CtrlK
BlogDocsLog inGet started
Tessl Logo

security-audit

Security audit — save tampering, cheat vectors, network exploits, data exposure, input validation. Before public or multiplayer release.

61

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

70%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally concrete, well-sequenced audit procedure whose only real weakness is verbosity: the critical NOT-ASSESSED/zero-hit safety rules are argued repeatedly with justificatory prose instead of stated once. Structure is a single long file that would benefit from splitting reference material out.

Suggestions

State the zero-hit/NOT ASSESSED rule once (e.g., in Phase 5) and cross-reference it from Phase 1, Phase 3, and each category blockquote instead of re-arguing it four times.

Delete meta-commentary about the skill's own development history (e.g., 'That warning was earned along the version axis... shipped anyway') — it justifies the rule to a reader but instructs the executor nothing.

Move the Phase 5 report template and the per-engine grep pattern tables into references/ files (e.g., references/report-template.md, references/engine-patterns.md) and keep SKILL.md as the phased overview.

DimensionReasoningScore

Conciseness

The same failure-mode warning ("zero hits in this category renders the report clean", NOT ASSESSED rules) is restated at length in the Phase 1 multiplayer note, the Phase 3 engine-table intro, the Category 1 blockquote, the Phase 5 blockquote, and Phase 7, and meta-commentary about the skill's own history ("That warning was earned along the version axis... the identical hole along the engine axis shipped anyway") justifies rules rather than instructing. Several padded/redundant sections could be cut or consolidated without losing any operational content. Not a 1: it never explains concepts Claude already knows — the padding is repetition, not tutorials. Not a 3: the redundancy is more than 'some' unnecessary explanation; the identical rule is argued three to four times.

2 / 5

Actionability

Fully executable throughout: exact grep patterns per category (`FileAccess`, `ENetMultiplayerPeer`, `api[_-]?key`, `BEGIN PRIVATE KEY`), an engine-specific pattern table, a copy-paste brief template with explicit fill-in slots, a complete severity table, and a full report template down to the per-finding field list. Even the user-facing messages in Phase 7 are given verbatim.

5 / 5

Workflow Clarity

A clearly sequenced 7-phase workflow with explicit validation checkpoints: first-match-wins release recommendation, NOT ASSESSED handling for every unscannable surface, ask-before-write in Phase 6, re-audit trigger after CRITICAL/HIGH remediation, and defined fallbacks for every failure mode (unresolved code root, unspawnable security-engineer, unset multiplayer keys). Error-recovery feedback loops are present for every risky branch.

5 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ absent), so all ~440 lines are inlined in one SKILL.md. Section headers and phases are clear and the external doc references (docs/engine-reference/..., .claude/docs/...) are given with exact paths, but content that clearly belongs in separate reference files — the full report template, the per-engine pattern tables, the six category checklists — is inlined. Not a 4: the file's length is itself the navigation cost the rubric's splitting guidance targets.

3 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete domain areas, an explicit use-when clause, and natural trigger terms, all in third person. Only minor gaps — the dependency/supply-chain category and the secondary triggers from the body are left out.

DimensionReasoningScore

Specificity

Names the action ("Security audit") plus five concrete areas — "save tampering, cheat vectors, network exploits, data exposure, input validation" — which is several specific capabilities. Not a 5: coverage has a minor gap; the skill's Category 6 (dependency/supply chain) is absent from the description. Not a 3: it lists several areas, not just 1-2.

4 / 5

Completeness

Both parts are present: the 'what' is auditing the five named vectors, and the 'when' is explicit — "Before public or multiplayer release." Not a 5: the 'when' covers only the release case; the body's other triggers (before enabling online features, after implementing disk/network-reading systems, when a security bug is reported) are omitted, so it could be more specific. Not a 3: the 'when' is explicit, not weakly implied.

4 / 5

Trigger Term Quality

Good natural keyword coverage: "security audit", "save tampering", "cheat vectors", "network exploits", "data exposure", "input validation", "public or multiplayer release" are all phrases a user would plausibly say. Not a 5: common synonyms like "vulnerability", "hardening", or "penetration test" are missing.

4 / 5

Distinctiveness Conflict Risk

"Security audit" scoped to game release vectors (save tampering, cheats, multiplayer exploits) is a clear niche with distinct triggers; nothing generic that would collide with other skills. Third-person voice, no fluff.

5 / 5

Total

17

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

13

/

16

Passed

Repository
Donchitos/Claude-Code-Game-Studios
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.