CtrlK
BlogDocsLog inGet started
Tessl Logo

owasp-security

Comprehensive OWASP-aligned security guidance across six standards - Top 10 (2021) for web apps, ASVS 5.0, MASVS v2.1.0 for mobile, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the Agentic Applications 2026 edition for AI/LLM. Use for security reviews, vulnerability audits, secure auth/crypto/access-control implementation, Kubernetes manifest hardening, and LLM/agent prompt-injection defense - including indirect requests like "is this login flow secure?", "review this endpoint", or "audit my pod spec".

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude-plugin/skills/owasp-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a thorough, actionable reference with strong INSECURE/SECURE code examples, but it is verbose for a single inlined file and lacks the multi-file structure and validation feedback loops the rubric rewards. Splitting per-standard detail into reference files and trimming restated concepts would raise the score.

Suggestions

Move each per-standard section (Top 10, ASVS, MASVS, API, K8s, Agentic) into separate reference files under references/ and keep SKILL.md as a concise overview with one-level-deep links.

Trim framing sentences that restate widely known concepts (e.g., what the OWASP Top 10 is, that APIs differ from web apps) to improve token efficiency.

For sections that are currently checklist-only (A04, A06-A10), add a brief executable example or a concrete verification command so the guidance is consistently actionable.

DimensionReasoningScore

Conciseness

The ~900-line body is mostly lean reference material, but several framing sentences restate concepts a competent model already knows ('The OWASP Top 10 represents the most critical security risks in web applications', 'REST and GraphQL APIs have unique security challenges different from traditional web apps').

3 / 5

Actionability

Provides extensive executable INSECURE/SECURE code pairs across JS, Python, Swift, Kotlin, and YAML plus concrete commands ('npm audit', 'pip safety'), though several sections (A04, A06, A07, A08, A09, A10) are checklist-only with no code.

4 / 5

Workflow Clarity

It is a reference catalog rather than a sequenced workflow; the consistent Detection/Mitigation/Example/Checklist structure organizes content but lacks explicit sequencing or validation checkpoints, and several checklist-only sections omit executable steps.

3 / 5

Progressive Disclosure

No bundle files exist, so all per-standard detail is inlined into a single large SKILL.md; a Quick Navigation TOC provides structure, but content that clearly belongs in separate reference files is not split out or signaled.

3 / 5

Total

13

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is comprehensive and well-structured, clearly stating capabilities, named standards, and concrete trigger phrases including indirect user requests. It only loses a point on trigger_term_quality for a few missing synonyms.

DimensionReasoningScore

Specificity

Lists multiple concrete actions across six named standards ('security reviews, vulnerability audits, secure auth/crypto/access-control implementation, Kubernetes manifest hardening, and LLM/agent prompt-injection defense'), giving comprehensive coverage of what the skill does.

5 / 5

Completeness

Explicitly answers both 'what' (six named OWASP standards with versions and concrete actions) and 'when' ('Use for ... including indirect requests like ...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Includes natural verbatim user phrases ('is this login flow secure?', 'review this endpoint', 'audit my pod spec') alongside standard review terms, though a few common synonyms are absent.

4 / 5

Distinctiveness Conflict Risk

Names six specific versioned standards, carving a clear niche with distinct triggers and minimal overlap risk with generic skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (906 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
davila7/claude-code-templates
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.