CtrlK
BlogDocsLog inGet started
Tessl Logo

your-skill-name

Replace with a clear description of what this skill does and when Claude should use it.

43

1.01x
Quality

11%

Does it follow best practices?

Impact

100%

1.01x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No known issues

Optimize this skill with Tessl

npx tessl skill review --optimize ./template/SKILL.md
SKILL.md
Quality
Evals
Security

Evaluation results

100%

Security Review: Flask Web Application

Security finding format on vulnerable Flask app

Criteria
Without context
With context

File:line citation

100%

100%

Evidence shown

100%

100%

Impact explained

100%

100%

Remediation provided

100%

100%

OWASP reference included

100%

100%

SQL injection found

100%

100%

XSS found

100%

100%

Hardcoded secrets found

100%

100%

Path traversal found

100%

100%

100%

2%

Comprehensive Security Assessment: Internal API Platform

Full security assessment report for multi-file API platform

Criteria
Without context
With context

File:line citations

80%

100%

Evidence quoted

100%

100%

Impact stated per finding

100%

100%

Remediation per finding

100%

100%

OWASP references

100%

100%

Report has executive summary

100%

100%

Weak secret key found

100%

100%

Command injection found

100%

100%

Insecure deserialization found

100%

100%

Vulnerable dependencies found

100%

100%

Weak password storage found

100%

100%

Predictable reset token found

100%

100%

100%

Infrastructure Security Audit: Container Deployment Configuration

Infrastructure config security audit with finding format

Criteria
Without context
With context

File:line citation

100%

100%

Evidence shown

100%

100%

Impact explained

100%

100%

Remediation provided

100%

100%

OWASP or security standard reference

100%

100%

Privileged container found

100%

100%

Secrets in environment vars found

100%

100%

Weak TLS protocols found

100%

100%

Missing security headers found

100%

100%

Docker socket exposure found

100%

100%

Repository
OWASP/secure-agent-playbook
Evaluated
Agent
Claude Code
Model
Claude Sonnet 4.6

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.