CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

48

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./.kiro/skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is rich with concrete, mostly copy-paste-ready security patterns and per-topic verification checklists, which is its main strength. But it is a monolithic ~490-line reference that re-teaches widely known practices, duplicates its checklists in a pre-deployment section, and offers no sequenced review workflow or external reference files. It works as a lookup manual but is expensive to load and weak as a process guide.

Suggestions

Cut or compress sections that re-state knowledge Claude already has (parameterized queries, DOMPurify, cookie flags), and deduplicate the per-topic "Verification Steps" against the final "Pre-Deployment Security Checklist" — keep one consolidated checklist.

Split the SKILL.md into an overview plus one-level-deep references: move the Solana/blockchain section and the per-topic pattern libraries (e.g., REFERENCES/auth.md, REFERENCES/blockchain.md) out of the main file.

Replace the topic list with a sequenced workflow (review scope → run checks → triage findings → fix → re-run security tests) and fix the non-executable examples — provide the `@/lib/csrf` implementation or use a real library, and correct the `@solana/web3.js` signature-verification API.

DimensionReasoningScore

Conciseness

The ~490-line body re-teaches security practices Claude already knows (parameterized queries, DOMPurify sanitization, httpOnly cookies, express-rate-limit), and the "Pre-Deployment Security Checklist" duplicates every per-topic "Verification Steps" list. This is noticeably padded (anchor 2) rather than mostly efficient with incidental slack (anchor 3).

2 / 5

Actionability

Concrete, mostly executable code throughout — zod schemas, file-upload validation, Supabase RLS policies, rate-limit configs, and security tests. Minor gaps keep it below anchor 5: the CSRF example imports a presumed `@/lib/csrf` helper that isn't provided, and the Solana `verify(...)` call does not match `@solana/web3.js`'s actual API signature.

4 / 5

Workflow Clarity

The body is organized topic-by-topic as a reference rather than a sequenced review workflow — there is no explicit order (review → triage findings → fix → re-run tests) and no feedback loop for remediation. Verification checkboxes exist, but the sequence is only implicit, fitting anchor 3 rather than 4 ("Clear sequence with most checkpoints present").

3 / 5

Progressive Disclosure

There are no bundle files at all; all ~490 lines live in SKILL.md with decent section headers, but content that clearly belongs in separate references is inlined — notably the niche Solana/blockchain section and the full per-topic pattern libraries. Fits anchor 3 ("Some structure but could be better organized; content that should be separate is inline"), not 2 (structure is reasonable) and not 4 (nothing is split out).

3 / 5

Total

12

/

20

Passed

Description

52%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has a strong, explicit activation clause with natural trigger phrases, but the capability statement is generic ("Provides comprehensive security checklist and patterns") and the triggers are broad enough to fire on routine feature work. Overall it reads as a domain-labeled skill without a crisp statement of what it actually does.

Suggestions

Replace "Provides comprehensive security checklist and patterns" with concrete outcomes, e.g., "Reviews code for vulnerabilities (SQL injection, XSS, CSRF, secrets exposure) and applies secure patterns for auth, input validation, and rate limiting."

Add the trigger terms users naturally reach for: "security review", "vulnerability", "audit code", "harden", "OWASP".

Narrow the triggers to security intent — "creating API endpoints" and "handling user input" alone would activate on almost any feature task and conflict with general coding skills.

DimensionReasoningScore

Specificity

The only stated action is "Provides comprehensive security checklist and patterns", which is generic and buzzword-adjacent ("comprehensive"); no concrete verbs like "reviews code for vulnerabilities" or "audits secrets handling" are given. This matches anchor 2 ("Names the domain but actions are minimal or generic") rather than 3, which requires at least one concrete, specific action.

2 / 5

Completeness

The "when" is explicit and strong ("Use this skill when adding authentication, handling user input..."), but the "what" ("Provides comprehensive security checklist and patterns") is vague — it never states outcomes such as identifying vulnerabilities or hardening code. Both parts are present (ruling out 2-3 structure), but the weak "what" keeps it below anchor 4.

3 / 5

Trigger Term Quality

"adding authentication, handling user input, working with secrets, creating API endpoints, implementing payment/sensitive features" are natural phrases users would say. However common variations are missing — "security review", "audit", "vulnerability", "harden", "OWASP" — so it fits anchor 4 ("Good keyword coverage; a few natural terms missing") rather than 5.

4 / 5

Distinctiveness Conflict Risk

The security domain anchors it somewhat, but triggers like "handling user input" and "creating API endpoints" would fire on nearly all ordinary feature work, and the name "security-review" collides with an existing built-in security-review skill. Fits anchor 3 ("Somewhat specific but could still overlap with similar skills"), not 4, since the overlap risk extends beyond closely related skills.

3 / 5

Total

12

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.