CtrlK
BlogDocsLog inGet started
Tessl Logo

senior-security

Use when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the right specialist skill (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review). This skill owns threat modeling; everything else routes to a sibling.

80

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a model skill document: terse and competence-assuming, with executable commands backed by real scripts, a sequenced workflow including an explicit verification/done-signal gate, and a clean one-level-deep reference structure. No improvements needed.

DimensionReasoningScore

Conciseness

Lean and information-dense — the STRIDE matrix, the terse 'S=Spoofing→authn...' mapping, and '20+ patterns (AWS keys, GitHub tokens, private keys)' all assume Claude's competence with no padding or re-explanation of known concepts.

5 / 5

Actionability

Fully executable, copy-paste-ready commands verified against real scripts with matching CLI signatures: 'python3 scripts/threat_modeler.py --component "User Authentication" --assets "credentials,sessions" --json --output threats.json' and the secret_scanner invocation, plus concrete output-consumption guidance (sort by DREAD ≥7).

5 / 5

Workflow Clarity

Five-step workflow with an explicit verification gate and feedback loop — 'every threat with DREAD ≥ 7 has an owner + mitigation ... Re-run both tools after mitigations land — that re-run is the done signal' — satisfying the destructive/batch validation requirement.

5 / 5

Progressive Disclosure

Clear overview with well-signaled one-level-deep references — the '## References (load on demand)' table links three real files (threat-modeling-guide, security-architecture-patterns, cryptography-implementation, all verified present) with content summaries and no nested indirection.

5 / 5

Total

20

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it states concrete owned actions, enumerates natural trigger terms, explicitly answers both 'what' and 'when', and draws a crisp boundary against sibling skills to avoid routing conflicts. No changes needed.

DimensionReasoningScore

Specificity

Names the domain and multiple concrete actions — 'STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan' plus 'routing to the right specialist skill' — with comprehensive coverage of both owned actions and routed lanes.

5 / 5

Completeness

Explicitly answers both: an explicit 'Use when the user asks for...' trigger clause (when) and 'This skill owns threat modeling; everything else routes to a sibling' plus the action list (what), with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural terms a security requester would say — 'STRIDE threat modeling', 'DREAD risk scoring', 'secret scan', and the full lane list (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review).

5 / 5

Distinctiveness Conflict Risk

Clear niche (threat modeling + routing) with an explicit boundary — 'This skill owns threat modeling; everything else routes to a sibling' — that disambiguates it from sibling skills, giving minimal conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.