CtrlK
BlogDocsLog inGet started
Tessl Logo

bk-monitor-security-audit

对前端代码进行安全审计,检测 XSS、CSRF 等漏洞。当用户请求代码审查或询问代码安全性时使用。

54

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./bcs-services/bcs-project-manager/.cursor/skills/bk-monitor-security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

42%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body has a clear structure and a sensible audit checklist but provides only abstract guidance with no executable detection patterns, and it points to reference files that do not exist while duplicating the resource listing. Adding concrete audit patterns and fixing the dangling/duplicated references would most improve it.

Suggestions

Add concrete, executable detection patterns or code snippets for each checklist item (e.g. regex or AST queries for innerHTML/v-html, eval, postMessage) instead of naming categories only.

Create the missing references/ files (audit-rules.md, report-template.md, security-checklist.md) or remove the dangling skill:// references so navigation is valid.

Remove the duplicated '📦 可用资源' section and add a validation/verification step to the workflow (e.g. confirm each finding with file:line evidence before reporting).

DimensionReasoningScore

Conciseness

The body is short but contains a fully duplicated '📦 可用资源' resource block, which is unnecessary padding; otherwise it is mostly efficient, matching anchor 3 rather than the cleaner anchor 4.

3 / 5

Actionability

The workflow ('读取代码文件', '按检查清单逐项审计', '按 report-template.md 输出报告') and checklist give only high-level hints with no concrete detection patterns, commands, or executable code, matching anchor 2; not 3 because no concrete executable detail is supplied.

2 / 5

Workflow Clarity

A coherent three-step sequence exists (read → audit by checklist → report) but has no validation checkpoints or feedback loops for verifying findings, matching anchor 3; not 4 because checkpoints are entirely absent.

3 / 5

Progressive Disclosure

The body cites three references under references/*.md but no references/ bundle directory exists, so the references are dangling; section structure is present but the referenced detailed materials are missing and the resource block is duplicated, matching anchor 3 rather than 4.

3 / 5

Total

11

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and clearly answers both what the skill does and when to use it, with concrete trigger phrases. Its main weakness is limited action specificity and only moderate keyword breadth.

DimensionReasoningScore

Specificity

Names the frontend security domain plus two concrete actions ('进行安全审计', '检测 XSS、CSRF 等漏洞'), but does not enumerate the broader checklist coverage (postMessage, eval, prototype pollution), matching anchor 3 rather than the more comprehensive anchor 4.

3 / 5

Completeness

Explicitly answers both 'what' (frontend security audit detecting XSS/CSRF) and 'when' (when the user requests code review or asks about code security) with concrete trigger phrases, matching anchor 5; not 4 because the 'when' clause is already explicit rather than merely implicit.

5 / 5

Trigger Term Quality

Includes natural user phrases '请求代码审查' and '询问代码安全性' plus security keywords (XSS, CSRF), giving good keyword coverage; falls short of anchor 5 because common synonyms and variations are not exhaustively covered.

4 / 5

Distinctiveness Conflict Risk

The '前端代码安全审计' niche with XSS/CSRF triggers is mostly distinct with only minor overlap risk against general code-review skills, matching anchor 4; not 5 because it could still overlap with broader review skills.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
TencentBlueKing/bk-bcs
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.