CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

55

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strongly actionable checklist skill with consistent FAIL/PASS examples and verification steps per category, but it is a long monolithic file with redundant checklist layers, implicit workflow sequencing, and several stub code examples. Splitting deep-dive topics into reference files and deduplicating the checklists would improve both conciseness and navigation.

Suggestions

Deduplicate the per-section 'Verification Steps' against the 'Pre-Deployment Security Checklist' — either keep one consolidated gate checklist or have sections link to it.

Move niche or bulky material (Blockchain/Solana section, security-testing examples) into one-level-deep reference files (e.g. references/blockchain.md, references/testing.md) with clear pointers from the body.

Make the stub examples executable or explicitly justify them as patterns: '@/lib/csrf', 'getBalance', and the '@solana/web3.js' verify import reference undefined code as written.

DimensionReasoningScore

Conciseness

The body is mostly lean FAIL/PASS code and checklists with little concept explanation, but it is padded by redundancy and filler: each section's 'Verification Steps' checklist largely duplicates the 'Pre-Deployment Security Checklist', the Solana blockchain section is niche, and the closing 'Remember: Security is not optional...' paragraph adds nothing. This is 'mostly efficient but includes some unnecessary material that could be tightened' rather than 4's 'minor instances'.

3 / 5

Actionability

Nearly every section gives concrete, mostly executable guidance — zod validation schema, parameterized query with placeholder-syntax prose, Supabase RLS policies, CSP header config, rate-limit code, npm audit commands, and security test cases. Not 5 because several snippets are stubs referencing undefined helpers ('@/lib/csrf', 'getBalance', 'Transaction', the '@solana/web3.js' verify import), so they are not fully copy-paste ready.

4 / 5

Workflow Clarity

The content is organized as a per-topic catalog with verification checklists rather than a sequenced workflow: there is no explicit order of operations, no fix-and-recheck feedback loop, and the only sequencing signal is the 'Before ANY production deployment' pre-deployment gate. Validation checkpoints exist, so this sits at 3 ('checkpoints missing or implicit' in terms of an actual sequence) rather than 2, but not 4, which requires a clear sequence.

3 / 5

Progressive Disclosure

Section structure within SKILL.md is good (numbered categories, consistent FAIL/PASS/checklist pattern), but no bundle exists and everything is inlined in a ~500-line single file — the security-testing examples, the Solana section, and per-topic deep dives are candidates for one-level-deep reference files. This matches 'some structure but content that should be separate is inline' rather than 4, where bulk content lives in clearly signaled separate files.

3 / 5

Total

13

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit and concrete when-clause with good natural trigger coverage, but the what-side is thin — a single padded sentence about a 'checklist and patterns'. Strengthening the what with concrete capabilities and adding a few security-specific synonyms would lift it.

Suggestions

Replace the vague what-side ('Provides comprehensive security checklist and patterns') with concrete capabilities, e.g. 'Reviews code for hardcoded secrets, injection risks, missing authorization checks, and misconfigured security headers, and provides fail/pass patterns for each'.

Add natural trigger synonyms users would say — 'authorization', 'vulnerabilities', 'security audit', 'XSS', 'SQL injection' — to the when-clause.

Drop the filler word 'comprehensive'; it adds no information and reads as over-claiming.

DimensionReasoningScore

Specificity

The what-side is a single generic action — 'Provides comprehensive security checklist and patterns' — with 'comprehensive' acting as padding; the concrete domain list (authentication, secrets, payments) lives only on the trigger side. This matches 'names domain and 1-2 concrete actions, but not comprehensive' rather than 4, which requires several specific listed actions.

3 / 5

Completeness

Both what ('Provides comprehensive security checklist and patterns') and when ('Use this skill when adding authentication...') are explicitly present, and the when-clause is concrete. Not 5 because the what-side is weak — 'checklist and patterns' is vague next to the 5-anchor's fully concrete both-parts example.

4 / 5

Trigger Term Quality

'adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features' covers natural phrases users would say. Not 5 because common synonyms like 'authorization', 'security audit', 'vulnerabilities', or named injection attacks (SQL injection, XSS) are missing.

4 / 5

Distinctiveness Conflict Risk

Security review occupies a clear niche with distinct triggers (secrets, payment features, auth), so it is mostly distinguishable from sibling skills. Not 5 because broad triggers like 'handling user input' and 'creating API endpoints' could fire on routine, non-security coding work.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (512 lines); consider splitting into references/ and linking

Warning

metadata_version

'metadata.version' is missing

Warning

Total

14

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.