CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review-checklist

Static review rules for authorization, validation, and privilege escalation risks

58

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/security-review-checklist/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

80%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an efficient, well-organized instruction-only checklist with clear scope and ownership boundaries and no wasted tokens. Its main weakness is the lack of a sequenced review workflow with validation checkpoints before escalating findings.

Suggestions

Add a short sequenced workflow (e.g., for each rule check the code -> record findings -> confirm before escalating) with explicit verification checkpoints.

Provide one or two concrete examples of what triggers each rule (e.g., a controller action lacking a policy check) to lift actionability.

Clarify how findings should be reported or escalated so the Escalation Principle ties into an actionable output.

DimensionReasoningScore

Conciseness

The body is lean with no padding or basic-concept explanation; every section (Purpose, Scope, Ownership Boundary, Rules, Escalation Principle) earns its place and assumes Claude's competence, matching the score-5 lean-and-efficient anchor.

5 / 5

Actionability

Rules like "Every sensitive action MUST have explicit authorization check" and "No unguarded resource actions (create/update/delete/view)" are concrete checklist items, but lack specific worked examples of what counts, fitting the score-4 mostly-executable anchor.

4 / 5

Workflow Clarity

The content presents rules and an escalation principle rather than a sequenced review workflow, and there are no explicit validation checkpoints for confirming a finding before escalating, matching the score-3 anchor of listed items with missing checkpoints.

3 / 5

Progressive Disclosure

The skill is under 50 lines with no bundle files and is organized into clearly labeled, well-separated sections, so per the simple-skill exception progressive disclosure scores 5 with good organization alone.

5 / 5

Total

17

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and specific about its security-review domain and concrete targets, but omits any explicit 'Use when' trigger guidance, which limits its completeness and trigger coverage. It is reasonably distinct from generic skills but could add trigger phrases to improve discoverability.

Suggestions

Add an explicit trigger clause such as 'Use when reviewing code for authorization, validation, or privilege-escalation risks'.

Include natural synonyms users actually say (e.g., access control, permissions, security review) to broaden trigger-term coverage.

Name a second concrete action (e.g., flags issues, reports findings) to lift specificity beyond a single review action.

DimensionReasoningScore

Specificity

"Static review rules for authorization, validation, and privilege escalation risks" names the domain and lists concrete review targets, but offers only one action (static review) rather than several distinct actions, matching the score-3 anchor of domain plus limited actions.

3 / 5

Completeness

The description clearly states what it does ("Static review rules for...") but contains no "Use when..." trigger clause, so per the rubric a missing explicit trigger caps completeness at 3.

3 / 5

Trigger Term Quality

"authorization, validation, and privilege escalation" are relevant natural terms, but common synonyms a user would say (security review, access control, permissions, authz) are missing, fitting the score-3 anchor of some relevant keywords but missing variations.

3 / 5

Distinctiveness Conflict Risk

"Static review rules for authorization, validation, and privilege escalation risks" carves a fairly specific security-review niche with minor overlap risk against a general code-review skill, matching the score-4 anchor of mostly distinct.

4 / 5

Total

13

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Bottelet/DaybydayCRM
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.