CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Deprecated standalone security review skill

64

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a model of brevity for a deprecated skill: a single unambiguous redirect to `$code-review` with no wasted tokens. It earns top marks across all content dimensions precisely because it does one clear thing and does it efficiently.

DimensionReasoningScore

Conciseness

The body is a lean two-line deprecation plus a task placeholder, with no padding or explanation of concepts Claude already knows, matching 'lean and efficient; assumes Claude's competence.'

3 / 3

Actionability

It gives a concrete, executable directive ('Use `$code-review` directly for new review workflows when security concerns are in scope') pointing to a specific skill, matching 'fully executable... copy-paste ready' rather than vague direction.

3 / 3

Workflow Clarity

This is a single-action skill (do not invoke; route to `$code-review`) and the action is unambiguous, so per the simple-skills scoring note workflow clarity scores 3 without needing multi-step sequencing or validation checkpoints.

3 / 3

Progressive Disclosure

The skill is well under 50 lines, needs no external references, and is organized into a clear header and body, so per the simple-skills note progressive disclosure scores 3; no bundle files exist to require further structuring.

3 / 3

Total

12

/

12

Passed

Description

50%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description accurately flags deprecation and names the security-review domain, but it offers no concrete actions, a single thin trigger term, and no positive use-when guidance, leaving it at the mid-level across all dimensions. As a deprecation marker it functions, but as a capability description it is thin.

Suggestions

If the skill must remain discoverable, add a one-line positive capability summary (e.g., 'Reviews code for security vulnerabilities and risks') before the deprecation notice so the what is concrete.

Add a couple of natural trigger terms a user would say (e.g., 'security review, vulnerability audit, threat modeling') to improve trigger_term_quality even within a deprecation context.

Clarify the relationship to `$code-review` (e.g., 'folded into $code-review') so the distinctiveness/conflict distinction is explicit rather than implicit.

DimensionReasoningScore

Specificity

The description names the domain ("security review") but lists no concrete actions, matching the 'names domain and some actions, but not comprehensive' anchor rather than the multiple-specific-actions level 3 or the fully vague level 1.

2 / 3

Completeness

It conveys what the skill is ("Deprecated standalone security review skill") but provides no positive 'Use when...' trigger clause, so per the guideline a missing explicit trigger caps completeness at 2 rather than reaching the explicit-what-and-when level 3.

2 / 3

Trigger Term Quality

"security review" is a natural keyword a user might say, but it is the sole term, dominated by the deprecation framing, and missing common variations like security audit or vulnerability scan, fitting 'some relevant keywords but missing common variations.'

2 / 3

Distinctiveness Conflict Risk

"security review" is a recognizable niche, but the description explicitly overlaps with and routes to `$code-review`, fitting 'somewhat specific but could still overlap with similar skills' rather than a clearly distinct, conflict-free niche.

2 / 3

Total

8

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Yeachan-Heo/oh-my-codex
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.