CtrlK
BlogDocsLog inGet started
Tessl Logo

security-scan

AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。

81

2.25x
Quality

73%

Does it follow best practices?

Impact

97%

2.25x

Average score across 3 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./docs/ja-JP/skills/security-scan/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, token-efficient instruction body built almost entirely from executable commands with clear section organization. Its main weakness is workflow clarity around the --fix flow, which mutates configuration files without an explicit verification/re-scan checkpoint.

Suggestions

Add a verification loop after the --fix step, e.g. 'Re-run npx ecc-agentshield scan after fixing and confirm the grade improved; if findings remain, address manual-only suggestions individually', to lift workflow clarity.

Present the core flow (前提条件 → スキャン → 出力確認 → 修正 → 再スキャン) as an explicit numbered sequence rather than relying on section order alone.

Move the severity-level table and 結果の解釈 reference material into a separate reference file (e.g. findings.md) and link to it from SKILL.md to improve progressive disclosure.

DimensionReasoningScore

Conciseness

Lean, command-first sections with no explanations of concepts Claude already knows; scan targets and severity grades are table-formatted. Minor trimmable material exists — the 結果の解釈 section largely restates what the tool's own report output already shows.

4 / 5

Actionability

Every section provides copy-paste-ready commands ('npx ecc-agentshield scan --path /path/to/.claude', '--format json', '--fix', the GitHub Action YAML), covering install, scan, output formats, auto-fix, deep analysis, and init. The only placeholder is ANTHROPIC_API_KEY=your-key, which is appropriate.

5 / 5

Workflow Clarity

Sections follow a sensible implicit order (前提条件 → 使用方法 → 出力 → 解釈 → 修正) but there is no explicit step sequence, and the --fix flow — which modifies settings.json, CLAUDE.md, and permission files — has no verification step such as re-running the scan to confirm the grade improved. Per the validation cap for workflows that modify configuration in bulk, workflow clarity cannot exceed 3.

3 / 5

Progressive Disclosure

A single-file skill (no references/, scripts/, or assets/ bundle exists, and no in-body file references are broken) with well-organized sections and clear headers. Minor gap: the severity table and 結果の解釈 reference material could live in a separate reference file to keep SKILL.md as a leaner overview.

4 / 5

Total

16

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-targeted description that clearly states what it does and which files it checks, written in proper third-person voice. Its main gap is the complete absence of a 'Use when…' trigger clause, which limits when it would be surfaced.

Suggestions

Append an explicit trigger clause such as 'Use when auditing Claude Code configuration before committing changes, onboarding a repo with a .claude/ directory, or when the user mentions security vulnerabilities, misconfigurations, or prompt injection in Claude Code settings.'

Mention the additional concrete capabilities the tool offers (auto-fix with --fix, --format json/markdown/html reports, GitHub Action) to lift specificity from 4 to 5.

Add natural synonyms like '監査 (audit)', '権限 (permissions)', and 'セキュリティチェック' to broaden trigger term coverage.

DimensionReasoningScore

Specificity

Names a concrete tool and target ('AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)') and enumerates specific objects checked (CLAUDE.md, settings.json, MCP サーバー、フック、エージェント定義) plus issue classes (脆弱性、設定ミス、インジェクションリスク). Falls short of a 5 because the only actions stated are 'スキャンします/チェックします' — capabilities like auto-fix, init, and report generation are not mentioned.

4 / 5

Completeness

The 'what' is clear and concrete, but the description contains no 'Use when…' clause or equivalent trigger guidance, which caps completeness at 3 per the judging guidelines. Not a 4 because the 'when' is entirely absent rather than merely implicit or under-specified.

3 / 5

Trigger Term Quality

Contains natural phrases users would say when needing this skill: 'セキュリティ脆弱性', '設定ミス', 'MCP サーバー', 'フック', 'settings.json'. A few natural synonyms such as '監査 (audit)', '権限 (permissions)', or 'セキュリティチェック' are missing, keeping it just below comprehensive coverage.

4 / 5

Distinctiveness Conflict Risk

A clear niche — auditing Claude Code's own .claude/ configuration with a named tool — with file-level specifics that no generic skill would match. Conflict risk with other skills is minimal; only a very generic security-review skill could marginally overlap.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.