CtrlK
BlogDocsLog inGet started
Tessl Logo

competition-supply-chain

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for CI/CD, registry, dependency drift, artifact provenance, image build, release pipeline, and runtime consumer challenges. Use when the user asks to trace dependency drift, registry pulls, malicious packages, build or release tampering, CI execution, artifact signing, or which shipped artifact the runtime actually consumes. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is token-efficient and well-structured with proper progressive disclosure to a real reference file. It is weaker on actionability and workflow clarity, where the guidance remains strategic rather than tactical and lacks explicit verification checkpoints.

Suggestions

Add concrete tactical commands or tooling examples (e.g., comparing artifact hashes, inspecting lockfiles, listing image layers) so the analysis steps are executable rather than purely strategic.

Include a worked mini-example of tracing one divergence from source to runtime consumer to anchor the abstract workflow.

Add an explicit verification checkpoint before reporting (e.g., confirm the runtime consumer actually consumes the suspect artifact before naming the break point).

DimensionReasoningScore

Conciseness

Lean body that assumes Claude's competence — it never explains what CI/CD, registries, or provenance are, and every line (Quick Start, Workflow, What To Preserve) earns its place.

3 / 3

Actionability

Gives concrete investigative framing ("Compare declared version, resolved version, and shipped artifact") but stays at the strategic level without tactical commands, tooling, or worked examples that would make it copy-paste ready.

2 / 3

Workflow Clarity

A clear 5-step Quick Start and 3-phase workflow (trace → reconcile → report) provide good sequencing, but there are no explicit validation checkpoints or verification steps before reporting conclusions.

2 / 3

Progressive Disclosure

Well-organized overview with a single clearly signaled one-level-deep reference ("Load `references/supply-chain.md` for the provenance checklist..."), and that file exists and holds the detail appropriately split out.

3 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, complete (both what and when), and clearly scoped as a downstream specialization with an explicit routing guard. It avoids fluff and over-claims.

DimensionReasoningScore

Specificity

Lists multiple concrete actions and challenge domains ("trace dependency drift, registry pulls, malicious packages, build or release tampering, CI execution, artifact signing") rather than vague language.

3 / 3

Completeness

Explicitly answers both what ("CTF-sandbox workflow for CI/CD, registry, dependency drift, artifact provenance...") and when ("Use when the user asks to trace...") with an explicit trigger clause.

3 / 3

Trigger Term Quality

The "Use when the user asks to trace dependency drift, registry pulls, malicious packages, build or release tampering, CI execution, artifact signing" clause gives natural keywords a CTF user would actually say.

3 / 3

Distinctiveness Conflict Risk

Clear supply-chain niche with distinct triggers and an explicit guard ("Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions"), making conflict with other skills unlikely.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.