CtrlK
BlogDocsLog inGet started
Tessl Logo

healthcheck

Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).

89

2.11x
Quality

85%

Does it follow best practices?

Impact

95%

2.11x

Average score across 3 eval scenarios

SecuritybySnyk

Medium

Suggest reviewing before use

The canonical home for this skill is healthcheck in Hung-Reo/hungreo-openclaw

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actionable hardening workflow with concrete commands, explicit validation checkpoints, and strong safety gates. The main gaps are a Windows command-coverage hole, repeated phrasing that could be trimmed, and length that could benefit from offloading some sections into reference files.

Suggestions

Add Windows-specific read-only check commands (e.g., for firewall, listening ports, update status) to match the macOS/Linux coverage, since Windows is listed as a supported OS in step 1.

Deduplicate the model-self-check guidance between the 'Core rules' section and step 0, and consolidate repeated 'read-only' phrasing to tighten the token budget.

Move the detailed cron-scheduling specifics, memory-write format, and command-accuracy lists into reference files (e.g., CRON.md, MEMORY.md guidance) so SKILL.md reads as a leaner overview with one-level-deep pointers.

DimensionReasoningScore

Conciseness

Mostly lean with concrete commands and no padding of concepts Claude already knows, but the model-self-check guidance and "read-only" phrasing are repeated across sections and could be tightened.

4 / 5

Actionability

Provides exact OS-specific commands, precise openclaw flags, cron job names, and numbered profiles/options, but lacks Windows-specific commands despite listing Windows as a possible OS, and the risk-profile step is more descriptive than executable.

4 / 5

Workflow Clarity

Clear 0–8 numbered sequence with validation checkpoints (stop-on-unexpected output, verify-and-report step, required-confirmations checklist, show-plan-before-changes), though rollback is described as a strategy without per-step concrete recovery commands.

4 / 5

Progressive Disclosure

Well-organized with clear section headers and no nested references, but the ~240-line body inlines content (cron scheduling specifics, memory-write format, command-accuracy list) that could be split into reference files for a cleaner overview.

4 / 5

Total

16

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong, clearly answering both what the skill does and when to use it with concrete, natural trigger terms and an OpenClaw-specific niche that minimizes conflict risk. The only minor weakness is that capabilities are framed as trigger phrases rather than as performed actions, which keeps specificity just below the top anchor.

DimensionReasoningScore

Specificity

Names the domain ("Host security hardening and risk-tolerance configuration") and several concrete actions (security audits, firewall/SSH/update hardening, exposure review, cron scheduling, version status checks), but they are framed as triggers rather than performed actions, leaving minor coverage gaps.

4 / 5

Completeness

Explicitly answers both what ("Host security hardening and risk-tolerance configuration for OpenClaw deployments") and when ("Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review...") with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage including synonyms ("risk posture", "exposure review") and concrete device types ("laptop, workstation, Pi, VPS") that users would naturally say.

5 / 5

Distinctiveness Conflict Risk

Clearly scoped to OpenClaw deployments with distinct triggers ("OpenClaw cron scheduling", "machine running OpenClaw"), giving it a clear niche with minimal conflict risk against other skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
trpc-group/trpc-agent-go
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.