CtrlK
BlogDocsLog inGet started
Tessl Logo

critical-interval-security-checker

Analyzes code to identify security-critical time intervals and timing vulnerabilities in authentication, authorization, and time-sensitive security operations. Use this skill when reviewing code for proper timeout enforcement, token expiration, session management, rate limiting, password reset validity, or any time-sensitive security mechanism. Detects missing expiration checks, excessive timeout values, lack of rate limiting, client-side only validation, hardcoded timeouts, and timing attack vulnerabilities. Triggers when users ask to check security timeouts, verify token expiration handling, audit session timeout implementation, review rate limiting, or analyze time-based security controls.

89

1.17x
Quality

83%

Does it follow best practices?

Impact

99%

1.17x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable body with good/bad and before/after code examples, a clear numbered workflow, and correctly signaled one-level-deep references to real bundle files. Its main weakness is conciseness: some content is duplicated across the workflow, Quick Reference, and Helper Script sections and could be consolidated into the reference files.

Suggestions

Consolidate the duplicated detection-pattern and vulnerability-summary material: keep the workflow tight and move the per-language patterns and standards tables that overlap references/ into those files, linking instead of inlining.

Add an explicit validation checkpoint to the workflow (e.g., 'confirm each finding's severity and exploitability before proposing a fix') to lift workflow clarity toward a formal validate-fix-retry loop.

Trim the redundant 'Helper Script' usage block, which repeats the commands already shown in workflow step 3, or replace it with a one-line pointer to that step.

DimensionReasoningScore

Conciseness

Mostly efficient with genuinely useful good/bad code comparisons, but contains redundancy (the 'Critical Vulnerabilities' Quick Reference and the 'Helper Script' usage repeat content from workflow steps 2-3) and some over-explanation of basic patterns Claude already knows.

3 / 5

Actionability

Provides concrete, mostly copy-paste-ready code (real jwt.decode calls, @limiter.limit, timedelta before/after fixes) and runnable commands (python scripts/check_intervals.py); minor gaps such as the rate-limit snippet omitting decorator wiring keep it just short of fully executable coverage.

4 / 5

Workflow Clarity

A clear 7-step numbered workflow with a structured 'Document Findings' severity/location format and explicit manual-verification checks in step 4; a 5 requires an explicit validation checkpoint and error-recovery loop before fixes, and this skill's verification is implicit rather than a formal validate-fix-retry gate.

4 / 5

Progressive Disclosure

Well-organized 7-step body with clearly signaled, real one-level-deep references (references/vulnerability_patterns.md, references/time_intervals.md) and the script appropriately under scripts/; falls just short of 5 because the Quick Reference and per-language detection patterns duplicate material that overlaps the reference files.

4 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, comprehensive description that explicitly covers what the skill does, when to use it, and concrete trigger phrases in third person. It enumerates specific capabilities and natural trigger terms with minimal fluff or conflict risk.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('identify security-critical time intervals', 'reviewing code for proper timeout enforcement, token expiration, session management, rate limiting', 'Detects missing expiration checks, excessive timeout values, lack of rate limiting') with comprehensive coverage, matching the anchor 5 example.

5 / 5

Completeness

Explicitly answers both 'what' (analyze code for timing vulnerabilities and detect specific issues) and 'when' via both an explicit 'Use this skill when reviewing code for...' clause and a 'Triggers when users ask to...' clause with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural triggers users would actually say ('check security timeouts', 'verify token expiration handling', 'audit session timeout implementation', 'review rate limiting', 'analyze time-based security controls'), written in third person ('Analyzes', 'Detects', 'Triggers').

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (security-critical time-interval and timing-vulnerability analysis) with distinct, specific triggers, giving minimal conflict risk with other skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ArabelaTso/Skills-4-SE
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.