CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

58

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/zh-TW/skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized and highly actionable, with concrete FAIL/PASS examples and per-topic validation checklists for each security area. Its weaknesses are length and redundancy (duplicated checklists, coverage of well-known practices) and the absence of any progressive disclosure — everything, including niche blockchain content, is inlined in one long file.

Suggestions

Deduplicate the checklists: keep either the per-section '驗證步驟' lists or the final '部署前安全檢查清單', not both, since they repeat the same items nearly verbatim.

Move the niche sections (區塊鏈安全/Solana, 安全測試) into references/ files linked from SKILL.md so the main file is a lean overview, and fix the non-executable examples (Solana verify import, @/lib/csrf placeholder).

Trim sections covering well-known practices (basic zod validation, npm audit usage) to checklist items only, keeping code examples for the non-obvious patterns (RLS policies, CSP headers).

DimensionReasoningScore

Conciseness

The body is mostly tight FAIL/PASS code contrasts and checklists with no padded prose, but at ~490 lines it extensively documents standard security practices Claude already knows (parameterized queries, httpOnly cookies, DOMPurify, npm audit), and the final '部署前安全檢查清單' largely duplicates the per-section '驗證步驟' checklists. Not 4 because the duplication and known-material length are noticeable; not 2 because there is no conceptual over-explanation of basics.

3 / 5

Actionability

Concrete, mostly executable examples throughout: zod schema validation, parameterized Supabase/$1 queries, RLS policies, DOMPurify sanitization, rate-limit configs, npm audit commands. Not 5 because some examples are not executable as written — `import { verify } from '@solana/web3.js'` is not a real export (correct API is nacl.sign.detached.verify), `@/lib/csrf` is an unexplained placeholder, and express-rate-limit middleware is mixed into Next.js-style route handlers; not 3 because the vast majority of code is copy-paste ready.

4 / 5

Workflow Clarity

Each topic section pairs FAIL/PASS examples with an explicit '驗證步驟' checklist, and the closing pre-deployment checklist aggregates checkpoints across all areas — validation gates are clearly present. Not 5 because no review sequence is defined and there is no fail→fix→recheck loop telling Claude what to do when a check fails; not 3 because checkpoints are explicit and per-topic, not merely implied.

4 / 5

Progressive Disclosure

A single ~490-line file with no references at all; domain-specific sections (區塊鏈安全/Solana, 安全測試) are inlined content that could live in separate reference files, though clear section headers keep navigation reasonable. Not 4 because nothing is split out despite the length; not 2 because the file is well-structured with headers, not a wall of text.

3 / 5

Total

14

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has a strong, explicit 'when' clause with several natural trigger terms, but the 'what' half is vague ('comprehensive security checklist and patterns') and does not name the concrete vulnerabilities or checks covered. It is clearly usable but sits below the top anchor on specificity and completeness.

Suggestions

Replace the vague 'Provides comprehensive security checklist and patterns' with concrete capabilities, e.g., 'Reviews code for SQL injection, XSS, CSRF, hardcoded secrets, and missing authorization checks, and provides FAIL/PASS patterns for each.'

Add natural synonyms and trigger words users actually say: 'auth', 'login', 'tokens', 'vulnerabilities', 'security audit', 'penetration-check my code'.

State the output of the skill (a per-topic verification checklist and a pre-deployment security checklist) so the 'what' is explicit.

DimensionReasoningScore

Specificity

"Provides comprehensive security checklist and patterns" names the domain but is generic about what the skill actually does; the enumerated items ("adding authentication, handling user input, working with secrets") are trigger conditions rather than concrete actions. It is not 4 because no specific capabilities (e.g., SQL injection, XSS, CSRF, secret-leak checks) are stated in the 'what', and not 2 because the domain plus trigger list give it more substance than a minimal one-liner.

3 / 5

Completeness

Both parts are explicitly present: an explicit when clause ("Use this skill when adding authentication... or implementing payment/sensitive features") and a what ("Provides comprehensive security checklist and patterns"). Not 5 because the 'what' is vague — 'comprehensive' and 'patterns' do not state what the checklist covers; not 3 because the when clause is explicit and multi-trigger, not weakly implied.

4 / 5

Trigger Term Quality

Good natural keywords users would say: "authentication", "user input", "secrets", "API endpoints", "payment", "sensitive features". Not 5 because common synonyms and specifics are missing: "auth", "login", "vulnerabilities", "security audit", "XSS", "SQL injection"; not 3 because coverage goes well beyond a single keyword.

4 / 5

Distinctiveness Conflict Risk

Clear security niche with distinct triggers (secrets, payments, API endpoints) that mostly avoids conflicting with general code or document skills. Not 5 because of moderate overlap risk with generic code-review or security-audit skills; not 3 because the trigger set is security-specific, not merely 'somewhat specific'.

4 / 5

Total

15

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.