CtrlK
BlogDocsLog inGet started
Tessl Logo

common-llm-security

OWASP LLM Top 10 (2025) audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction. Use when performing any security review touching LLM client code, prompt templates, agent tools, or vector stores.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/common/common-llm-security/SKILL.md

The canonical home for this skill is common-llm-security in HoangNguyen0403/agent-skills-standard

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured audit-checklist skill with excellent progressive disclosure (a verified one-level reference) and largely actionable detection signals. The main gaps are workflow clarity — the audit sequence is only partially ordered and lacks an explicit verify/report checkpoint, with an empty P0 header hinting at dropped content — and minor token waste from the dangling 'Canonical response anchors' section.

Suggestions

Add an explicit step-by-step audit sequence covering all ten LLM risks (not just LLM01 and LLM06) ending with a validation/reporting checkpoint, e.g. '4. Re-verify every 🔴 item against references/owasp-llm.md before reporting; 5. Summarize findings with severity and the capped score.'

Fix or remove the empty '## **Priority: P0 (CRITICAL)**' header and the 'Canonical response anchors' section that ends in a single dangling '- sanitize' bullet — either complete these sections or delete them to remove ambiguity and wasted tokens.

Tighten the Implementation Guidelines bullets by attaching a concrete example to each (e.g. 'pin source revision and hashes' → 'record sha256 of each package in a lockfile and verify on install') so the guidance is copy-paste actionable without loading the reference.

DimensionReasoningScore

Conciseness

The body is lean — a compact 10-row table of detection signals and terse bullets with no explanations of concepts Claude already knows — matching anchor 4. It misses anchor 5 because of small wastes: an empty '## **Priority: P0 (CRITICAL)**' header with no content beneath it, a 'Canonical response anchors' section ending in a single dangling item ('- sanitize'), and awkward phrasing like '— not skip any item'.

4 / 5

Actionability

Guidance is mostly executable for an audit workflow: ordered checks ('Check LLM01 first', 'Check LLM06 next'), a marking scheme ('✅ not affected | ⚠️ needs review | 🔴 confirmed finding'), a scoring rule ('P0 finding caps Security score at 40/100'), and concrete per-risk signals like 'No `max_tokens` on LLM call. No rate limit on invocations.' This matches anchor 4; it is not 5 because fix guidance lives entirely in the reference file and a couple of guidelines (e.g. 'pin source revision and hashes') lack concrete examples inline.

4 / 5

Workflow Clarity

A partial sequence exists (LLM01 first, LLM06 next, then 'mark each item'), but the remaining eight risks are unsequenced and there is no explicit validation or reporting checkpoint — the marking scheme is implied rather than a stated verify/report step. This matches anchor 3 ('steps listed but validation gaps; checkpoints missing or implicit'), and the empty P0 priority header suggests missing workflow content that would be needed for anchor 4.

3 / 5

Progressive Disclosure

SKILL.md is a genuine overview: a summary table of the ten risks with key signals, while full detection signals are split into one real, one-level-deep reference (references/owasp-llm.md, verified to exist, 115 lines) that is clearly signaled twice with load-when guidance ('load when auditing any LLM client code'). This matches anchor 5 — clear overview, well-signaled one-level-deep references, easy navigation — and is above anchor 4 because nothing that belongs in the reference is inlined and no reference is buried.

5 / 5

Total

16

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit 'Use when...' clause and concrete trigger surfaces, giving excellent completeness and distinctiveness. Its only weakness is action specificity — it describes one action (audit checklist) across many targets rather than enumerating several distinct capabilities — and a few natural trigger synonyms are relegated to metadata keywords rather than the description text.

DimensionReasoningScore

Specificity

The description names a clear domain and surfaces ("audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction") but offers only one action verb — auditing — rather than several specific actions. It matches anchor 3 (domain plus 1-2 concrete actions) rather than 4, which requires a list of several distinct actions.

3 / 5

Completeness

It explicitly answers both questions: the what ("OWASP LLM Top 10 (2025) audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction") and the when ("Use when performing any security review touching LLM client code, prompt templates, agent tools, or vector stores") with concrete trigger phrases. This is a direct match for anchor 5 and clearly above anchor 4, whose 'when' is less specific.

5 / 5

Trigger Term Quality

Natural user phrases like "security review", "LLM client code", "prompt templates", "agent tools", "RAG pipelines", and "vector stores" give good keyword coverage, matching anchor 4. It falls short of anchor 5 because common synonyms a user would actually say — e.g. "prompt injection", "LLM security", "AI security" — appear only in metadata.triggers, not in the description itself.

4 / 5

Distinctiveness Conflict Risk

The skill occupies a clear niche (LLLM application security auditing against the OWASP LLM Top 10) with distinct, targeted triggers, matching anchor 5. Overlap risk with general security or general coding skills is minimal since the triggers are specific to LLM client code, prompt templates, agent tools, and vector stores.

5 / 5

Total

17

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

13

/

16

Passed

Repository
HoangNguyen0403/agent-skills-standard
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.