CtrlK
BlogDocsLog inGet started
Tessl Logo

security-reviewer

Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews, dependency audits, secrets scanning, or compliance checks. Produces vulnerability reports, prioritized recommendations, and compliance checklists.

76

Quality

96%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized with a sequenced workflow, concrete runnable commands, a complete finding template, and a clean one-level-deep reference structure with authorization/validation checkpoints appropriate to a destructive security-testing context. It is only slightly held back from full marks by minor restatable phrasing.

Suggestions

Tighten restatable lines such as 'Tools miss context — manual review is mandatory' and 'Run automated tools before manual review' into the workflow/constraint sections to remove redundant explanation Claude already infers.

Consider adding flags for the most common scan contexts (e.g. language-specific semgrep rulesets) to move the SAST commands from runnable to optimally-targeted for the common cases.

DimensionReasoningScore

Conciseness

Mostly lean and efficient with actionable lists, runnable commands, and a concrete finding template; minor instances of restatable phrasing ('Tools miss context — manual review is mandatory', 'Run automated tools before manual review') keep it just below the anchor-5 'every token earns its place' bar, placing it noticeably above the anchor-3 midpoint.

4 / 5

Actionability

Provides copy-paste-ready commands ('semgrep --config=auto .', 'bandit -r ./src', 'gitleaks detect --source=.', 'npm audit --audit-level=moderate', 'trivy fs .') and a complete executable finding example with a concrete remediation code diff covering the common case, matching the anchor-5 example rather than the minor-gaps anchor-4.

5 / 5

Workflow Clarity

Five-step sequenced Core Workflow with explicit validation checkpoints for an active-testing/destructive context ('Confirm written authorization and rules of engagement', 'Verify written scope authorization before active testing', 'Confirm findings with stakeholder before finalizing', 'Report critical findings immediately'); the missing-validation cap does not apply and the anchor-5 validation-with-checkpoints example fits.

5 / 5

Progressive Disclosure

Clear overview body with a well-signaled Reference Guide table of six one-level-deep references, each with a 'Load When' column and all confirmed to be real files, with content appropriately split into separate reference files; matches the anchor-5 clear-overview-with-one-level-deep-references example.

5 / 5

Total

19

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, comprehensive, and well-structured with concrete actions and explicit 'Use when'/'Invoke for' trigger guidance. It uses correct third-person voice and maintains a clear security niche distinct from neighboring skills.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions ('Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance', 'Produces vulnerability reports, prioritized recommendations, and compliance checklists') with comprehensive coverage; clearly the anchor-5 example rather than the several-actions anchor-4.

5 / 5

Completeness

Explicitly answers both 'what' (identifies vulnerabilities, generates reports, remediation) and 'when' with concrete trigger phrases ('Use when conducting security audits...', 'Invoke for SAST scans...'), matching the anchor-5 example; not 4 because the 'when' is explicit and specific rather than merely present.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage including synonyms and tool names users actually say ('security audits', 'SAST scans', 'penetration testing', 'DevSecOps', 'cloud security reviews', 'dependency audits', 'secrets scanning', 'compliance checks'), matching the anchor-5 comprehensive-synonym example; not the 4 anchor which expects a few missing terms.

5 / 5

Distinctiveness Conflict Risk

Clear security niche with distinct triggers ('SAST scans', 'penetration testing', 'secrets scanning') and minimal conflict risk against adjacent skills; third-person voice throughout with no first/second-person penalty; the anchor-5 clear-niche example fits better than the minor-overlap anchor-4.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
Jeffallan/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.