CtrlK
BlogDocsLog inGet started
Tessl Logo

review-hog-perspective-contracts-security

The Contracts & Security review perspective for ReviewHog. Verifies that changed code is safe and maintains compatibility — API contracts and breaking changes, injection / authz / data exposure, input validation, and schema / interface alignment. Reports security and contract issues only.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./products/review_hog/skills/review-hog-perspective-contracts-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is well-structured and actionable with concrete investigation commands, but lacks an explicit sequenced workflow with validation checkpoints and carries some redundancy between the investigation-areas and key-questions sections.

Suggestions

Add a short numbered workflow (e.g., run investigation commands → triage candidate issues → check against 'What a valid finding looks like' → report) with an explicit validation step before reporting.

Merge or trim the 'Key questions' section since it restates the 'Primary investigation areas', to reduce token redundancy.

DimensionReasoningScore

Conciseness

The body is mostly lean with concrete commands and no concept explanations Claude already knows, though the 'Key questions' section largely restates the 'Primary investigation areas', adding mild redundancy.

4 / 5

Actionability

Provides concrete, copy-paste-ready `rg` commands for finding endpoints, validation, SQL, auth, and schema, plus a concrete 'What a valid finding looks like' list — minor gaps in covering all common cases.

4 / 5

Workflow Clarity

Investigation areas and focus targets are listed but there is no explicit sequenced workflow with validation checkpoints for triaging/reporting findings, leaving the process checkpoints implicit.

3 / 5

Progressive Disclosure

Single self-contained file with well-organized section headers and no bundle files to navigate; structure is clear, with only minor room to tighten the redundant 'Key questions' section.

4 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-scoped to a distinct niche, but lacks an explicit 'Use when...' trigger clause, which caps its completeness and slightly weakens trigger guidance.

Suggestions

Add an explicit 'Use when...' clause naming the trigger conditions (e.g., 'Use when reviewing a PR for security, contract, or breaking-change risks').

Include a few more colloquial synonyms users might say (e.g., 'security review', 'breaking API changes') to broaden natural trigger coverage.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities — 'API contracts and breaking changes, injection / authz / data exposure, input validation, and schema / interface alignment' — giving comprehensive coverage of the perspective's actions.

5 / 5

Completeness

The 'what' is clearly stated ('Verifies that changed code is safe and maintains compatibility') but there is no explicit 'Use when...' trigger clause, so per the boundary guidance completeness is capped at 3 with only weakly implied 'when'.

3 / 5

Trigger Term Quality

Includes natural review-oriented terms like 'API contracts', 'breaking changes', 'injection', 'authz', and 'input validation', but is missing some common synonyms a user might voice and is somewhat technical rather than colloquial.

4 / 5

Distinctiveness Conflict Risk

The narrow scoping ('Reports security and contract issues only') and the named perspective carve a clear niche with minimal overlap risk against sibling review perspectives.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PostHog/posthog
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.