CtrlK
BlogDocsLog inGet started
Tessl Logo

chatto-security-review

Perform a comprehensive security review of the Chatto codebase. Launch multiple exploration agents in parallel to examine different security aspects, then have an adversarial reviewer verify and challenge the findings.

69

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a tightly written, highly actionable multi-agent orchestration recipe with a clear phased workflow, explicit verification/adversarial feedback loops, and well-organized sections. It assumes Claude's expertise and gives copy-paste-ready specifics throughout.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — it enumerates attack surfaces and key file paths without explaining what XSS, CSP, or IDOR are, and every section earns its place.

3 / 3

Actionability

Provides concrete, executable guidance: exact agent counts (5 parallel + 1 adversarial), subagent_type, per-agent focus areas, cited key file paths, specific output file paths, and enumerated severity/verdict labels (CONFIRMED, FALSE POSITIVE, etc.).

3 / 3

Workflow Clarity

A clear four-phase sequence with explicit validation checkpoints — the adversarial Phase 3 verifies every finding against source code, challenges severity, checks for false positives, and supports adding new findings, forming a strong feedback loop.

3 / 3

Progressive Disclosure

Single-file skill (~75 lines) with no bundle files present; it is well-organized into clearly labeled phases and a 'Known Good Patterns' section, which the rubric permits to score 3 for a self-contained, well-structured skill.

3 / 3

Total

12

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly conveys a specific, multi-step security-review methodology but omits an explicit 'Use when...' trigger and under-covers natural trigger terms users might actually say. It is distinctive and actionable, just not maximally triggerable.

Suggestions

Add an explicit trigger clause such as 'Use when the user asks for a security review, security audit, or vulnerability assessment of the Chatto codebase.'

Broaden trigger-term coverage to include natural synonyms users would say, e.g. 'security audit', 'vulnerabilities', 'pentest', or 'threat model'.

Keep the third-person voice (already correct) but tighten the opening so the trigger guidance reads as a distinct clause rather than being implied.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Perform a comprehensive security review', 'Launch multiple exploration agents in parallel', and 'have an adversarial reviewer verify and challenge the findings' — rather than vague abstractions.

3 / 3

Completeness

Clearly states what the skill does (multi-agent security review with adversarial verification) but lacks an explicit 'Use when...' trigger clause, so the 'when' guidance is only implied — capping completeness at 2 per the rubric.

2 / 3

Trigger Term Quality

Contains relevant natural terms like 'security review' and 'security aspects', but omits common variations users would say such as 'security audit', 'vulnerabilities', or 'pentest', giving only partial coverage.

2 / 3

Distinctiveness Conflict Risk

The niche is clearly bounded ('security review of the Chatto codebase' with a multi-agent adversarial methodology), making it unlikely to trigger for unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
chattocorp/chatto
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.