CtrlK
BlogDocsLog inGet started
Tessl Logo

security-audit

Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

65

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./crates/openfang-skills/bundled/security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concrete, well-organized methodology reference with specific tools and patterns, but it reads as a category checklist rather than a sequenced audit workflow and restates some concepts Claude already knows.

Suggestions

Add a short sequenced audit workflow (e.g. scope -> SAST/DAST -> dependency scan -> manual review -> report) with validation checkpoints to lift workflow clarity.

Trim restatements of well-known fundamentals (e.g. the SQL-injection root cause) to keep the content to what Claude does not already know.

DimensionReasoningScore

Conciseness

The body is mostly lean bullet points, but several clauses restate knowledge Claude already has (e.g. 'string concatenation in SQL is the root cause of injection', 'Attackers bypass the UI entirely'), placing it just below the lean/efficient anchor.

2 / 3

Actionability

It names specific tools and commands (Semgrep, CodeQL, Bandit, 'npm audit', 'cargo audit', OWASP ZAP, bcrypt/Argon2id, CSP 'default-src self') giving concrete, executable guidance rather than abstract direction.

3 / 3

Workflow Clarity

Content is organized into clear categories (Principles, Techniques, Patterns, Pitfalls) but presents no sequenced audit workflow with validation checkpoints for what is inherently a multi-step process.

2 / 3

Progressive Disclosure

At under 50 lines with no external references needed, the well-organized section structure satisfies the rubric's simple-skill exception for progressive disclosure.

3 / 3

Total

10

/

12

Passed

Description

82%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-targeted description that names concrete capabilities and natural trigger terms, but it omits an explicit 'Use when...' usage clause, which caps completeness.

Suggestions

Add a 'Use when...' clause, e.g. 'Use when reviewing code for vulnerabilities, analyzing CVE impact, or planning penetration tests.'

Include common phrasing variations like 'vulnerability assessment', 'pentest', or 'secure code review' to broaden trigger coverage.

DimensionReasoningScore

Specificity

The description lists multiple concrete capabilities — 'OWASP Top 10, CVE analysis, code review, and penetration testing' — matching the anchor for naming several specific actions rather than vague language.

3 / 3

Completeness

It clearly states what the skill does but has no 'Use when...' clause or equivalent explicit trigger guidance, so per the rubric completeness is capped at 2.

2 / 3

Trigger Term Quality

It includes natural terms a user requesting security work would say ('OWASP Top 10', 'CVE analysis', 'code review', 'penetration testing'), giving good coverage of domain keywords.

3 / 3

Distinctiveness Conflict Risk

The security-audit niche anchored by OWASP/CVE/pentest triggers is clearly distinct from general skills; the broad 'code review' mention is subordinate to a clear security framing.

3 / 3

Total

11

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
RightNow-AI/openfang
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.