CtrlK
BlogDocsLog inGet started
Tessl Logo

email-security

Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/email-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is concise and well-structured with proper progressive disclosure to a real reference file, but the workflow and tool guidance stay at the task-outline level without executable commands or explicit validation feedback loops.

Suggestions

Add concrete executable commands to the tool table (e.g., 'dig TXT example.com' / 'nslookup -type=txt' and a urlscan.io invocation) instead of tool names alone.

Insert an explicit validation checkpoint in the workflow (e.g., 'verify Received-chain integrity before proceeding to auth alignment') with a fix-and-retry loop.

Expand the self-check into inline pass/fail gates tied to each workflow step rather than a single end-of-task list.

DimensionReasoningScore

Conciseness

The body is lean — short checklists, a compact tool table, and a one-line routing context — with no padding or explanations of concepts Claude already knows; nearly every token earns its place.

3 / 3

Actionability

It names concrete checks ('完整原始头', 'SPF/DKIM/DMARC 对齐结果') and tools (dig/nslookup, urlscan) but stops short of executable commands or specific syntax, leaving the operator to fill in details.

2 / 3

Workflow Clarity

The 'ACT' arrow ('头认证 → 内容/URL → 附件沙箱 → 租户控制面建议') gives a clear sequence and a closing self-check exists, but validation checkpoints are implicit and there is no validate→fix→retry feedback loop.

2 / 3

Progressive Disclosure

The body is well-organized into labeled sections and points to a real, one-level-deep reference (references/email-auth-checklist.md) under a clearly signaled 参考 section, with sibling-skill routing hints kept separate.

3 / 3

Total

10

/

12

Passed

Description

72%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description targets a clear, distinctive niche with strong natural trigger terms, but it relies on a single 'Use for' clause that omits an explicit user-trigger 'when' and uses imperative rather than third-person voice for the capability statement.

Suggestions

Lead with a third-person capability statement (e.g., 'Analyzes email security samples and tenant configurations...') before the 'Use when' clause.

Add an explicit trigger clause such as 'Use when the user asks to analyze phishing emails, review SPF/DKIM/DMARC, or investigate BEC or mailbox token abuse.'

Convert the activity noun phrases into verb-led actions ('analyze phishing samples', 'evaluate SPF/DKIM/DMARC alignment') to sharpen specificity.

DimensionReasoningScore

Specificity

The description lists concrete sub-areas ('phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research') but presents them as activity noun phrases rather than verb-driven actions, and opens with the imperative 'Use for' instead of a third-person capability statement.

2 / 3

Completeness

It states the purpose and activities ('authorized email security review including...') but combines what and when into a single 'Use for' clause without an explicit 'Use when the user mentions...' trigger, so the when-guidance is only implied.

2 / 3

Trigger Term Quality

It covers natural terms a user would say for this domain — 'email security', 'phishing', 'SPF/DKIM/DMARC', and 'BEC' — giving good coverage of likely trigger phrasing.

3 / 3

Distinctiveness Conflict Risk

The 'authorized email security review' niche with specific markers (SPF/DKIM/DMARC, BEC, mailbox token abuse) is clearly bounded and unlikely to trigger for unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.