CtrlK
BlogDocsLog inGet started
Tessl Logo

security-reviewer

Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure. Use instead of code-reviewer when the prompt explicitly asks for security, vulnerability, threat, auth, or OWASP review.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-structured security-review methodology with a clear sequenced workflow and concrete checklists. It could tighten the intro/Vibe sections and add an explicit validate-and-rescan feedback loop.

Suggestions

Add an explicit feedback loop in the workflow (e.g., after Remediation Output, re-run the Initial Scan to confirm the fix closed the finding) to strengthen validation checkpoints.

Trim overlap between the opening sentence and the Routing Boundary section, and consider whether the Vibe Integration pairing notes earn their tokens or could fold into Routing Boundary.

For actionability, add one or two concrete commands or tool invocations (e.g., a grep pattern for hardcoded secrets or a suggested dependency-audit command) to move from methodology toward executable guidance.

DimensionReasoningScore

Conciseness

Lean bullet-style checklists assume Claude's knowledge of OWASP/XSS/SSRF without padding; the "Vibe Integration" section and slight overlap between the intro and Routing Boundary could be trimmed, keeping it just below 5.

4 / 5

Actionability

Concrete, specific guidance ("parameterized queries, sanitized inputs", "URL allowlist", severity tiers CRITICAL/HIGH/MEDIUM/LOW, "file + line + risk") with minor gaps; no executable commands, but this is an instruction-only review skill so code absence is not penalized.

4 / 5

Workflow Clarity

A clear 4-phase numbered sequence (Initial Scan → OWASP Checks → High-Risk Pattern Audit → Remediation Output) with a verification checkpoint ("Verification steps after fix"); minor gap is the lack of an explicit re-scan/retry loop after remediation.

4 / 5

Progressive Disclosure

Under 50 lines with no bundle files present and none needed; content is well-organized into clearly headed sections (Routing Boundary, Workflow, Vibe Integration), satisfying the simple-skill exception for a top score.

5 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-targeted description that clearly states the skill's purpose and gives explicit routing guidance with natural trigger terms. Minor room to add synonyms and frame items as concrete actions.

DimensionReasoningScore

Specificity

Lists several concrete risk categories ("secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure") with only minor coverage gaps; not a 5 because these are risk domains rather than explicit audit actions.

4 / 5

Completeness

Explicitly answers both what ("Dedicated security-audit route for OWASP-style risks...") and when ("Use instead of code-reviewer when the prompt explicitly asks for security, vulnerability, threat, auth, or OWASP review") with concrete trigger phrases.

5 / 5

Trigger Term Quality

Good natural keyword coverage ("security, vulnerability, threat, auth, or OWASP review") that users would actually say; a few common synonyms like "pentest", "exploit", or "CVE" are missing, keeping it just below 5.

4 / 5

Distinctiveness Conflict Risk

Carves out a clear security-audit niche and explicitly distinguishes from code-reviewer ("Use instead of code-reviewer"), giving distinct triggers with minimal conflict risk.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
foryourhealth111-pixel/Vibe-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.