CtrlK
BlogDocsLog inGet started
Tessl Logo

owasp-security-review

Quick-scan security code review against the OWASP Top 10:2025 for React/TypeScript apps using Azure AD (Entra ID) OAuth and deployed as Azure App Service. Reports findings by severity (HIGH / MEDIUM / LOW) with recommended fixes. Use this skill when asked for a security review, OWASP scan, security audit, vulnerability check, or when running /branch-wrapup (it is called automatically as Phase 6).

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured scan procedure: executable grep targets, concrete fixes, an exact output template, and clear sequencing with a caller-facing PASS/FAIL contract. The main improvement opportunities are consolidating version/chatty asides, adding an explicit HIGH-finding verification checkpoint, and moving the per-category pattern tables into reference files.

Suggestions

Add an explicit verification step between Step 2 and Step 4 (e.g., 'Re-confirm each HIGH finding against the source line before declaring FAIL') to sequence the anti-hallucination intent of Rule 1 into the workflow.

Trim conversational asides ("Why this matters", "which is great — but there are escape hatches") and consolidate the scattered "New in 2025" version notes into a single note near the top.

Consider moving the ten per-category check tables into a references/ file (e.g., references/owasp-checks.md) so SKILL.md stays a lean overview of procedure and report format.

DimensionReasoningScore

Conciseness

Dense grep-pattern tables, severity guides, and a copy-paste report template with almost no filler; it assumes Claude's competence throughout. Not 5 because of a few trimmable asides ("Why this matters: the #1 vulnerability", "React's JSX auto-escapes by default, which is great") and scattered "New in 2025" version notes outside any consolidated section.

4 / 5

Actionability

Concrete grep targets per check ("jwt.decode (should be jwt.verify)", "cacheLocation: 'localStorage'", a literal ``SELECT.*\$\{`` pattern), exact fix snippets ("@Microsoft.KeyVault(SecretUri=...)", tenant-specific authority URL), and a fully specified report format. This is copy-paste-ready guidance covering the common cases of the target stack.

5 / 5

Workflow Clarity

Steps 1-5 are clearly sequenced with a per-category checklist, a PASS/FAIL exit contract for callers, an ignore-comment escape hatch, and skip rules with reporting requirements. Not 5 because there is no explicit checkpoint to re-verify HIGH findings before declaring FAIL — Rule 1 ("Don't hallucinate findings") implies it but does not sequence it into the workflow.

4 / 5

Progressive Disclosure

The body is cleanly sectioned (Purpose, When to Use, Composability, per-category checks, Azure config, report format, Rules) with no buried or nested references and no bundle files to navigate. Not 5 because ~200 lines of per-category pattern tables sit fully inline in the always-loaded SKILL.md where a one-level references split could lighten it.

4 / 5

Total

17

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete what-and-when structure with natural trigger terms and a well-defined niche. Its only weaknesses are a slightly thin action inventory and a few missing trigger synonyms alongside generic security terms that could collide with broader security skills.

DimensionReasoningScore

Specificity

Names the domain ("Quick-scan security code review against the OWASP Top 10:2025") and several concrete actions ("Reports findings by severity (HIGH / MEDIUM / LOW) with recommended fixes") scoped to a precise stack. Not 5 because the action list is short of the comprehensive coverage the top anchor shows; not 3 because coverage goes well beyond 1-2 actions.

4 / 5

Completeness

Explicitly answers both: what ("Quick-scan security code review against the OWASP Top 10:2025 ... Reports findings by severity ... with recommended fixes") and when ("Use this skill when asked for a security review, OWASP scan, security audit, vulnerability check, or when running /branch-wrapup"). Matches the anchor-5 pattern with concrete trigger phrases.

5 / 5

Trigger Term Quality

"security review, OWASP scan, security audit, vulnerability check, or when running /branch-wrapup" are natural phrases a user would say, plus a slash command. Not 5 because a few common synonyms are missing (e.g., "vuln scan", "security check", "pen test"); not 3 because coverage of natural terms is good, not partial.

4 / 5

Distinctiveness Conflict Risk

"OWASP", "Azure AD (Entra ID) OAuth", and "Azure App Service" carve a clear niche with distinct triggers. Not 5 because generic phrases like "security review" and "security audit" still overlap with general security-review skills; not 3 because the stack-specific framing makes confusion unlikely.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
0xRabbidfly/Eric-Cartman
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.