CtrlK
BlogDocsLog inGet started
Tessl Logo

security

Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth. Use when writing any action, route, or component that touches user data or external input.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-organized security reference: concrete executable patterns for every rule, explicit validation tooling, and a closing checklist. Its main cost is length — dated incident history and guard implementation details are inlined in SKILL.md rather than split into reference files, which hurts token efficiency and progressive disclosure.

Suggestions

Move the 2026-04-29/2026-04 incident history and the four guard-allowlist/opt-out enumerations into a references/guards.md file, keeping only the rule and the guard name in SKILL.md.

Place dated, time-sensitive information in an explicit 'old patterns' or 'deprecated' section (or drop the dates in favor of the current rule) so it does not age the skill.

Tighten the SSRF and Same-Origin sections to rule + one code example, trimming explanatory prose around the mechanics (DNS rebinding, redirect hops) that the code comments already cover.

DimensionReasoningScore

Conciseness

The body is dense and assumes competence (no re-explanation of what XSS or SQL injection are) and mostly earns its tokens with project-specific rules, but it carries inline time-sensitive material — 'On 2026-04-29 the previous one-arg resolveCredential…', 'the 2026-04 cross-tenant leak class', 'MCP 2026 hosts' — outside any old-patterns/deprecated section, plus long incident narratives and guard-allowlist enumerations that could be tightened. Not 4 because the dated history and guard minutia are noticeable padding that could move to a reference file.

3 / 5

Actionability

Every rule ships copy-paste-ready executable code: defineAction with Zod schema, parameterized Drizzle/SQL, ssrfSafeFetch with options, resolveCredential with request context, getSession/401 handlers, accessFilter/runWithRequestContext route pattern, authorize and needsApproval examples. Runnable verification commands ('pnpm action db-check-scoping', 'pnpm prep' guards) and bad/good code contrasts cover the common cases.

5 / 5

Workflow Clarity

The custom-routes section gives a clear numbered 1-2-3 sequence, a closing checklist consolidates the rules, and CI guards plus db-check-scoping provide validation checkpoints. Not 5 because there are no explicit validate-fail-fix-retry loops, and the multi-section rule layout (appropriate for this reference-style skill) is not a single sequenced workflow.

4 / 5

Progressive Disclosure

Well-organized single file with clear section headers and clearly signaled one-level-deep pointers to related skills ('storing-data', 'actions', 'authentication') and spec files; no bundle files exist so everything is inline. Not 5 because at ~340 lines the guard-allowlist details and historical incident notes are content that could split into reference files, keeping the core rules leaner; not 3 because navigation is easy and references are explicit, not buried.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names concrete security domains, uses natural trigger vocabulary, and pairs an explicit 'what' with an explicit 'Use when...' clause. Minor improvements would be adding SSRF/authorization to the capability list and a few synonym triggers, but nothing rises to a real weakness.

DimensionReasoningScore

Specificity

Enumerates concrete capability areas — 'input validation, SQL injection, XSS, secrets, data scoping, and auth' — which names the domain with several specific practices rather than generic claims. Not 5 because these are topic areas rather than fully concrete actions and coverage has minor gaps (e.g. SSRF and approval gating are in the body but absent here); not 3 because the list is comprehensive and domain-anchored, not just 1-2 actions.

4 / 5

Completeness

Explicitly answers both: what ('Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth') and when ('Use when writing any action, route, or component that touches user data or external input') with concrete trigger phrases. Matches the 5 anchor directly.

5 / 5

Trigger Term Quality

Includes natural phrases users would actually say — 'SQL injection', 'XSS', 'secrets', 'auth', 'user data', 'external input'. Not 5 because common variations and synonyms ('vulnerability', 'hardening', 'exploit', 'injection attack') are missing; not 3 because the terms present are the natural vocabulary, not jargon-only.

4 / 5

Distinctiveness Conflict Risk

Clear niche (security for this agent-native framework) with distinct triggers tied to 'action, route, or component that touches user data or external input'. Minimal conflict risk — it scopes itself to the framework's security primitives rather than overlapping generic document/file skills.

5 / 5

Total

18

/

20

Passed

Validation

75%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 12 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 5 missing

Warning

Total

12

/

16

Passed

Repository
BuilderIO/agent-native
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.