CtrlK
BlogDocsLog inGet started
Tessl Logo

review-security

Use when reviewing a branch diff for security concerns — auth, tokens and sessions, injection, secrets, cookies, CSP and third-party content — and reporting findings with S-C/H/M/L IDs in the four-field format.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/review-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally actionable skill body: verbatim commands, concrete routing rules, explicit mid-run and final validation with recovery steps, and well-structured one-level-deep references. The only weakness is verbosity — motivational and repeated prose around the report-shape rules that could be tightened without losing the procedural content.

Suggestions

Trim the motivational framing in Step 0 (e.g. "The file is the deliverable: a run that leaves a differently-shaped file has produced nothing, however good the analysis inside it. Writing the shape now means the rest of the run only fills it in. Leaving it until the end is how a section goes missing.") to a single directive sentence — the rule lands identically without the rhetoric.

The report-shape rules are stated three times (Step 0, the Step 2 mid-run check, and Report shape/final check); consolidate the rationale into one place and keep only the commands plus the expected counts at the checkpoints.

Cut meta-commentary that explains the skill's own organization rather than instructing the reviewer, such as "They are there rather than here because no scenario in this repository's eval suite exercises them, not because they matter less" — the open-condition ("open the file whenever Step 1 routes to one of them") already carries the instruction.

DimensionReasoningScore

Conciseness

The body is mostly dense, high-value, repo-specific guidance, but includes motivational padding ("The file is the deliverable: a run that leaves a differently-shaped file has produced nothing, however good the analysis inside it", "not because they matter less", "costs the review its credibility") and restates the shape rules three times in prose. This matches anchor 3 ("mostly efficient but includes some unnecessary explanation or could be tightened") rather than 4, where over-explanation would be only minor.

3 / 5

Actionability

Fully executable throughout: a verbatim `cat > SECURITY-REVIEW.md <<'EOF'` skeleton, copy-paste `BASE=$(git config ...)` base-branch resolution, a concrete grep routing table with exact patterns, a `grep -c` shape check with expected output ("It must print 4"), a 4-step sibling-verb comparison procedure, a JWT-options tabulation procedure with a decision rule per claim, and an exact finding-format template — matching anchor 5 (copy-paste ready, covering the common cases).

5 / 5

Workflow Clarity

Clear sequence (Step 0 skeleton → Step 1 route the diff → Step 2 work mandatory sections → report sections → final check) with explicit validation checkpoints and error-recovery feedback loops: the mid-run "Check the shape once, as soon as the first finding is in the file" with instructions to "restore the 4 headings, put the finding back under the right one, and edit from then on", plus a routing-table checklist. This matches anchor 5.

5 / 5

Progressive Disclosure

Two one-level-deep reference files, both verified to exist (references/checklists.md, references/compliance.md), are clearly signaled with explicit open-conditions ("open the file whenever Step 1 routes to one of them"; "read that file when the diff adds a column, a table, a request body …"), and the routing table maps grep hits to the reference sections. Hot-path checklists are inlined and cold-path ones split out — a clear overview with easy navigation, matching anchor 5.

5 / 5

Total

18

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names a clear domain, enumerates concrete security coverage areas, and specifies the exact report format and ID scheme. Its main gaps are a 'when' clause that restates the 'what' instead of listing user-side trigger phrases, and missing common synonyms like "vulnerabilities" or "security review".

DimensionReasoningScore

Specificity

"reviewing a branch diff for security concerns — auth, tokens and sessions, injection, secrets, cookies, CSP and third-party content — and reporting findings with S-C/H/M/L IDs in the four-field format" enumerates several concrete coverage areas plus a specific output format, matching anchor 4 ("lists several specific actions; minor gaps in coverage"). Not 5: the actual actions number only two (review, report); not 3: far more concrete than the anchor-3 pattern of naming a domain with 1-2 generic actions.

4 / 5

Completeness

Both parts are explicit: what = "reviewing a branch diff for security concerns … and reporting findings with S-C/H/M/L IDs in the four-field format"; when = "Use when reviewing a branch diff for security concerns". The 'when' clause largely restates the 'what' rather than adding user-utterance triggers (e.g. "when the user asks for a security review or mentions vulnerabilities"), which is exactly the anchor-4 pattern ("'when' could be more explicit or specific") rather than anchor 5.

4 / 5

Trigger Term Quality

Natural trigger words a user would say are present: "security", "review", "branch diff", "auth", "tokens", "injection", "secrets", "cookies", "CSP". Missing common synonyms and variations ("vulnerabilities", "threat", "OWASP", "PR/pull request review", "audit"), so it matches anchor 4 ("good keyword coverage; a few natural terms missing") rather than 5.

4 / 5

Distinctiveness Conflict Risk

The security-specific triggers (auth, tokens, injection, secrets, cookies, CSP) carve a clear niche unlikely to fire for unrelated skills, but "reviewing a branch diff" overlaps with a general code-review skill in the same environment, matching anchor 4 ("mostly distinct; minor overlap risk with closely related skills") rather than 5.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
englishstreetventures/englishstreetventures.com
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.