CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

55

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, actionable security reference whose main weaknesses are token efficiency and structure: it duplicates guidance across per-topic and pre-deployment checklists, inlines code Claude largely already knows, and keeps everything in one long file instead of splitting topics into reference files. The per-section verification steps are its strongest feature.

Suggestions

Cut the body to a lean core checklist and move per-topic code deep-dives (blockchain, security testing, Supabase RLS) into reference files under references/

Deduplicate: keep either the per-section Verification Steps or the consolidated pre-deployment checklist, not both covering the same items

Fix non-executable examples — replace the pseudo '@solana/web3.js' verify call and the undescribed '@/lib/csrf' helper with runnable code or flag them as illustrative patterns

DimensionReasoningScore

Conciseness

At ~490 lines, the body inlines extensive worked examples of practices Claude already knows well (parameterized queries, DOMPurify sanitization, express-rate-limit, JWT cookie flags, npm audit), and repeats the same guidance twice — per-section 'Verification Steps' checklists and then again in the 'Pre-Deployment Security Checklist'. Not a 1 because there is no conceptual over-explanation of basics; not a 3 because the volume of predictable example code and duplicated checklists is substantial padding.

2 / 5

Actionability

Mostly executable, copy-paste-ready TypeScript/SQL/bash snippets per topic (zod schemas, Supabase RLS policies, CSRF token verification, CSP headers). Not a 5 because several examples are not directly runnable: 'verify' from '@solana/web3.js' is not a real export, 'csrf.verify' assumes an undescribed local lib, and the transaction-verification example is pseudocode-shaped; not a 3 because the majority of code is concrete and complete.

4 / 5

Workflow Clarity

The skill is organized as a per-topic checklist with explicit 'Verification Steps' checkboxes in each section plus a consolidated pre-deployment checklist — clear validation checkpoints for a review process. Not a 5 because there is no stated order or feedback loop (e.g., how to prioritize findings or what to do when a check fails); not a 3 because validation checkpoints are explicit and thorough throughout.

4 / 5

Progressive Disclosure

Well-sectioned single file with no bundle files at all; self-contained content that arguably belongs in reference files (the Solana/blockchain section, the security-testing suite, per-topic deep dives) is fully inlined at ~490 lines. Not a 4 because none of this volume is split out or navigable by loading only relevant sections; not a 2 because internal structure (numbered sections, checklists) is good and there are no buried or nested references.

3 / 5

Total

13

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit, multi-trigger 'when' clause using natural user language, but the 'what' portion ('comprehensive security checklist and patterns') is generic and buzzword-adjacent. Tightening the capability statement with concrete deliverables would raise specificity and completeness.

Suggestions

Replace 'Provides comprehensive security checklist and patterns' with concrete actions, e.g., 'Reviews code for vulnerabilities such as hardcoded secrets, SQL injection, XSS, and missing authorization checks'

Add natural trigger synonyms users are likely to say, e.g., 'security review', 'authorization', or 'vulnerabilities'

Drop the buzzword 'comprehensive' — state what the checklist actually covers instead

DimensionReasoningScore

Specificity

The 'what' is 'Provides comprehensive security checklist and patterns' — it names the security domain but the action is generic and 'comprehensive'/'patterns' read as buzzwords rather than concrete capabilities. Not a 4 because it does not list several specific actions the skill performs; not a 2 because it does name the domain with a discernible action (providing a checklist).

3 / 5

Completeness

Both parts are present: an explicit trigger clause ('Use this skill when adding authentication, ...') and a 'what' ('Provides comprehensive security checklist and patterns'). Not a 5 because the 'what' is vague — 'checklist and patterns' does not state concretely what the skill does; not a 3 because the 'when' is explicit with multiple concrete triggers.

4 / 5

Trigger Term Quality

Natural phrases users would say are present: 'adding authentication', 'handling user input', 'working with secrets', 'creating API endpoints', 'implementing payment/sensitive features'. Not a 5 because common synonyms and variations are missing (e.g., 'security review', 'authorization', 'vulnerabilities', 'XSS/SQL injection'); not a 3 because coverage is genuinely good across multiple trigger categories.

4 / 5

Distinctiveness Conflict Risk

Triggers (secrets, payments, auth, sensitive features) carve out a fairly distinct security niche, though 'handling user input' and 'creating API endpoints' are broad and could overlap with general coding or API-design skills. Not a 5 due to that overlap risk; not a 3 because the security framing dominates the description.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
devrev/meerkat
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.