CtrlK
BlogDocsLog inGet started
Tessl Logo

security-audit

Security audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

62%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-sequenced, validation-rich methodology overview with strong workflow clarity, but it is prose-heavy in places and critically depends on companion files that are not present in the bundle, weakening both actionability and progressive disclosure.

Suggestions

Ship the referenced bundle files (RECONNAISSANCE.md, HUNTING.md, ATTACK-CLASSES.md, the domain companions, VALIDATION-AND-REPORTING.md, report-schema.json, validate-findings.cjs) under references/ or alongside SKILL.md so the one-level-deep links resolve.

Tighten the Core Principles prose — e.g. condense the dynamic-confirmation and comparables paragraphs into bullet points — to lift conciseness without losing the methodology.

Inline at least one concrete executable snippet (e.g. a minimal findings.json skeleton or a validate-findings.cjs invocation) so the body is actionable even before the companion files are opened.

DimensionReasoningScore

Conciseness

It assumes Claude's competence and does not explain basic vulnerability concepts, but several prose blocks (dynamic-confirmation paragraph, comparables discussion, the 10-item anti-patterns list) could be tightened; mostly efficient with some padding.

2 / 3

Actionability

The severity table, validation bar, and phase assignments are concrete, but the actual executable methodology lives in referenced files (HUNTING.md, RECONNAISSANCE.md, etc.) that do not exist in the bundle, leaving the body's own guidance incomplete.

2 / 3

Workflow Clarity

All six phases are explicitly sequenced in order with dedicated validation checkpoints (Phase 3 consolidate/disprove, Phase 6 verify) and a feedback loop, matching the clear-sequence-with-validation anchor.

3 / 3

Progressive Disclosure

References are clearly signaled and one level deep in the workflow overview, but every cited companion file (RECONNAISSANCE.md, HUNTING.md, ATTACK-CLASSES.md, the domain companions, report-schema.json, validate-findings.cjs) is absent from the bundle, so the disclosure structure is broken in practice.

2 / 3

Total

9

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that covers what, when, and scope with concrete actions and natural trigger terms. It also usefully bounds scope to exploitable issues, sharpening trigger matching.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('find security bugs, do a security review, audit for vulnerabilities, or pen-test the code') plus specific target types ('web apps, APIs, services, CLI tools, libraries, daemons'), matching the multi-action anchor.

3 / 3

Completeness

Explicitly answers both what ('Security audit of a codebase — web apps, APIs, services...') and when via an explicit 'Use when asked to find security bugs...' trigger clause.

3 / 3

Trigger Term Quality

Natural phrases a user would actually say are well covered — 'find security bugs', 'security review', 'audit for vulnerabilities', 'pen-test the code' — with no jargon-only or generic terms.

3 / 3

Distinctiveness Conflict Risk

Clear niche (exploitable security auditing) with distinct triggers and an explicit scope delimiter ('not theoretical concerns or industry-standard behavior'), making conflict with other skills unlikely.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 12 missing

Warning

Total

15

/

16

Passed

Repository
cloudflare/security-audit-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.