CtrlK
BlogDocsLog inGet started
Tessl Logo

supply-chain-security

Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete tooling and good progressive disclosure to real reference files, but it carries some redundant framing prose and the top-level workflow lacks explicit validation gating between its batch-operations steps.

Suggestions

Remove or shrink the 'ACTION REQUIRED' preamble and the overlapping '适用场景'/'六层供应链治理框架' sections, since they restate scope already covered by the description and workflow, to improve conciseness.

Add explicit validation checkpoints between the top-level workflow steps (e.g., 'only proceed to CI/CD hardening after SBOM/SCA scan passes with no untriaged CRITICAL findings') to lift workflow clarity above 2.

Consolidate the per-tool install snippets scattered across sections into the single '工具链' table to reduce duplication.

DimensionReasoningScore

Conciseness

The body is largely lean checklists and executable commands, but the 'ACTION REQUIRED' process-nagging preamble and the partially overlapping '适用场景'/'六层供应链治理框架' sections add tokens that could be trimmed, matching the 'mostly efficient but could be tightened' anchor.

2 / 3

Actionability

Provides real, copy-paste-ready tool invocations (osv-scanner, trivy, cosign, hadolint) with concrete flags and numeric thresholds (CVSS >= 7.0, lock commit SHA), matching the 'fully executable commands' anchor rather than the pseudocode level.

3 / 3

Workflow Clarity

A clear six-section workflow with one strong validation sub-flow (reachability) and a final self-check exists, but the top-level steps are parallel topic areas without explicit inter-step validation gates for batch/risky operations, capping clarity at 2 per the missing-checkpoint guideline.

2 / 3

Progressive Disclosure

The '## 参考' section signals two real, one-level-deep bundle files (verified to exist with no nested .md references), keeping methodology detail externalized while the overview stays navigable, matching the 'clear overview with well-signaled one-level-deep references' anchor.

3 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly scopes a distinct supply-chain security niche with explicit trigger guidance and the vocabulary practitioners use. It covers what and when without vague fluff or over-claims.

DimensionReasoningScore

Specificity

Enumerates seven concrete capability areas (SBOM, SCA, CI/CD, container images, build integrity, provenance, reachability), matching the 'lists multiple specific concrete actions' anchor rather than the partial 'names domain and some actions' level.

3 / 3

Completeness

Clearly states what the skill does and includes an explicit 'Use for...' trigger clause covering scope, answering both 'what' and 'when' rather than leaving the trigger implied.

3 / 3

Trigger Term Quality

Uses the natural practitioner vocabulary (SBOM, SCA, CI/CD pipelines, container images, dependency provenance, vulnerability reachability) that a user would actually say, exceeding the 'some relevant keywords but missing common variations' level.

3 / 3

Distinctiveness Conflict Risk

The specialized supply-chain security niche with distinct technical triggers is unlikely to overlap with generic security or development skills, matching the 'clear niche with distinct triggers' anchor.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.