CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

AI DevKit · Review code, skills, and prompts for security vulnerabilities — OWASP Top 10, prompt injection, business logic flaws, and insecure defaults. Use when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release.

73

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, lean security-review skill with a clear sequenced workflow, validation feedback loops, and appropriate offloading of detail to a real checklist reference. The lone gap is slightly fewer executable code examples, which keeps actionability at 4.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence: brief hard rules, a structured scan list with terse category glosses ('Injection — SQL, NoSQL, command, template, SSRF, path traversal, XSS'), and no padding explaining what OWASP or SQL injection is, so every token earns its place.

5 / 5

Actionability

Provides copy-paste executable commands (`npx ai-devkit@latest memory search/store ...`), a concrete severity table, and an output template, but as an instruction-heavy skill it offers fewer executable code examples than the anchor-5 'fully copy-paste ready' ideal, landing at 4.

4 / 5

Workflow Clarity

Five sequenced steps (Scope, Scan, Classify, Remediate, Verify) include an approval gate before code changes, a Verify step that re-scans fixed files for regressions, and a referenced checklist — explicit validation with a feedback loop matching anchor 5.

5 / 5

Progressive Disclosure

SKILL.md is a clear overview with a single well-signaled, one-level-deep reference (`[checklist.md](references/checklist.md)`, verified to exist), and the 101-line detailed checklist is appropriately offloaded rather than inlined.

5 / 5

Total

19

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that explicitly states both capability and usage triggers with domain-specific vocabulary. The only soft spot is specificity, where a single review verb carries most of the action weight.

DimensionReasoningScore

Specificity

Names the security-review domain and lists concrete vulnerability categories (OWASP Top 10, prompt injection, business logic flaws, insecure defaults), but centers on a single action verb ('review') rather than multiple distinct actions, so it stops short of the comprehensive multi-action anchor 5.

4 / 5

Completeness

It explicitly answers 'what' ('Review code, skills, and prompts for security vulnerabilities ...') and 'when' ('Use when reviewing PRs, auditing modules ...') with concrete trigger phrases, matching the anchor-5 example structure.

5 / 5

Trigger Term Quality

Natural trigger phrases ('reviewing PRs, auditing modules, reviewing AI skills/prompts, preparing for release') cover the domain well, but a few common synonyms and any file/extension cues are absent, fitting the 'good coverage, a few terms missing' anchor 4.

4 / 5

Distinctiveness Conflict Risk

The security-review niche with OWASP/prompt-injection framing and targeted triggers is clearly distinguishable from general code or doc skills, with minimal overlap risk; voice is third-person with no pronoun penalty.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
codeaholicguy/ai-devkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.