CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/zh-CN/skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a strong, actionable security reference: concrete FAIL/PASS code pairs, per-category verification checklists, and executable test examples, with virtually no padding. Its main weakness is structure — everything lives in one ~520-line file with no progressive disclosure or reference files, and there is no ordered review workflow or fix-recheck loop tying the checklists together.

Suggestions

Split niche sections (Solana/blockchain security, Supabase RLS, framework-specific CSP config) into reference files under references/ and keep SKILL.md as the overview with well-signaled one-level-deep links.

Add an ordered review workflow (e.g. 1. scan secrets → 2. input/SQL → 3. auth → 4. re-check after fixes) with a fix-and-revalidate loop, instead of only parallel category checklists.

Deduplicate the pre-deployment checklist against the per-category verification steps, or reframe it as a one-line summary per category that links back to the detailed section.

DimensionReasoningScore

Conciseness

The body is dense, well-commented FAIL/PASS code with no explanations of concepts Claude already knows, and it assumes competence throughout. It is not a 5 because the final pre-deployment checklist largely repeats the per-category verification steps, which could be trimmed or deduplicated.

4 / 5

Actionability

Every section provides concrete, mostly executable code — zod validation schemas, parameterized queries, RLS SQL policies, npm audit commands — matching the 'mostly executable with minor gaps' anchor. Not a 5 because several snippets reference undefined or illustrative helpers ('@/lib/csrf', getBalance, the Solana verify import) that are not copy-paste ready.

4 / 5

Workflow Clarity

Each category ends with explicit '验证步骤' checkboxes and a final pre-deployment gate provides a summary checkpoint. Not a 5 because there is no overall review sequence (what order to check things in) and no fix-and-recheck feedback loop; not a 3 because per-category validation checkpoints are explicit and complete.

4 / 5

Progressive Disclosure

The single file has clear section headers and is navigable, but it is a ~520-line monolith with no bundle files at all — niche content (Solana blockchain security, Supabase RLS, Next.js-specific CSP) that clearly belongs in separate reference files is inlined in SKILL.md, matching the 'structure present but content that should be separate is inline' anchor.

3 / 5

Total

15

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has a strong, explicit trigger clause with five concrete activation conditions, which is its main strength. Its weakness is a vague 'what' — 'comprehensive security checklist and patterns' says little about the actual coverage (10 vulnerability categories, FAIL/PASS patterns, pre-deploy checklist). Trigger vocabulary could also add common synonyms like security audit, vulnerability, or OWASP.

Suggestions

Make the 'what' concrete by listing the actual capabilities, e.g. 'Reviews code for 10 vulnerability categories (secrets management, injection, XSS/CSRF, auth, rate limiting, ...) with FAIL/PASS code patterns and a pre-deployment checklist'.

Add natural trigger synonyms users would say: security review, vulnerability, security audit, hardening, OWASP, penetration-check.

Keep the existing '在...时使用此技能' trigger clause — it is the strongest part of the description.

DimensionReasoningScore

Specificity

The description names the security domain and its deliverables ("提供全面的安全检查清单和模式" — comprehensive security checklist and patterns) but never enumerates the concrete actions it covers (e.g. injection, XSS, auth flaws), matching the anchor for domain plus 1-2 actions rather than a list of several specific actions.

3 / 5

Completeness

Both parts are present: an explicit 'when' ("在...时使用此技能" with five concrete triggers) and a 'what' ("提供全面的安全检查清单和模式"). It is not a 5 because the 'what' is generic — it does not concretely state what the skill does beyond 'checklist and patterns'.

4 / 5

Trigger Term Quality

Natural trigger phrases users would actually say are present ("添加身份验证", "处理用户输入", "机密信息", "API端点", "支付/敏感功能"), but common variations such as "security review", "vulnerability", "audit", or "OWASP" are missing, so coverage is good rather than comprehensive.

4 / 5

Distinctiveness Conflict Risk

The security-review niche with its specific triggers (auth, secrets, payments, API endpoints) is mostly distinct, with only minor overlap risk against general code-review or dependency-management skills.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (528 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.