CtrlK
BlogDocsLog inGet started
Tessl Logo

secure-dependency-health-check

Helps choose secure, healthy open-source packages by evaluating vulnerability status, maintenance health, popularity, community, and security posture. Use this skill when: - Agent needs to import a new dependency - User asks "which package should I use for X?" - User wants to compare packages (A vs B) - User asks "is this package safe?" - User asks for a "secure alternative" to a package - User mentions "dependency health", "package chooser", or "package security"

75

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers highly actionable, well-sequenced guidance with concrete tool usage, templates, and error-recovery loops. Its main weaknesses are a redundant step that repeats the tool-field listing and a progressive-disclosure failure: the existing references/package-evaluation-criteria.md is never surfaced from SKILL.md and its content substantially duplicates the body.

Suggestions

Add a clearly signaled, one-level-deep pointer to the reference, e.g. under Phase 2: '**Detailed evaluation criteria**: See [references/package-evaluation-criteria.md](references/package-evaluation-criteria.md)', so the bundled reference is discoverable.

De-duplicate the body against the reference file: keep the hard disqualifiers in SKILL.md and move the detailed thresholds/tables (dependency-tree risk, update-frequency, popularity metrics) to the reference, replacing them with a pointer.

Delete or merge Step 2.2 ('Review Tool Results') into Step 2.1, since it repeats the same field list without adding new guidance.

DimensionReasoningScore

Conciseness

The body is mostly lean — phase goals, tool field listings, and templates all earn their place — but 'Step 2.2: Review Tool Results' largely repeats the field list already given in Step 2.1, and the Quick Start slightly duplicates the phase overview. This fits anchor 4 ('minor instances of over-explanation that could be trimmed') rather than 5, but is well above anchor 3's 'several unnecessary explanations'.

4 / 5

Actionability

Guidance is fully concrete: it names the exact tool ('snyk_package_health_check'), its arguments (name, version, ecosystem), the returned fields with their possible values, hard disqualifier criteria, and a copy-paste-ready comparison table and warning template. This matches anchor 5's 'copy-paste ready... specific examples cover the common cases', including the no-secure-option and error scenarios.

5 / 5

Workflow Clarity

A clear four-phase sequence with a Quick Start summary, explicit validation checkpoints (the disqualifiers in Step 2.3), and feedback loops for error recovery ('Retry once; if still no data, fall back to manual research'; report partial results with disclaimer). This matches anchor 5; the operations are read-only health checks, so the destructive/batch validation cap does not apply.

5 / 5

Progressive Disclosure

The body is well-sectioned, but the bundle's reference file (references/package-evaluation-criteria.md) is never mentioned or linked anywhere in SKILL.md — a buried reference the agent would only find by listing files. Additionally, evaluation criteria (disqualifiers vs. the reference's Red Flags Checklist, decision thresholds) are duplicated between body and reference. This matches anchor 3 ('references present but not clearly signaled; content that should be separate is inline'); anchor 4 requires references to be 'mostly clear', which an unlinked reference is not.

3 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: it states concrete capabilities in third person, lists comprehensive natural trigger phrases with synonyms, and explicitly covers both what the skill does and when to use it. Distinctiveness is strong with minimal conflict risk against other skills.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete evaluation actions — 'evaluating vulnerability status, maintenance health, popularity, community, and security posture' — giving comprehensive coverage of the package-selection domain. It exceeds anchor 4 because no meaningful evaluation dimension is missing, and is far above anchor 3's '1-2 concrete actions'.

5 / 5

Completeness

It explicitly answers both what ('Helps choose secure, healthy open-source packages by evaluating...') and when ('Use this skill when:' followed by six concrete trigger conditions). This mirrors anchor 5's example structure exactly; anchor 4 would need a weaker or less explicit 'when' clause, which is not the case here.

5 / 5

Trigger Term Quality

Natural user phrasings are comprehensively covered with synonyms: 'which package should I use for X?', 'is this package safe?', 'secure alternative', 'compare packages (A vs B)', 'dependency health', 'package chooser', 'package security'. It matches anchor 5's requirement for natural terms and synonyms; anchor 4 would require a noticeably missing common phrase, and none is.

5 / 5

Distinctiveness Conflict Risk

It occupies a clear niche (secure open-source package selection) with distinct triggers like 'is this package safe?' and 'package chooser' that few other skills would claim. Anchor 5 fits; anchor 4's 'minor overlap risk with closely related skills' does not apply since the trigger phrasing is specific to dependency/package evaluation.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.