CtrlK
BlogDocsLog inGet started
Tessl Logo

secure-dependency-health-check

Helps choose secure, healthy open-source packages by evaluating vulnerability status, maintenance health, popularity, community, and security posture. Use this skill when: - Agent needs to import a new dependency - User asks "which package should I use for X?" - User wants to compare packages (A vs B) - User asks "is this package safe?" - User asks for a "secure alternative" to a package - User mentions "dependency health", "package chooser", or "package security"

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A solid, actionable workflow with clear sequencing and validation gates; its main weaknesses are an un-linked reference file and somewhat verbose example templates.

Suggestions

Link the existing references/package-evaluation-criteria.md from the body (e.g., 'For detailed per-category thresholds and the decision matrix, see [package-evaluation-criteria.md](references/package-evaluation-criteria.md)') so the bundle reference is discoverable.

Compress the full comparison-table and alternative-scenario blocks into compact column schemata with one short worked example to reduce token weight while preserving the template.

Move the detailed per-category rating tables (currently only in the reference) into the referenced file and keep the body focused on the decision flow, tightening the redundancy between Phase 2 and the reference.

DimensionReasoningScore

Conciseness

Largely lean and free of concept-padding, but the full multi-row comparison-table template and the complete 'No Secure Option Available' block add tokens that could be condensed into compact schemata.

2 / 3

Actionability

Concrete, executable guidance: a specific tool call with named arguments, enumerated return fields, explicit disqualifiers, and a copy-paste-ready comparison template.

3 / 3

Workflow Clarity

Phases 1–4 are clearly sequenced with decision gates (Step 2.3 disqualifiers) and feedback loops in Error Handling (retry once, fall back to manual research).

3 / 3

Progressive Disclosure

Section structure is clean, but the bundle file references/package-evaluation-criteria.md is never linked or signaled from the body, leaving detailed criteria undiscoverable.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-crafted description: third-person voice, concrete capabilities, and explicit natural-language triggers covering both what and when. No fluff or over-claims.

DimensionReasoningScore

Specificity

Lists multiple concrete actions: 'evaluating vulnerability status, maintenance health, popularity, community, and security posture' rather than vague language.

3 / 3

Completeness

Clearly answers both what (choose/evaluate secure healthy packages) and when via an explicit 'Use this skill when:' clause with enumerated triggers.

3 / 3

Trigger Term Quality

Strong natural trigger coverage: 'which package should I use for X?', 'is this package safe?', 'secure alternative', 'dependency health', 'package chooser', 'package security' — terms users would actually say.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear package-security/health niche with distinct triggers, unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.