CtrlK
BlogDocsLog inGet started
Tessl Logo

secure-dependency-health-check

Helps choose secure, healthy open-source packages by evaluating vulnerability status, maintenance health, popularity, community, and security posture. Use this skill when: - Agent needs to import a new dependency - User asks "which package should I use for X?" - User wants to compare packages (A vs B) - User asks "is this package safe?" - User asks for a "secure alternative" to a package - User mentions "dependency health", "package chooser", or "package security"

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-sequenced, actionable instruction-only skill with concrete tool usage, disqualifier checkpoints, and error-recovery paths. Its main weaknesses are minor redundancy (duplicated purpose statement, restating tool-output fields) and a progressive-disclosure gap: the bundled reference file is orphaned, with no pointer from the body.

Suggestions

Add a clearly signaled pointer to the bundled reference, e.g. a line under Phase 2 such as "**Detailed evaluation criteria**: See [references/package-evaluation-criteria.md](references/package-evaluation-criteria.md) for the full scoring rubric", so the 193-line criteria file is discoverable.

Remove the opening paragraph that restates the frontmatter description, and trim the Step 2.1 field-by-field listing to only the fields Step 2.2 actually surfaces for comparison.

Include one worked mini-example of the comparison table (with realistic values for two known packages) so the Phase 3 template is concrete rather than a blank skeleton.

DimensionReasoningScore

Conciseness

The phased body is tight and template-driven with little padding. Minor over-explanation: the opening paragraph restates the frontmatter description almost verbatim, and Step 2.1 enumerates tool-response fields (overall_rating, security, maintenance, ...) that Claude will see directly in the tool output. Anchor 4 rather than 5; not 3 since the bulk is efficient and free of concept explanations Claude already knows.

4 / 5

Actionability

Gives a concrete tool call (snyk_package_health_check with name/version/ecosystem), specific field checks (is_archived, latest_release_published_at), fill-in output templates, and exact error strings with retry/fallback behavior. Anchor 4 rather than 5 because the comparison table and recommendation templates are blank skeletons with no worked example.

4 / 5

Workflow Clarity

Clear sequence (Quick Start → Phases 1–4) with an explicit disqualifier checkpoint list (Step 2.3) and error-recovery feedback loops ("Retry once; if still no data, fall back to manual research and report partial results with a disclaimer"). This is a read-only analysis skill, so the destructive/batch validation cap does not apply; matches anchor 5's explicit validation steps, feedback loops, and checklist.

5 / 5

Progressive Disclosure

The body itself is well-sectioned, but the bundle's references/package-evaluation-criteria.md (193 lines of evaluation criteria) is never mentioned or linked anywhere in the body — a reference that is present but not signaled at all. Anchor 3 (references present but not clearly signaled); not 4 because an entirely unlinked reference file is a real navigation gap for the deeper criteria detail.

3 / 5

Total

16

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly states what the skill does and provides an explicit, well-phrased trigger list. The main gaps are a slightly redundant action list and a few missing natural trigger synonyms.

DimensionReasoningScore

Specificity

Names the domain and several concrete evaluation actions: "evaluating vulnerability status, maintenance health, popularity, community, and security posture". Falls just short of anchor 5 because "security posture" overlaps "vulnerability status" and the action list is evaluation dimensions rather than a fully comprehensive set of capabilities.

4 / 5

Completeness

Explicitly answers both: what ("Helps choose secure, healthy open-source packages by evaluating vulnerability status, maintenance health, popularity, community, and security posture") and when ("Use this skill when:" followed by six concrete trigger bullets). Matches anchor 5 exactly; anchor 4 would require the 'when' to be less explicit.

5 / 5

Trigger Term Quality

Includes natural user phrases like "which package should I use for X?", "is this package safe?", "compare packages (A vs B)", "secure alternative", and "dependency health" — good keyword coverage matching anchor 4. Not anchor 5 because common variations such as "is this package maintained", "abandoned package", or "supply chain risk" are missing.

4 / 5

Distinctiveness Conflict Risk

Clear niche (package selection health/security) with distinct trigger phrasing unlikely to fire for unrelated skills. Minor overlap risk with generic vulnerability-scanning or dependency-audit skills via the phrase "package security", so anchor 4 rather than 5.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.