CtrlK
BlogDocsLog inGet started
Tessl Logo

threat-hunting

Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

69

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-organized hunting workflow with clear sequencing, validation checkpoints, and proper progressive disclosure. The main gap is that the Sigma/query examples are skeletons rather than copy-paste executable artifacts.

Suggestions

Replace the comment-only Sigma YAML skeleton with a minimal but complete, runnable Sigma rule example to raise actionability to 3.

Provide at least one concrete executable SIEM query snippet (e.g. a Splunk SPL or KQL stub) for the lateral-movement hypothesis instead of describing the query in prose.

The hunting-loop.md reference is very short (one line of phases); consider folding its content inline or expanding it so the reference adds real detail.

DimensionReasoningScore

Conciseness

Lean body that assumes Claude's competence — it does not explain what Sigma, YARA, or a SIEM are, and every section (workflow, tool table, checklist) earns its place.

3 / 3

Actionability

Concrete field mappings and a tool table are provided, but the Sigma block is a comment-only skeleton and the query steps are described rather than given as executable queries, fitting the "some concrete guidance but incomplete / pseudocode" anchor.

2 / 3

Workflow Clarity

A clear sequenced workflow (hypothesis → query → rule-ify → validate) with explicit validation steps (replay historical logs, Atomic Red Team in authorized lab only) and a completion self-check checklist.

3 / 3

Progressive Disclosure

Overview body points to a real one-level-deep reference (references/hunting-loop.md, confirmed to exist) plus clearly signaled cross-skill references, with content appropriately split.

3 / 3

Total

11

/

12

Passed

Description

82%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-targeted description with strong trigger terms and a clear niche. Its main weakness is the implicit rather than explicit "when to use" trigger clause.

Suggestions

Add an explicit trigger clause such as "Use when the user asks for threat hunting, Sigma/YARA rule authoring, SIEM query design, or detection validation" to lift completeness to 3.

Optionally call out common user phrasings (e.g. "write a Sigma rule", "tune this alert", "hunt for lateral movement") to strengthen natural trigger terms further.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities — "blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation" — matching the anchor for several specific concrete actions.

3 / 3

Completeness

Clearly states what the skill does, but the "when" trigger is only implied via "Use for" rather than an explicit "Use when the user mentions..." clause, which caps completeness at 2 per the rubric guideline.

2 / 3

Trigger Term Quality

Natural domain keywords a user would say ("threat hunting", "Sigma", "YARA", "SIEM query", "incident detection validation") are present with good coverage.

3 / 3

Distinctiveness Conflict Risk

A clear blue-team detection-engineering niche with distinct triggers, unlikely to fire for unrelated skills.

3 / 3

Total

11

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.