross-references rather than restating it verbatim in Core Contract, Always, Never, and Workflow.

Either bundle the referenced reference/*.md and _common/*.md files or note explicitly that they live in a shared skill system, so progressive-disclosure navigation resolves to real files.

DimensionReasoningScore

Conciseness

Dense and assumes Claude's competence without explaining basics, but the CAPABILITIES_SUMMARY HTML comment largely duplicates the body and the persistence-first rule is restated ~5 times across Core Contract, Always, Never, and Workflow sections — tightening room beyond minor.

3 / 5

Actionability

Concrete executable commands appear throughout ('launchctl unload', 'systemctl --user stop', 'git log --diff-filter=A --name-only', 'scan --verify-clean', 'npm ci --ignore-scripts') with exact IoC strings and paths, though the bulk of hashes and tables is deferred to reference files.

4 / 5

Workflow Clarity

A clear six-phase sequence (SURVEY → SCAN → TRIAGE → ERADICATE → ROTATE → REPORT) with a purpose/action/read table, plus explicit validation (verify-clean second scan, eradication-gated rotation) and checklists (Always/Ask First/Never) for destructive operations.

5 / 5

Progressive Disclosure

A clear Reference Map gives one-level-deep, well-signaled navigation with 'Read this when' guidance, but the referenced reference/*.md and _common/*.md files are not present in the bundle and the inlined Critical Patterns quick-reference duplicates detail nominally held in ioc-database.md.

4 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, distinctive, and well-routed, but it lacks an explicit positive 'Use when...' trigger clause, relying on negative routing instead. Adding a concrete positive trigger phrase would lift completeness.

Suggestions

Add an explicit positive 'Use when...' clause naming the triggering situations (e.g. 'Use when a developer environment may have been hit by a named npm/PyPI worm campaign').

Include a couple of natural synonyms such as 'compromised package' or 'malicious dependency' to broaden trigger coverage.

Surface 'eradication runbook' as an explicit action alongside scan and rotation since it is a primary capability.

DimensionReasoningScore

Specificity

Names the domain and multiple concrete actions — 'IoC scan', 'OS/IDE persistence', 'safe credential rotation', 'Scanning and eradicating supply-chain malware' — covering the skill's core pillars comprehensively in one line.

5 / 5

Completeness

The 'what' is clear and concrete, but there is no explicit positive 'Use when...' trigger clause — only negative routing ('Not for SAST (Sentinel) or skill/MCP audit (Chain)'), which caps completeness at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

Strong natural terms ('supply-chain malware', 'npm/PyPI worms', 'credential rotation') plus named campaigns (Shai-Hulud, S1ngularity), but a few common synonyms like 'compromised/malicious package' are absent.

4 / 5

Distinctiveness Conflict Risk

A clearly distinct niche (live-environment supply-chain worm scanning with named campaigns) plus explicit routing away from Sentinel and Chain, giving minimal conflict risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
simota/agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.