CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

52

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly concrete and actionable as a per-topic pattern reference, with real code and per-area verification checkboxes. Its weaknesses are volume and structure: ~490 inline lines largely restating security fundamentals Claude already knows, with no progressive disclosure into reference files and no ordered workflow for actually executing a review.

Suggestions

Cut the body to a lean core checklist and move domain-specific deep dives (Solana wallet verification, Supabase RLS policies, CSP header recipes) into references/ files linked one level deep, e.g. 'See [blockchain.md](references/blockchain.md)'.

Add a short ordered review workflow with executable discovery commands (e.g., `grep -rE "(api[_-]?key|secret|password)" --include="*.ts"`, `gitleaks detect`, `npm audit --production`) so the model knows how to find issues, not just what to check.

Delete the duplicated verification lists: fold the per-area 'Verification Steps' into the single Pre-Deployment checklist, and trim code examples to the one that best illustrates each failure/pass pair.

Fix or remove non-executable examples — the `@solana/web3.js` `verify` import and the `@/lib/csrf` module do not exist, which undermines the copy-paste reliability of the skill.

DimensionReasoningScore

Conciseness

At ~490 lines, the body extensively re-teaches standard security knowledge Claude already has — JWT-in-httpOnly-cookies, parameterized queries, DOMPurify, express-rate-limit, npm audit — with several padded sections and redundancy (per-area 'Verification Steps' duplicated almost verbatim by the 'Pre-Deployment Security Checklist'). It is above score 1 because there is no conceptual filler prose (no 'what is XSS' explanations), but noticeably below the midpoint because most of the volume adds little beyond Claude's existing knowledge.

2 / 5

Actionability

Nearly every section gives copy-paste-ready TypeScript/SQL/bash (zod schemas, Supabase RLS policies, Set-Cookie headers, npm audit commands) plus checkbox verification steps. Not a 5 because some examples are not actually executable: `import { verify } from '@solana/web3.js'` (no such export — wallet verification needs tweetnacl), the invented `@/lib/csrf` module, and a `Transaction` object with nonexistent `.to`/`.amount` fields.

4 / 5

Workflow Clarity

There is a usable structure — activation triggers, ten themed checklist areas, a testing section, and a final pre-deployment checklist — but no sequenced process for conducting a review (how to find hardcoded secrets, e.g. grep/secret-scanning commands, in what order to check things). It matches 'steps/checks listed but validation gaps; checkpoints implicit' rather than score 4, which would require an explicit ordered review workflow with checkpoints.

3 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are absent), so everything is inline in one 490-line file. Section headers are clear and the structure is not minimal (so above score 2), but specialty content that clearly belongs in separate reference files — the Solana blockchain section, Supabase RLS SQL — is inlined in a general-purpose checklist, matching 'some structure but content that should be separate is inline'.

3 / 5

Total

12

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid trigger-focused description with an explicit and multi-condition 'Use when' clause, but the capability half is thin — 'comprehensive security checklist and patterns' tells the model little about what the skill actually does. Broad triggers ('handling user input', 'creating API endpoints') also raise false-positive activation risk.

Suggestions

Replace 'Provides comprehensive security checklist and patterns' with concrete actions, e.g., 'Audits code for vulnerabilities — injection, XSS, CSRF, auth flaws, secret exposure — against a per-area checklist with pass/fail code examples.'

Sharpen the broad triggers so they only fire for security work: e.g., 'handling user input validation' instead of 'handling user input', and 'exposing new API endpoints' instead of 'creating API endpoints'.

Add the natural vocabulary users actually invoke for this task: 'security review', 'vulnerability', 'authorization', 'pen-test my changes'.

DimensionReasoningScore

Specificity

The 'what' is limited to "Provides comprehensive security checklist and patterns" — 'comprehensive' is filler and the only concrete deliverables named are a checklist and patterns. The domain (security) is clearly named, matching the anchor 'names domain and 1-2 concrete actions, but not comprehensive'; it is above score 2 because a deliverable is named, and below 4 because no specific actions (e.g., 'audit code for injection flaws, verify secret handling') are listed.

3 / 5

Completeness

Both parts are present: an explicit 'when' ("Use this skill when adding authentication... creating API endpoints") and a 'what' ("Provides comprehensive security checklist and patterns"). It is not a 5 because the 'what' is generic — it never says what the skill actually does (review code for vulnerabilities against a checklist) — and not a 3 because the 'when' is explicit and multi-trigger, not weakly implied.

4 / 5

Trigger Term Quality

Phrases like "adding authentication", "handling user input", "working with secrets", "creating API endpoints", "implementing payment/sensitive features" are natural terms users say when writing this kind of code. Not a 5 because common variations are missing — 'authorization', 'login', 'vulnerability', 'security audit/review', 'XSS' — and no file/tech extensions are given.

4 / 5

Distinctiveness Conflict Risk

The security niche is distinguishable from sibling skills, but triggers like "handling user input" and "creating API endpoints" fire on a large fraction of ordinary coding tasks, creating real overlap risk with general coding/review skills. It sits between 'very broad; high overlap risk' (2) and 'mostly distinct; minor overlap risk' (4) — the security framing helps, but the two broadest triggers are not security-specific.

3 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.