Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
83
Quality
79%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Advisory
Suggest reviewing before use
Optimize this skill with Tessl
npx tessl skill review --optimize ./docs/v19.7/configuration/agent/skills_external/antigravity-awesome-skills-main/skills/cc-skill-security-review/SKILL.mdSecurity
1 medium severity finding. This skill can be installed but you should review these findings before use.
The skill is specifically designed for direct financial operations, giving the agent the ability to move money or execute financial transactions — such as payment processing, cryptocurrency operations, banking integrations, or market order execution.
Direct money access detected (high risk: 1.00). The skill includes an explicit "Blockchain Security (Solana)" section with concrete crypto-specific code and checks: using @solana/web3.js to verify wallet ownership, transaction verification logic (recipient, amount, balance checks), and guidance like "No blind transaction signing". These are explicit blockchain/wallet/transaction operations (not generic tooling) and thus fall under crypto/ blockchain financial functionality. Therefore it meets the criterion for Direct Financial Execution risk.
20ba150
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.