CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。

66

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/ja-JP/skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with comprehensive executable security patterns and per-section validation checkboxes. Its main weakness is monolithic structure: everything lives in one file with no progressive disclosure to separate reference materials.

Suggestions

Move the detailed per-control code examples into reference files (e.g., references/auth.md, references/input-validation.md) and keep SKILL.md as an overview pointing to them, improving progressive disclosure.

Trim the opening restatement (このスキルは…) and consolidate redundant prose to tighten conciseness.

Add an explicit top-level validate→fix→retry workflow so the per-section checklists feed into one clear feedback loop.

DimensionReasoningScore

Conciseness

The body is mostly efficient with executable examples, but the intro restatement (このスキルは…) and a few explanatory prose lines could be trimmed; it is comprehensive yet carries some unnecessary padding.

3 / 5

Actionability

Provides fully executable TypeScript, SQL, and bash examples with concrete FAIL/PASS contrasts covering the common security cases copy-paste ready.

5 / 5

Workflow Clarity

Each section includes explicit validation checkboxes (検証ステップ) and a deploy-preflight checklist with clear structure, though there is no single top-level validate→fix→retry loop tying the workflow together.

4 / 5

Progressive Disclosure

The file is a well-organized single document with clear section headers and checklists, but at ~490 lines with no external reference files or bundle structure it inlines content that could be split out.

3 / 5

Total

15

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong, third-person, and clearly states both capabilities and concrete trigger conditions for a security review skill. It avoids vague fluff and would be triggered naturally in the right contexts.

DimensionReasoningScore

Specificity

Lists several concrete trigger contexts (認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能) and states it provides a comprehensive security checklist and patterns, with only minor coverage gaps.

4 / 5

Completeness

Explicitly answers both 'what' (包括的なセキュリティチェックリストとパターンを提供) and 'when' (…実装時にこのスキルを使用します) with concrete trigger phrases.

5 / 5

Trigger Term Quality

Uses natural phrases users would say (認証, ユーザー入力, APIエンドポイント, 支払い) but lacks synonyms or file-extension variants, stopping just short of comprehensive coverage.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear security-review niche with distinct, specific triggers (secrets, auth, payments) that minimize overlap with unrelated skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.