CtrlK
BlogDocsLog inGet started
Tessl Logo

security-scan

使用AgentShield扫描您的Claude代码配置(.claude/目录),以发现安全漏洞、配置错误和注入风险。检查CLAUDE.md、settings.json、MCP服务器、钩子和代理定义。

82

1.72x
Quality

73%

Does it follow best practices?

Impact

100%

1.72x

Average score across 3 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./docs/zh-CN/skills/security-scan/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, highly actionable CLI-wrapper skill: every mode of the tool is documented with executable commands, the findings-interpretation section gives concrete triage guidance, and structure is clean throughout. The only real gaps are a missing post-fix verification checkpoint and minor trimmable content (a version-specific section title and the grade table).

DimensionReasoningScore

Conciseness

The body is efficient — compact command blocks with inline comments, tables, and no explanation of concepts Claude already knows — but the 'Opus 4.6 深度分析' section title hard-codes a time-sensitive model version and the A–F grade table restates tool output, both mildly trimmable, so it does not reach the lean 'every token earns its place' anchor at 5.

4 / 5

Actionability

Fully executable, copy-paste-ready commands cover every common case: version check and install, basic scan, --path, --min-severity, all four --format variants, --fix, --opus --stream, init, and a complete GitHub Actions YAML snippet. Specific examples cover the common cases with no gaps.

5 / 5

Workflow Clarity

A clear sequence is present: prerequisite check/install → scan → interpret findings via the severity grades and prioritized findings triage (立即修复 → 生产前修复 → 建议修复 → 了解情况) → targeted --fix. It stops short of 5 because there is no explicit re-scan/verification checkpoint after the config-mutating --fix step (e.g. 're-run scan and confirm the grade improved').

4 / 5

Progressive Disclosure

There are no bundle files (references/, scripts/, assets/ do not exist), and the single-file body is well organized with clear sections that stand on their own — matching the 'good structure, most content appropriately placed' anchor. It is not 5 because ~170 lines of detail (the severity grade table and findings-interpretation catalog) could arguably be split into a reference file, keeping SKILL.md a leaner overview.

4 / 5

Total

17

/

20

Passed

Description

65%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-differentiated description that names the tool, the target directory, the class of findings, and the exact files checked. Its main weaknesses are the missing 'when to use' trigger clause and second-person phrasing, both of which cost it under the rubric guidelines.

Suggestions

Add an explicit trigger clause, e.g. '新项目设置、修改 .claude 配置后、或用户要求安全审计/加固 Claude Code 配置时使用' (Use when setting up a project, after modifying .claude config, or when the user asks for a security audit).

Rewrite in third person to remove '您的' (your), e.g. 'Scans the Claude Code configuration (.claude/ directory) for security vulnerabilities…', restoring the specificity point lost to the second-person penalty.

Include a few natural synonyms users might say, such as '安全审计' (security audit) or '加固' (hardening), to broaden trigger coverage.

DimensionReasoningScore

Specificity

The description lists several concrete actions ("扫描…以发现安全漏洞、配置错误和注入风险" and "检查CLAUDE.md、settings.json、MCP服务器、钩子和代理定义") which would anchor at 4, but it uses second person voice ("扫描您的Claude代码配置" — 'scan your configuration'), which the judging guidelines penalize by reducing specificity by 1.

3 / 5

Completeness

The 'what' is clear and specific (scan Claude Code config for vulnerabilities, misconfigurations, and injection risks), but there is no 'Use when…' clause or equivalent explicit trigger guidance, which per the judging guidelines caps completeness at 3. It is not a 2 because the 'what' is concrete rather than vague.

3 / 5

Trigger Term Quality

Good keyword coverage with natural terms users would say (scan/扫描, security vulnerabilities/安全漏洞, 配置/config, plus concrete file names CLAUDE.md, settings.json, MCP, hooks, agents), but common synonyms such as 'audit/安全审计' or 'harden/加固' are missing, so it falls short of the comprehensive-synonyms anchor at 5.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear niche — security auditing of the Claude Code `.claude/` configuration specifically — with a named tool (AgentShield) and concrete file targets (CLAUDE.md, settings.json, mcp.json, hooks, agents), giving it distinct triggers and minimal conflict risk with other skills.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.