CtrlK
BlogDocsLog inGet started
Tessl Logo

bk-monitor-security-audit

对前端代码进行安全审计,检测 XSS、CSRF 等漏洞。当用户请求代码审查或询问代码安全性时使用。

57

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./bcs-services/bcs-project-manager/.cursor/skills/bk-monitor-security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is admirably concise and correctly structured as an overview-plus-references pattern, but it fails on follow-through: every referenced detail file is missing from the bundle, the resource section is duplicated verbatim, and the workflow's only actionable depth is delegated to files that don't exist. What remains is a checklist of topics rather than executable audit guidance.

Suggestions

Create the referenced files (references/audit-rules.md, references/report-template.md, references/security-checklist.md) or remove the skill:// references so navigation points at real resources.

Remove the duplicated '📦 可用资源' section and fold the load-hint ('根据 IF-THEN 规则判断是否需要加载') into a single resource listing tied to the workflow steps.

Add at least one concrete detection pattern or example per checklist item (e.g., what an unsafe innerHTML sink looks like and how to report it) so the skill is actionable even before the reference files are loaded.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence — checklist items are given as bare names ("innerHTML、v-html", "eval", "postMessage") with no concept explanations. However, the entire '📦 可用资源' section is duplicated verbatim, which is wasted tokens, so it fits anchor 4 (minor trimming needed) rather than anchor 5.

4 / 5

Actionability

The audit checklist names concrete inspection targets (DOM 操作/innerHTML, URL/重定向, postMessage, eval, 原型污染/ReDoS), but provides no how — no detection patterns, commands, or code examples — and the referenced detail files (audit-rules.md, report-template.md) do not exist in the bundle. This matches anchor 3 (concrete but incomplete, key details missing) rather than anchor 4 (mostly executable guidance).

3 / 5

Workflow Clarity

The workflow '读取代码文件 → 按检查清单逐项审计 → 按 report-template.md 输出报告' is a listed sequence but has no validation checkpoints or feedback loops, and the final step depends on a file that is absent from the bundle. This matches anchor 3 (steps listed, checkpoints missing) rather than anchor 4.

3 / 5

Progressive Disclosure

The body lists three skill:// references (audit-rules.md, report-template.md, security-checklist.md) but none of these files exist in the bundle — the references point to nothing. Combined with the verbatim-duplicated resource listing and an inline checklist duplicating the referenced security-checklist.md, navigation is misleading, matching anchor 2 (minimal/broken structure) rather than anchor 3.

2 / 5

Total

12

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-formed description that explicitly states what the skill does and when to use it, with natural trigger terms and domain-specific keywords. Its main weaknesses are limited specificity of capabilities (only vulnerability detection is named) and a code-review trigger that overlaps with general review skills.

Suggestions

List the concrete audit actions more comprehensively (e.g., 'audits DOM operations, URL handling, postMessage, and dynamic code execution; outputs a structured vulnerability report') to raise specificity.

Narrow or contextualize the 'code review' trigger (e.g., 'when the user asks for a security-focused review of frontend code') to reduce overlap with generic code-review skills.

DimensionReasoningScore

Specificity

The description names the domain ("前端代码进行安全审计") and one concrete action ("检测 XSS、CSRF 等漏洞"), matching the anchor for 1-2 concrete actions without comprehensive coverage. It does not list several specific actions like report generation or remediation guidance, so it falls below anchor 4.

3 / 5

Completeness

It explicitly answers both questions: what ("对前端代码进行安全审计,检测 XSS、CSRF 等漏洞") and when ("当用户请求代码审查或询问代码安全性时使用") with concrete trigger phrases. The when-clause is explicit and specific, matching anchor 5 rather than the weaker when-clause of anchor 4.

5 / 5

Trigger Term Quality

It includes natural trigger phrases users would say — "代码审查" (code review), "询问代码安全性" (asking about code security), plus the concrete keywords XSS and CSRF. A few natural synonyms (e.g., 安全扫描, 渗透测试, vulnerability disclosure terms) are missing, matching anchor 4 rather than the comprehensive coverage of anchor 5.

4 / 5

Distinctiveness Conflict Risk

The frontend security audit niche with XSS/CSRF keywords is fairly distinct, but the trigger "代码审查" (code review) is broad and overlaps with generic code-review skills. This is minor overlap risk with closely related skills, matching anchor 4 rather than the minimal-conflict profile of anchor 5.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
TencentBlueKing/bk-bcs
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.