CtrlK
BlogDocsLog inGet started
Tessl Logo

supercov-security

Scans a repository's source for security vulnerabilities with the supercov CLI, pointing to the line of each finding and mapping it to CWE classes. Use when the user asks for a security scan or audit, whether code is secure, or to find vulnerabilities, injection, hardcoded secrets or other insecure code.

80

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-crafted body for a simple skill: exact CLI invocations for whole-repo and diff-scoped scans, a versioned-docs pointer, and an explicit missing-key fallback that includes telling the user the scan did not run. Nothing is over-explained and nothing essential is missing.

DimensionReasoningScore

Conciseness

The body is lean — every sentence delivers a command, a fact about tool behavior, or an instruction (e.g. "Run `npx supercov security`... `npx supercov docs security` prints the guide for the installed version"). No concept Claude already knows is explained, and there is no padding; every token earns its place.

5 / 5

Actionability

Commands are copy-paste ready and cover the common cases: `npx supercov security` (whole repo), `npx supercov security patch` (a change), `npx supercov docs security` (versioned guide), plus the exact `TYPESAFE_API_KEY` variable and a concrete fallback procedure for a missing key. Fully executable with no gaps.

5 / 5

Workflow Clarity

This is a simple single-purpose skill and the primary action is unambiguous, but the body also sequences the conditional path explicitly: "If the key is missing the command says so: tell the user how to set it, then review the code by hand and say Supercov did not check it" — an error-recovery loop with a required disclosure step. Anti-drift check: no missing validation for risky operations; the fallback and honesty requirement are both explicit.

5 / 5

Progressive Disclosure

The skill is under 50 lines with no external references needed, and no bundle files (references/, scripts/, assets/) exist to mis-route. The body is cleanly organized into two focused paragraphs — invocation modes, then data-handling/consent and fallback — which for a skill this size is the appropriate structure.

5 / 5

Total

20

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete third-person capabilities, comprehensive natural trigger terms, and an explicit 'Use when' clause covering both what the skill does and when to invoke it. It reads like the reference good examples with no padding or over-claims.

DimensionReasoningScore

Specificity

The description lists multiple concrete, third-person actions — "Scans a repository's source for security vulnerabilities", "pointing to the line of each finding and mapping it to CWE classes" — with no vague filler. This matches the anchor for multiple specific concrete actions with comprehensive coverage; nothing is generic and there is no gap in what it claims to do.

5 / 5

Completeness

It explicitly answers "what" (line-level findings mapped to CWE classes via the supercov CLI) and "when" via a concrete trigger clause: "Use when the user asks for a security scan or audit, whether code is secure, or to find vulnerabilities...". Both halves are explicit with concrete triggers, matching the top anchor.

5 / 5

Trigger Term Quality

Phrases like "security scan or audit", "whether code is secure", "vulnerabilities, injection, hardcoded secrets or other insecure code" give comprehensive natural-language coverage with synonyms (scan/audit, vulnerabilities/insecure code). This is exactly the kind of wording a user would naturally say; no common synonym is missing.

5 / 5

Distinctiveness Conflict Risk

The security-vulnerability scanning niche (supercov CLI, CWE mapping, injection/hardcoded-secrets triggers) is distinct from general code-review or document skills, and the triggers are unlikely to fire for the wrong skill. Anti-drift check: it is not merely "mostly distinct" with overlap risk (anchor 4) — the trigger vocabulary is specific to security auditing.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
supercorp-ai/supercov
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.