CtrlK
BlogDocsLog inGet started
Tessl Logo

review-security

Use when reviewing a branch diff for security concerns — auth, tokens and sessions, injection, secrets, cookies, CSP and third-party content — and reporting findings with S-C/H/M/L IDs in the four-field format.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, well-sequenced security review workflow with executable commands, explicit validation feedback loops, and a deliberate two-file reference split. Its main weakness is repetition: the report-shape invariant and the comment-is-a-claim rule are each stated multiple times, and the inline checklist mass keeps the SKILL.md from being a lean overview of its own references.

Suggestions

State the report-shape invariant once (Step 0) and have later sections reference it in one line instead of re-explaining it at Step 2 and the final check.

Fold the Step 2 "a comment is a claim, not a control" rule and JWT rule 3 ("a comment arguing for the gap does not close it") into a single statement, since they make the same point.

Trim rhetorical framing ("however good the analysis inside it", "that is the one way this run fails outright") — the operative rule lands without the emphasis.

DimensionReasoningScore

Conciseness

Most content is repo-specific knowledge Claude cannot infer (grep routing table, OSN conventions, sibling-verb procedure), but the skeleton/shape invariant is stated three times (Step 0, mid-Step 2, final check), "a comment is a claim, not a control" appears twice, and rhetorical padding ("however good the analysis inside it") could be trimmed — anchor 3, not 4, because the repetition is noticeable.

3 / 5

Actionability

Fully copy-paste-ready throughout: the heredoc report skeleton, `git config --get branch.$(git branch --show-current).gh-merge-base` base resolution, the exact grep pattern table, the `grep -c` shape checks, the exact finding template, and the numbered JWT-options and sibling-verb procedures — matching the anchor-5 example of executable commands covering the common cases.

5 / 5

Workflow Clarity

Steps 0→1→2 are clearly sequenced with an explicit mid-run validation checkpoint ("It must print 4… restore the 4 headings, put the finding back under the right one") and a final verification pass with recovery guidance — a full validate→fix→re-check loop matching anchor 5.

5 / 5

Progressive Disclosure

Two one-level-deep references (references/checklists.md, references/compliance.md) exist as real files, are clearly signaled, and each carries an explicit when-to-open condition; however the body itself is ~280 lines of inline checklists rather than a lean overview pointing at them, fitting anchor 4 rather than 5.

4 / 5

Total

17

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it has an explicit "Use when" trigger clause, enumerates specific security concern areas, and specifies a concrete reporting format with tiered finding IDs. Keyword coverage is good but misses a few natural synonyms, and the capability list is one action over several domains rather than multiple distinct actions.

Suggestions

Add one or two natural synonyms users might say, e.g. "vulnerabilities" or "security audit", to broaden trigger coverage.

Name one more distinct action besides reviewing (e.g. "flags and rates each finding by severity") to make the capability list multi-action rather than one verb over domains.

DimensionReasoningScore

Specificity

Enumerates concrete concern classes ("auth, tokens and sessions, injection, secrets, cookies, CSP and third-party content") and a concrete output contract ("S-C/H/M/L IDs in the four-field format"), but centers on a single action (reviewing) over domains rather than multiple distinct actions, matching anchor 4 rather than 5.

4 / 5

Completeness

Opens with an explicit "Use when reviewing a branch diff for security concerns…" trigger clause and clearly states what it does (review the listed concern classes and report findings with tiered IDs in a four-field format), matching the anchor-5 example of both what and when stated explicitly with concrete triggers.

5 / 5

Trigger Term Quality

Contains natural terms users would say — "security", "review", "branch diff", "auth", "cookies", "injection", "secrets" — with good keyword coverage, though common synonyms like "vulnerability" or "threats" are absent, so it fits anchor 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

A clear niche — security review of a branch diff with a defined finding-ID report format — with mostly distinct triggers, though it retains minor overlap risk with generic code-review or broader security skills, matching anchor 4 rather than 5.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
englishstreetventures/osn
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.