CtrlK
BlogDocsLog inGet started
Tessl Logo

security-guard

Security specialist - finds vulnerabilities and ensures best practices

55

Quality

69%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/security-guard/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured, concise, and action-oriented with executable secure/insecure code contrasts, but its audit workflow lacks validation checkpoints and feedback loops, and the actionable guidance is checklist-heavy rather than fully procedural.

Suggestions

Add explicit validation/feedback steps to the Security Audit Template (e.g., verify findings against the checklist, re-test after remediation, confirm no regressions) to lift workflow clarity above 3.

Turn the generic 'Areas of Expertise' bullets into concrete actions or fold them into the checklist to cut padding.

Provide a runnable audit command or procedure (e.g., a dependency scan command, an ordered review routine) rather than only checklists to strengthen actionability.

DimensionReasoningScore

Conciseness

The body is mostly efficient, using checklists and tight BAD/GOOD code pairs that assume Claude's competence, with only minor padding (the generic 'Areas of Expertise' list and the closing quote).

4 / 5

Actionability

It provides concrete, executable BAD/GOOD code examples for SQL injection and XSS, but the audit section and most checklists are guidance rather than fully copy-paste-ready instructions, leaving minor gaps.

4 / 5

Workflow Clarity

The 'Security Audit Template' lists a clear six-step sequence, but it lacks explicit validation checkpoints or fix/retry feedback loops; for an audit/review workflow the cap of 3 applies.

3 / 5

Progressive Disclosure

With no bundle files present, the skill is a single-level, well-organized document with clear section headers and no nested references, satisfying the simple-skill exception for progressive disclosure.

5 / 5

Total

16

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description conveys a clear security niche and one concrete capability, but it lacks an explicit trigger/Use-when clause and uses fairly generic keywords rather than natural user phrases.

Suggestions

Add a 'Use when ...' clause naming concrete trigger scenarios (e.g., 'Use when reviewing code for security flaws, auditing authentication, or checking for OWASP Top 10 issues').

Replace generic phrasing with concrete actions users would say, such as 'audits code for vulnerabilities', 'checks authentication and authorization', 'reviews input validation'.

Include natural synonyms like 'security review', 'security audit', 'CVE', or 'OWASP Top 10' to improve trigger term coverage.

DimensionReasoningScore

Specificity

The description names the domain ('Security specialist') and one concrete action ('finds vulnerabilities') alongside the generic 'ensures best practices', matching the anchor for a couple of concrete actions that are not comprehensive.

3 / 5

Completeness

It has a clear 'what' (finds vulnerabilities and ensures best practices) but no 'Use when...' or equivalent trigger clause, so per the guideline completeness is capped at 3.

3 / 5

Trigger Term Quality

It includes relevant terms like 'Security', 'vulnerabilities', and 'best practices', but these are fairly generic and lack common natural synonyms a user would say (e.g., 'security review', 'audit', 'CVE').

3 / 5

Distinctiveness Conflict Risk

'Security specialist' carves a distinct niche with minimal overlap risk against most skills, though it could lightly overlap with general code-review skills.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
TurnaboutHero/oh-my-antigravity
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.