CtrlK
BlogDocsLog inGet started
Tessl Logo

email-security

Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/email-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly token-efficient with a clean structure and a properly signaled one-level reference file. Its weakness is actionability and workflow rigor: tool names appear without executable syntax, and risky batch email operations lack explicit validation checkpoints beyond a weak closing self-check.

Suggestions

Add concrete executable command examples (e.g., 'dig +short TXT example.com', 'nslookup -type=txt _dmarc.example.com', 'urlscan.io submit <url>') so the tool table is copy-paste ready.

Insert an explicit validation checkpoint before any tenant-control or redelivery-adjacent action (e.g., confirm authorization and that no real-user redelivery will occur before proceeding), rather than relying solely on the closing self-check.

Expand the workflow checklist to tie each step to its verification artifact (e.g., SPF/DKIM/DMARC alignment result, sandbox verdict) so completion is objectively checkable.

DimensionReasoningScore

Conciseness

The body is extremely lean with no over-explanation of concepts Claude already knows; every section (ACTION REQUIRED, workflow checklist, tool table) earns its place. Not below 5 as there is no padding.

5 / 5

Actionability

Provides a checkbox workflow and a tool table ('dig/nslookup', 'urlscan / 沙箱') but no concrete executable commands or syntax; guidance is high-level hints rather than copy-paste ready steps. Not a 4 because key execution details are missing, not a 2 because the structure still points to specific tools.

3 / 5

Workflow Clarity

Sequenced via 'ACTION REQUIRED' and a workflow checklist, with a closing self-check, but for batch/risky email operations validation is only an implicit end-of-task checklist rather than explicit validate-before-proceed checkpoints. Per the batch/destructive cap this cannot exceed 3; not a 2 because a clear sequence does exist.

3 / 5

Progressive Disclosure

Single one-level-deep reference 'references/email-auth-checklist.md' is clearly signaled and verified to exist; body is a concise overview split into well-organized sections. Not below 5 as navigation is easy and structure is appropriate.

5 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, third-person, and clearly pairs a 'Use for...' trigger with concrete email-security capabilities. Trigger terms are strong though a few common synonyms are absent. Overall a well-constructed skill description.

DimensionReasoningScore

Specificity

Quotes 'phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research' list several concrete actions; not a 5 because coverage is broad but not exhaustive of email-security actions.

4 / 5

Completeness

'Use for authorized email security review including...' explicitly states both when to trigger and what it does with concrete trigger phrases; not below 5 since both are clearly and explicitly answered.

5 / 5

Trigger Term Quality

Includes natural terms like 'phishing analysis', 'SPF/DKIM/DMARC', 'BEC', and 'mailbox token abuse'; missing a few common synonyms users might say such as 'suspicious email', so not a 5.

4 / 5

Distinctiveness Conflict Risk

The email-security niche with SPF/DKIM/DMARC and BEC triggers is clearly distinct from other skills with minimal conflict risk; no overlap concerns justify a lower score.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.