CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

How to review PRs for security — credentials, injection, workflow permissions, supply chain, git operation safety

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.copilot/skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, highly actionable single-file skill: concrete grep targets, worked findings with severity and fixes, and a structured output template make it immediately usable. Its weaknesses are mild over-explanation of well-known security concepts, some redundancy between Patterns and Anti-Patterns, and no progressive disclosure — all detail is inlined in one long file with no reference layer.

Suggestions

Split the six worked Examples into a references/examples.md and keep 1-2 inline, adding one-level-deep pointers to reduce the ~260-line monolith.

Trim explanations of concepts Claude already knows (why exec is injectable, generic path traversal theory) down to the project-specific rule or pattern to check.

Add a brief validation step before issuing the verdict, e.g. 'confirm all ten pattern categories were checked and every finding has File(s), Risk, and Fix fields.'

DimensionReasoningScore

Conciseness

The checklist format is mostly token-efficient, but the body re-explains concepts Claude already knows (e.g. 'exec uses a shell and is vulnerable to injection', generic path traversal explanation) and partially repeats the Patterns content in the Anti-Patterns section. It fits 'mostly efficient but includes some unnecessary explanation or could be tightened'.

3 / 5

Actionability

The content is fully executable: exact patterns to grep for ('exec(`git commit -m "${userMessage}"`)', 'GITHUB_TOKEN', 'git add .'), six worked findings each with severity, risk, and specific fix (e.g. 'Use execFile('git', ['commit', '-m', commitMessage])'), and a copy-paste review output template. This matches the 'fully executable, copy-paste ready' anchor.

5 / 5

Workflow Clarity

The ten numbered pattern sections plus the mandated Output Format give the review a clear sequence and a structured checkpoint (verdict + severity-tiered findings), and each pattern has its own checklist. It falls short of a 5 because there is no explicit validate-then-iterate loop (e.g. re-checking a fix or confirming coverage of all ten categories before issuing a verdict).

4 / 5

Progressive Disclosure

No bundle files exist (no references/, scripts/, or assets/ directories), so everything — 10 pattern sections, 6 examples, and the output format — is inlined in a single ~260-line file. Section headers make it navigable, but content that could live in separate one-level-deep references (worked examples, per-topic checklists) is inlined with no references at all, matching 'some structure but could be better organized'.

3 / 5

Total

15

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A focused, topic-rich description that clearly conveys the security-review domain with several distinct coverage areas and natural trigger terms. Its main weakness is the absence of an explicit 'Use when...' clause, leaving the invocation conditions only weakly implied and capping completeness.

Suggestions

Add an explicit trigger clause, e.g. 'Use when reviewing a PR that touches credentials, workflows, child processes, dependencies, or git operations.'

Include a few more natural synonyms users would say — 'secrets', 'tokens', 'vulnerabilities', 'audit' — alongside the existing topic list.

Lead with the action in a third-person imperative form ('Reviews PRs for security issues...') to sharpen the 'what' and reduce overlap with generic PR-review skills.

DimensionReasoningScore

Specificity

The description names the domain ('review PRs for security') and lists several concrete capability areas ('credentials, injection, workflow permissions, supply chain, git operation safety'), but describes a single action verb with a topic list rather than multiple distinct concrete actions, so it fits the 'several specific actions, minor gaps' anchor rather than the comprehensive anchor.

4 / 5

Completeness

The 'what' is clear ('How to review PRs for security'), but there is no 'Use when...' clause or equivalent explicit trigger guidance — 'when' is only weakly implied by 'review PRs'. Per the judging guidelines, a missing 'Use when...' clause caps completeness at 3.

3 / 5

Trigger Term Quality

Natural phrases like 'review PRs', 'security', 'credentials', 'injection', and 'supply chain' match what a user would actually say when needing this skill, but common synonyms such as 'secrets', 'vulnerabilities', 'tokens', or 'audit' are absent. This is good but not comprehensive coverage, matching the 'a few natural terms missing' anchor.

4 / 5

Distinctiveness Conflict Risk

'for security' plus the distinctive topic list (workflow permissions, supply chain, git operation safety) carves out a clear niche from general code-review skills, but the opening 'How to review PRs' still overlaps with generic PR-review skills, so it fits 'mostly distinct; minor overlap risk' rather than the minimal-conflict anchor.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
bradygaster/squad
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.