CtrlK
BlogDocsLog inGet started
Tessl Logo

validate-selector

Audit a Sim dynamic selector across its declaration, browser-safe manifest, server attachment, provider primitive, and selectors.execute security boundary. Use when reviewing selector correctness, secret handling, scope authorization, or migration completeness.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, well-structured audit checklist that assumes competence and gives concrete files, an ordered security boundary, and runnable validation commands. Its main weakness is that some inline detail could be factored into a reference file and the validate->fix->retry loop is only implicit.

Suggestions

Move the detailed plaintext/egress rules and the cache-exception rules into a one-level-deep reference file (e.g. references/security-boundary.md) and link to it from the server-boundary section to tighten the SKILL.md overview.

Add an explicit feedback loop after the validation command block (e.g. 'If any check fails, fix the underlying issue and re-run the failing suite before reporting') to strengthen workflow_clarity.

Convert the declaration/manifest checks that are phrased as criteria ('Allowed context is minimal', 'readiness matches the provider request') into a quick runnable verification where possible, or label them explicitly as review criteria, to push actionability toward fully executable.

DimensionReasoningScore

Conciseness

Lean and free of concept-explanation padding, with every clause carrying a distinct rule; not a 5 because the long prose paragraph on plaintext/egress is dense and could be tightened or split into a list.

4 / 5

Actionability

Concrete file paths (manifest.ts, types.ts, context.ts, registry.ts) and a copy-paste bash validation block make it mostly executable; not a 5 because several declaration/manifest checks are criteria to judge rather than runnable commands.

4 / 5

Workflow Clarity

Clear phased sequence (gather path -> declaration/manifest -> server boundary -> provider reuse -> tests/report) with an explicit 7-step ordered boundary and a validation command block; not a 5 because an explicit validate->fix->retry feedback loop is only weakly present, though the skill is a read-only audit so the destructive cap does not apply.

4 / 5

Progressive Disclosure

Well-organized into clear section headers with no nested references and no bundle files to misroute; not a 5 because at ~100 lines some detailed security rules (e.g., the egress/plaintext paragraph, the cache-exception rules) could be pulled into a one-level-deep reference file.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states the audit scope and gives explicit, natural trigger guidance. It distinguishes itself well from generic skills and answers both what and when.

DimensionReasoningScore

Specificity

Names the domain ('Sim dynamic selector') and five concrete audit surfaces (declaration, browser-safe manifest, server attachment, provider primitive, selectors.execute security boundary); not a 5 because the single verb 'Audit' governs all surfaces rather than enumerating multiple distinct actions.

4 / 5

Completeness

Explicitly answers both what (audit a selector across its five named surfaces) and when (concrete 'Use when reviewing...' triggers), matching the top anchor.

5 / 5

Trigger Term Quality

The 'Use when' clause supplies four natural trigger phrases a reviewer would say ('reviewing selector correctness', 'secret handling', 'scope authorization', 'migration completeness'); not a 5 because common synonyms/extensions are not exhaustively covered.

4 / 5

Distinctiveness Conflict Risk

A highly specific niche ('Sim dynamic selector', 'selectors.execute security boundary') with distinct, domain-locked triggers and minimal overlap with other skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
simstudioai/sim
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.