CtrlK
BlogDocsLog inGet started
Tessl Logo

supply-chain-security

Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/supply-chain-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, actionable supply-chain skill body with strong executable commands and sensible reference split. Its main gap is missing explicit validation/feedback loops in the workflow for risky batch scanning operations.

Suggestions

Add inline validate→fix→retry checkpoints inside the SCA and reachability workflow steps (e.g., 'if scan exits non-zero, triage findings, then re-scan fixed scope') rather than relying on a single end-of-task self-check.

Signal the two reference files inline beside their related sections (e.g., next to the SBOM/SCA step and the CI/CD step) instead of only in a bottom '## 参考' section.

Trim the conceptual '六层供应链治理框架' framing or move it to a reference so the body stays action-first.

DimensionReasoningScore

Conciseness

Mostly dense and token-efficient with checklist boxes, compact tool tables, and terse bash snippets, but the six-layer framework and a few framing headlines are mild over-explanation that could be trimmed.

4 / 5

Actionability

Copious copy-paste-ready commands ('osv-scanner scan -r . --format json', 'trivy image --severity HIGH,CRITICAL nginx:latest', 'cosign sign --key cosign.key myimage:tag') plus a full Actions workflow cover the common cases.

5 / 5

Workflow Clarity

A clear six-step sequenced workflow exists, but batch/risky scanning operations lack explicit validate→fix→retry feedback loops, and the closing self-check is a generic checklist rather than inline checkpoints.

3 / 5

Progressive Disclosure

Well-organized sections with two real one-level-deep references listed under a '## 参考' section, though references are signaled in a bottom section rather than inline beside each topic and some inlined detail could live in references.

4 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description with explicit trigger guidance and a clear, well-scoped niche. It could move from a topic-coverage framing to concrete action verbs and add user-phrase synonyms to reach the top anchor.

DimensionReasoningScore

Specificity

Enumerates seven concrete sub-domains ('SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability'), but they are framed as coverage topics rather than discrete verb-actions, so it stops short of the comprehensive action-list anchor.

4 / 5

Completeness

Both 'what' (the enumerated coverage scope) and 'when' ('Use for...') are explicit, but the trigger lists scope domains rather than concrete user-phrase triggers like the anchor-5 example.

4 / 5

Trigger Term Quality

Natural technical terms a user would say ('SBOM', 'CI/CD pipelines', 'container images', 'vulnerability reachability') are present with good coverage, though a few synonyms or file extensions are missing.

4 / 5

Distinctiveness Conflict Risk

'software supply-chain security assessment' with SBOM/provenance/reachability is a clear niche with distinct triggers and minimal conflict risk against unrelated skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.