CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Skill do Security Reviewer para auditoria de segurança e boas práticas. Use quando precisar revisar código para vulnerabilidades, validar implementação de auth, checar OWASP Top 10, revisar CORS/CSRF/XSS, garantir DRY e clean code, ou qualquer review de segurança. Trigger em: "segurança", "security review", "vulnerabilidade", "OWASP", "XSS", "CSRF", "CORS", "injection", "HttpOnly", "cookie seguro", "DRY", "code review", "boas práticas", "audit", "pentest", "sanitização".

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with concrete code and checklists, but it is verbose with some redundancy, lacks a sequenced review workflow with validation feedback loops, and references external files that are not present in the bundle.

Suggestions

Add a numbered end-to-end review workflow with explicit validation checkpoints (e.g., run npm audit → review findings → verify fixes → re-audit) to improve workflow_clarity.

Move the OWASP checklists, code snippets, and report template into reference files under references/ and link to them from SKILL.md, keeping only an overview inline, to fix the missing bundle and improve progressive_disclosure.

Trim redundancy — remove the 'Código Limpo' section that restates the DRY checklist's comment guidance, and drop explanations of SOLID/clean-code basics Claude already knows.

DimensionReasoningScore

Conciseness

The body is mostly actionable checklists and code, but it is padded with redundancy (the 'Código Limpo' section restates comment guidance from the DRY checklist) and re-explains concepts Claude knows (SOLID letter meanings, basic clean-code rules); it could be tightened.

2 / 3

Actionability

Fully executable TypeScript snippets for security headers, CORS, CSRF, and XSS sanitization, plus concrete thresholds ('cost factor >= 12', '15 min máx') and a copy-paste report template, match the score-3 anchor.

3 / 3

Workflow Clarity

Content is organized by topic rather than as a sequenced review process, and the Handoff section is a release gate rather than a validate→fix→retry feedback loop; per the rubric, missing validation checkpoints for a batch review operation caps this at 2.

2 / 3

Progressive Disclosure

References to GLOBAL.md, policies/*, docs/skill-guides/*, and personas/* are signaled and one-level-deep, but none of these bundle files exist, and large reference-grade material (OWASP checklists, code blocks, report template) is inlined rather than split out.

2 / 3

Total

9

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it concisely states concrete capabilities, provides an explicit 'Use quando' clause plus a dedicated trigger-term list, and occupies a clearly distinct security-review niche. Minor verbosity in the trigger list does not undermine clarity.

DimensionReasoningScore

Specificity

Lists multiple concrete actions such as 'revisar código para vulnerabilidades, validar implementação de auth, checar OWASP Top 10, revisar CORS/CSRF/XSS, garantir DRY e clean code', matching the score-3 anchor for multiple specific concrete actions.

3 / 3

Completeness

Clearly answers both 'what' (security audit and best-practices review with concrete actions) and 'when' ('Use quando precisar revisar código...' plus an explicit trigger list), matching the score-3 anchor.

3 / 3

Trigger Term Quality

An explicit 'Trigger em:' list provides good coverage of natural terms users would say ('vulnerabilidade', 'OWASP', 'XSS', 'code review', 'pentest', 'audit'), with common variations included.

3 / 3

Distinctiveness Conflict Risk

The security/OWASP niche is clear and the trigger terms are distinct; despite minor overlap with generic 'code review', it is unlikely to trigger for the wrong skill.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
felvieira/claude-skills-fv
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.