CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

AI DevKit · Review code, skills, and prompts for security vulnerabilities — OWASP Top 10, prompt injection, business logic flaws, and insecure defaults. Use when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release.

80

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, highly actionable security-review skill with a clear sequenced workflow, validation checkpoints, and well-organized external reference material. It respects the context budget while remaining concrete.

DimensionReasoningScore

Conciseness

Dense, unpadded body with no explanations of concepts Claude already knows; tables and lists carry information efficiently and every line earns its place.

3 / 3

Actionability

Concrete commands ('npx ai-devkit@latest memory search ...'), specific category checklists, a severity table, and a copy-ready output template give executable guidance rather than vague direction.

3 / 3

Workflow Clarity

The five-step Scope→Scan→Classify→Remediate→Verify workflow is clearly sequenced with explicit checkpoints (approval before change, re-scan for regressions, verify skill).

3 / 3

Progressive Disclosure

The body is an overview that offloads the detailed checklist to the real one-level-deep reference [checklist](references/checklist.md), with content appropriately split and clearly signaled.

3 / 3

Total

12

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A precise, third-person description that names concrete actions, specific vulnerability classes, and explicit natural-language triggers. It cleanly answers both what the skill does and when to invoke it.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('Review code, skills, and prompts for security vulnerabilities') and enumerates specific classes ('OWASP Top 10, prompt injection, business logic flaws, and insecure defaults').

3 / 3

Completeness

Explicitly answers what it does (review for named vulnerability classes) and when to use it (the 'Use when...' clause names concrete triggers).

3 / 3

Trigger Term Quality

'Use when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release' covers natural terms users would say when requesting a security review.

3 / 3

Distinctiveness Conflict Risk

A clear security-review niche with distinct triggers is unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
codeaholicguy/ai-devkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.