CtrlK
BlogDocsLog inGet started
Tessl Logo

audit-flow

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/audit-flow/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

60%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, action-dense skill body with genuinely strong sequencing and validation checkpoints, undermined by a broken bundle: the four referenced files it depends on (including the schema.sql the mandatory entry step requires) are missing, and the core safety rule is stated three times. Fixing the bundle and de-duplicating the guardrails would move this to the top band.

Suggestions

Add the missing bundle files (schema.sql, COMMANDS.md, EXAMPLES.md, .gitattributes) or rewrite the Files section and the mandatory Step 1 so no reference points at a file that does not exist — the required 'read schema.sql first' step is currently unexecutable.

Consolidate the three repetitions of the never-destroy-the-DB rule (entry-point preamble, FORBIDDEN ACTIONS table, and DB-First Discipline) into one authoritative section, and remove the duplicated git-setup/csv-export command listings.

Move the detailed SQL snippets, merge-strategy table, and validation severity rules into the referenced COMMANDS.md/EXAMPLES.md files to shrink the ~370-line body toward a navigable overview.

DimensionReasoningScore

Conciseness

The body is mostly dense, well-compressed tables with no explanations of concepts Claude already knows, but the same safety material is repeated three times (the 'MANDATORY ENTRY POINT' preamble, the 'FORBIDDEN ACTIONS' table, and the 'DB-First Discipline' section all restate 'never destroy the existing DB'), and commands like git-setup and csv-export appear twice. This matches 'mostly efficient but includes some ... could be tightened' better than the 2 anchor, since the repetition is deliberate guardrail reinforcement rather than padding of known concepts.

3 / 5

Actionability

Nearly everything is executable: exact bash invocations ('python .claude/skills/audit-flow/scripts/audit.py list'), concrete SQL INSERT examples with column lists, a full command table, and a validate command. It stops short of 5 because the mandated first step 'cat .claude/skills/audit-flow/schema.sql' and the Files-section references (COMMANDS.md, EXAMPLES.md, schema.sql) point at files that are not in the bundle, so the entry workflow cannot be executed as written, and CLI paths assume one fixed install location.

4 / 5

Workflow Clarity

The sequence is clear and well-checkpointed: numbered entry steps, session-start questions, granularity choice, 'Every 5 tuples -> audit.py show', 'Run ... validate <session> before export' with an error/warning table, and a completion checklist — this satisfies the validation requirement for DB/batch operations. It misses 5 because step 1 of the mandated entry workflow (reading schema.sql) references a file absent from the bundle, so the first checkpoint fails before the feedback loops are reached.

4 / 5

Progressive Disclosure

The Files section signals one-level-deep references, but scored against the actual bundle, 4 of the 5 referenced files (COMMANDS.md, EXAMPLES.md, schema.sql, .gitattributes) do not exist — only scripts/audit.py is present. Meanwhile ~370 lines of detailed SQL snippets, merge strategy, and validation rules that the missing COMMANDS.md/EXAMPLES.md were meant to hold are inlined in SKILL.md. This matches 'references are buried/broken and content that should be separate is inline' (2) rather than 3, where references would at least resolve.

2 / 5

Total

13

/

20

Passed

Description

80%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that explicitly answers both what the skill does and when to use it, with concrete technology specifics and an explicit trigger list. Its main weakness is trigger breadth: terms like 'brainstorm', 'debugging', and 'security review' are generic enough to compete with unrelated skills.

DimensionReasoningScore

Specificity

The description names concrete capabilities: 'flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export' — several specific features with concrete technology names. It falls short of the 5 anchor because 'Interactive system flow tracing' is a single composite capability rather than multiple enumerated concrete actions (e.g. it never states what the tool does with findings, exports beyond Mermaid, or the CLI operations).

4 / 5

Completeness

Both halves are explicit and concrete: the 'what' ('Interactive system flow tracing ... with SQLite persistence and Mermaid export') and the 'when' ('Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on ...'). This mirrors the 5-anchor example's structure of capability statement plus explicit trigger guidance.

5 / 5

Trigger Term Quality

'Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review' gives good natural-phrase coverage matching what users would actually say. Not a 5: common synonyms like 'map the flow', 'diagram the auth flow', or 'walk through this bug' are missing, and 'brainstorm' is a natural word but a stretch as a trigger for a DB-backed tracing tool.

4 / 5

Distinctiveness Conflict Risk

The layer keywords (CODE, API, AUTH, DATA, NETWORK) and 'SQLite persistence' carve a recognizable niche, but the trigger list includes broad generic terms — 'brainstorm', 'debugging', 'audit', 'security review' — that overlap with many common skills, so it could fire when a plain debugging or ideation skill is wanted. It is somewhat specific but still carries overlap risk, matching the 3 anchor rather than 4 (where overlap would be limited to closely related skills only).

3 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.