CtrlK
BlogDocsLog inGet started
Tessl Logo

common-security-audit

Probe for hardcoded secrets, injection surfaces, unguarded routes, business logic flaws, and platform-specific weaknesses across backend (Node, Go, Java, Python, Rust), frontend (React, Angular, Vue), and mobile (iOS, Android, Flutter) codebases. Use when performing security audits, vulnerability scans, secrets detection, or penetration testing.

67

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured directory that leans on real reference files, but actionability is uneven across sections and the workflow lacks explicit validation checkpoints for a destructive/batch audit context.

Suggestions

Add at least one inline executable command to the pointer-only sections (1, 2, 3, 5, 7) so the common cases are actionable without opening the reference file.

Insert explicit validation checkpoints in the workflow (e.g. confirm finding severity, re-run scan after remediation, verify secret rotation) to raise workflow_clarity above the destructive/batch cap of 3.

Tighten section headers that restate the topic without adding value to push conciseness from efficient to fully lean.

DimensionReasoningScore

Conciseness

Largely lean and pointer-driven, offloading detail to reference files; a few section headers restate the topic without adding executable content, so it is not fully maximally efficient.

4 / 5

Actionability

Sections 4, 6, and 8 provide concrete executable commands, but sections 1, 2, 3, 5, and 7 are pointer-only ('See references/implementation.md') with no inline command for the common cases.

3 / 5

Workflow Clarity

A numbered section sequence exists, but there are no explicit validate→fix→retry checkpoints; per the rubric cap, a destructive/batch audit skill without validation cannot score above 3.

3 / 5

Progressive Disclosure

Clear overview with well-signaled, one-level-deep references to verified real files (implementation.md, mobile-audit.md, REMEDIATION.md), with content appropriately split across them.

5 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete, comprehensive, and explicitly answers both what the skill does and when to use it with natural trigger terms. It is among the strongest reference examples.

DimensionReasoningScore

Specificity

Lists multiple concrete probe targets ('hardcoded secrets, injection surfaces, unguarded routes, business logic flaws') plus explicit platform coverage across backend, frontend, and mobile stacks.

5 / 5

Completeness

Clearly answers 'what' (probe for specific weakness classes across named stacks) and 'when' via an explicit 'Use when performing security audits, vulnerability scans, secrets detection, or penetration testing' clause.

5 / 5

Trigger Term Quality

Includes natural trigger phrases users would say ('security audits', 'vulnerability scans', 'secrets detection', 'penetration testing') with synonym coverage and no jargon-only gaps.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear security-audit niche with concrete, domain-specific triggers and platform enumeration that minimizes overlap with adjacent skills.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
HoangNguyen0403/agent-skills-standard
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.