CtrlK
BlogDocsLog inGet started
Tessl Logo

prd-securability-enhancement

Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written. Trigger on "harden the PRD/spec", "choose ASVS level", "map features to ASVS", "find missing security requirements", "add NFRs for security", "make these requirements securable", "security-review my product brief". For code review use securability-engineering-review; for code generation use securability-engineering.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, highly actionable requirements-engineering runbook with clear sequencing and a validation checklist. It loses a little on conciseness and progressive disclosure because substantial reference material (gap table, templates, worked example) lives inline rather than in separate bundle files.

Suggestions

Move the ASVS Coverage Gap Pattern Table and the full Output Templates into separate reference files (e.g. references/asvs-gap-patterns.md, references/output-templates.md) and link to them from the procedure, leaving only the procedural essence inline.

Tighten the Worked Example to a compact illustration of the output shape rather than a near-complete spec, or relocate it to a reference file to reduce SKILL.md token weight.

Trim explanatory sentences that restate the obvious (e.g. 'Selecting the level before mapping requirements prevents both under-scoping and over-scoping') where the table already conveys the rule.

DimensionReasoningScore

Conciseness

Mostly efficient and assumes Claude's competence; the ASVS gap-pattern table, output templates, and worked example are load-bearing material Claude does not already know rather than padding. Minor prose (the worked example and a few explanatory paragraphs) could be trimmed, so it sits just below the lean top anchor.

4 / 5

Actionability

Provides fully actionable, copy-paste-shape guidance: exact output templates A–E, a concrete worked example with specific ASVS references and testable acceptance criteria, and a gap-pattern table that prefills missing requirements — covering the common cases.

5 / 5

Workflow Clarity

Steps 1–6 are clearly sequenced (parse → choose level → map → notes → convert → emit) with an explicit validation gate — the 'Quality Checklist (run before emitting)' — providing the feedback loop the top anchor requires; the work is not destructive/batch so no cap applies.

5 / 5

Progressive Disclosure

Good section structure with clear navigation and external reference pointers (plays, data/asvs, data/fiasse), but the large ASVS gap-pattern table, full output templates, and worked example are all inlined in SKILL.md with no bundle files (references/scripts/assets) to offload them, leaving minor organization gaps relative to the one-level-deep ideal.

4 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is third-person, concise, and clearly states both the capability and the trigger conditions, with explicit routing away from adjacent code skills. It hits the top anchor on every dimension.

DimensionReasoningScore

Specificity

Names the domain (PRDs/specs/user stories/briefs) and lists multiple concrete actions — adding explicit OWASP ASVS coverage, FIASSE v1.0.4 SSEM guidance, choosing ASVS level, mapping features, finding missing requirements, adding NFRs — for comprehensive coverage.

5 / 5

Completeness

Explicitly answers both what (enhance pre-code requirements with ASVS coverage and FIASSE SSEM guidance) and when (a 'Trigger on…' clause with concrete trigger phrases), matching the top anchor.

5 / 5

Trigger Term Quality

Includes a comprehensive set of natural quoted phrases a user would actually say — 'harden the PRD/spec', 'choose ASVS level', 'map features to ASVS', 'find missing security requirements', 'add NFRs for security', 'make these requirements securable', 'security-review my product brief'.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (pre-code PRD securability) and explicitly disambiguates from sibling skills — 'For code review use securability-engineering-review; for code generation use securability-engineering' — minimizing wrong-skill triggering.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 suspicious

Warning

Total

15

/

16

Passed

Repository
OWASP/secure-agent-playbook
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.