CtrlK
BlogDocsLog inGet started
Tessl Logo

review-public-exposure

Review a change to a public repository for content written for an internal audience, or content a reader outside the company should not have. Use as one lens in a code review run.

69

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a tight, well-structured instruction lens that assumes Claude's intelligence and gives concrete review targets and reporting rules. Its only gap is the absence of an explicit verify-before-report checkpoint in the workflow.

Suggestions

Add an explicit validation checkpoint in the Method, e.g. confirm each candidate finding against the Threshold rules before reporting, to strengthen the workflow feedback loop.

Optionally give one short before/after example of an internal-audience line rewritten for an outside reader, to make the rewrite-fix option more actionable.

DimensionReasoningScore

Conciseness

The body is lean, assumes Claude's competence, and adds only domain-specific framing Claude would not infer; every line earns its place with no padding or basic-concept explanation.

5 / 5

Actionability

It gives concrete, specific guidance — enumerating review surfaces (example values, fixtures, file names) and exact reporting fields — but as an instruction-only review lens it offers no executable code or commands, which is acceptable yet not fully copy-paste ready.

4 / 5

Workflow Clarity

The Method section sequences the review (read every added line, check non-prose surfaces, read a file's reason for existing) with clear scope/threshold boundaries, but it lacks an explicit validation/feedback checkpoint for confirming a flagged item before reporting.

4 / 5

Progressive Disclosure

This is a short, single-purpose skill under 50 lines with no need for external references; it is well-organized into Scope/Method/Threshold/Reporting sections, qualifying for the simple-skill exception.

5 / 5

Total

18

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly states what the skill does and when to use it, with concrete review targets and third-person voice. It is specific and distinct, though trigger-term coverage could be broader with synonyms.

DimensionReasoningScore

Specificity

It names the domain (public repository exposure review) and several concrete actions — flagging internal-audience text, internal references, unreleased/commercial detail, and credentials — but stays at a high level rather than an exhaustive action list.

4 / 5

Completeness

It answers 'what' (review a change for internal-audience or forbidden content) and 'when' explicitly ('Use as one lens in a code review run') with a concrete trigger phrase.

5 / 5

Trigger Term Quality

It includes natural review-lens terms like 'code review run', 'public repository', and 'internal audience' that a user would say, though it lacks synonym breadth and file-type trigger variations.

4 / 5

Distinctiveness Conflict Risk

It carves a clear niche (public-exposure lens) distinct from general review skills, with only minor overlap risk against other security/secret-scanning review skills.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
tesslio/product-plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.