CtrlK
BlogDocsLog inGet started
Tessl Logo

skill-security-auditor

Security auditing for code, configs, and infrastructure. Use when the user wants to audit or improve security: scan for vulnerabilities (SQL injection, XSS, command injection, path traversal), detect hardcoded secrets and credentials, review auth and authorization, check dependencies for known CVEs, audit config files for insecure defaults, or generate security reports. Trigger on "security audit", "vulnerability scan", "code review for security", "find secrets", "check for vulnerabilities", "OWASP", "CVE", or questions about code security.

70

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable audit guide: lean, sequenced workflow with real bundle files behind clearly signaled references. Weaknesses are minor — truncated code snippets, slight duplication between inline examples and the reference files, and mostly-implicit finding-verification checkpoints.

Suggestions

Complete the truncated snippets (the JavaScript example's bare `throw new Error()` and the Go `http.Error(...)`) or replace them with fully executable equivalents so every example is copy-paste ready.

Deduplicate the reference pointers (Overview and Next Steps repeat the same two links) and trim the 'Common patterns to check' bullets, which restate what scripts/scan_secrets.py and references/secrets-patterns.md already provide.

Add an explicit verification checkpoint before reporting — e.g., manually confirm flagged findings to rule out false positives (references/secrets-patterns.md already has a False Positive Reduction section) — to strengthen the workflow's validation loop.

DimensionReasoningScore

Conciseness

The body is dense and assumes Claude's competence — no basic-concept explanations, just commands, tables, and dangerous/safe code pairs. Minor trimmable instances remain: the reference pointers are repeated in both Overview and Next Steps, the "Common patterns to check" bullets restate what the bundled scan script already covers, and the inline language-specific examples overlap references/vulnerability-patterns.md. This is anchor 4 (efficient, minor over-explanation to trim) rather than 5, where every token would earn its place; it is clearly above anchor 3, which requires unnecessary explanation.

4 / 5

Actionability

Mostly executable guidance: runnable scan-script commands, pip/npm/govulncheck/trivy commands, parameterized-query and path-traversal safe/unsafe pairs, and a concrete report template. Minor gaps keep it from anchor 5: the JavaScript "safe" example ends in a bare `throw new Error()`, the Go snippet is truncated (`http.Error(...)`), and `npx auditjs ossi` is a niche tool a user may not have. Anchor 4 (concrete code with minor gaps) is the best fit.

4 / 5

Workflow Clarity

A clear six-step sequence (Reconnaissance → Secrets Detection → Vulnerability Scanning → Dependency Audit → Configuration Review → Auth Review) with a report format closing the loop, and a checkpoint in the dependency step ("Review the output and categorize by severity"). It is anchor 4 rather than 5 because validation checkpoints are implicit in places — e.g., no explicit step to verify scan findings (false-positive reduction is only in the secrets reference) before reporting. The destructive/batch cap does not apply since this is a read-only audit workflow.

4 / 5

Progressive Disclosure

Scored against the actual bundle: references/vulnerability-patterns.md, references/secrets-patterns.md, scripts/scan_project.py, and scripts/scan_secrets.py all exist, are one level deep, and are clearly signaled in Overview, the relevant workflow steps, and Next Steps. Anchor 4 rather than 5 because some content duplicated from the reference files (language-specific safe/unsafe examples, the secrets pattern bullet list) is inlined where the reference already holds the detail.

4 / 5

Total

16

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, concrete enumerated capabilities, and an explicit 'Use when' clause with natural trigger terms. The only weakness is minor overlap risk with generic code-review skills via the "code review for security" trigger.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions with concrete vulnerability types — "scan for vulnerabilities (SQL injection, XSS, command injection, path traversal), detect hardcoded secrets and credentials, review auth and authorization, check dependencies for known CVEs, audit config files for insecure defaults, or generate security reports" — comprehensive coverage across code, dependencies, and configs. Fits the anchor-5 example (multiple specific actions, comprehensive) better than anchor 4, which is for coverage with minor gaps; no action area of the skill's own body is unrepresented.

5 / 5

Completeness

Explicitly answers both what ("Security auditing for code, configs, and infrastructure" plus enumerated capabilities) and when ("Use when the user wants to audit or improve security..." with concrete trigger phrases). This is the anchor-5 pattern almost verbatim; it is not anchor 4 because the 'when' clause is explicit and trigger-specific rather than merely adequate.

5 / 5

Trigger Term Quality

Comprehensive natural trigger phrases users would actually say: "security audit", "vulnerability scan", "code review for security", "find secrets", "check for vulnerabilities", "OWASP", "CVE", plus "questions about code security". This matches anchor 5 (comprehensive natural terms including synonyms); anchor 4 would apply if common variations were missing, but both colloquial phrasings and domain standards are covered.

5 / 5

Distinctiveness Conflict Risk

A clear niche (defensive security auditing) with distinct triggers (OWASP, CVE, secrets detection), but "code review for security" and "audit or improve security" create minor overlap risk with general code-review and code-quality skills. Mostly distinct with minor overlap — anchor 4; not anchor 5 because the security-review wording could pull the skill in on general code-review requests.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
eigent-ai/eigent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.