CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/secrets-baseline-manager

Builds and maintains a unified secrets baseline/allowlist across gitleaks (.gitleaksignore + --baseline-path), TruffleHog (--results=verified filter + trufflehog:ignore), and Kingfisher (--baseline-file + --exclude/--skip-* flags); adopts legacy findings without blocking PRs; enforces a waiver lifecycle (expires + approved_by + reason) stored in .secrets-waivers.yaml; prevents baseline rot via quarterly audit + expiry enforcement. Use when onboarding secrets scanning onto a repo that already has historical findings, or when per-scanner ignore configs have drifted out of sync and need consolidating into one governed allowlist.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A high-quality, lean, actionable skill body with concrete commands, a clear sequenced workflow with validation, and properly structured one-level-deep references. Little to improve.

DimensionReasoningScore

Conciseness

Lean decision-surface document that assumes Claude's competence, with no padding or explanation of basic concepts; its length reflects genuine task complexity rather than verbosity.

3 / 3

Actionability

Provides fully executable CLI commands for all three scanners and a copy-paste-ready waiver YAML template with concrete field names, all directly runnable.

3 / 3

Workflow Clarity

Clear numbered sequence (Steps 1-5, with 2a/2b/2c sub-steps) plus explicit validation checkpoints (finding-triage rejects expired/malformed waivers) and an anti-patterns table as error-recovery guidance.

3 / 3

Progressive Disclosure

SKILL.md acts as a concise overview with well-signaled, one-level-deep references to waiver-lifecycle.md and baseline-rot-prevention.md, both of which are real files; content is appropriately split.

3 / 3

Total

12

/

12

Passed

Description

85%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-triggered description that concretely names capabilities across three scanners and gives explicit use-when guidance. Trigger terms are somewhat internal-facing and could surface more common user phrasings.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('Builds and maintains a unified secrets baseline/allowlist', 'adopts legacy findings', 'enforces a waiver lifecycle', 'prevents baseline rot via quarterly audit') with named scanner mechanisms.

3 / 3

Completeness

Explicitly answers both what (unified baseline + waiver lifecycle + rot prevention) and when via a clear 'Use when onboarding... or when... drifted out of sync' clause.

3 / 3

Trigger Term Quality

Has relevant trigger phrasings ('onboarding secrets scanning', 'per-scanner ignore configs have drifted out of sync') but leans technical/internal and misses more common surface-level variations a user might say.

2 / 3

Distinctiveness Conflict Risk

A sharply defined niche (cross-scanner secrets baseline governance across three named tools) that is clearly distinct from the per-scanner scanning skills and unlikely to trigger for the wrong skill.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

15

/

16

Passed

Reviewed

Table of Contents