CtrlK
BlogDocsLog inGet started
Tessl Logo

performing-security-audits

Analyze code, infrastructure, and configurations by conducting comprehensive security audits. It leverages tools within the security-pro-pack plugin, including vulnerability scanning, compliance checking, and cryptography review. Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.

52

Quality

Does it follow best practices?

Impact

No eval scenarios have been run

SecuritybySnyk

Passed

No known issues

SKILL.md
Quality
Evals
Security

Quality

Content

20%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is mostly generic marketing-style prose with no executable guidance and no links to the actual bundled scripts and templates, instead referencing fictional agents. It reads as boilerplate rather than operational instructions for Claude.

Suggestions

Replace the abstract 'Invoke the agent' steps with concrete, executable usage of the bundled scripts/security_scan.py and link to the three asset report templates.

Cut filler sections (Integration, Prerequisites, Output, Instructions, Resources) that state what Claude already knows; keep only operational guidance.

Add validation/review checkpoints to the audit workflow (run scan → triage findings by severity → confirm remediation → re-scan) so the sequence is robust for batch/risky operations.

DimensionReasoningScore

Conciseness

The body is padded with generic filler Claude already knows — "This skill seamlessly integrates with all other components", "Required dependencies installed", "The skill produces structured output relevant to the task" — matching the verbose/explains-known-concepts anchor rather than the lean one.

1 / 3

Actionability

There is no executable code, command, or file path; guidance is abstract ("Invoke the Security Auditor Expert agent", "Execute the selected tool") and the real bundled security_scan.py is never referenced, matching the 'describes rather than instructs' anchor.

1 / 3

Workflow Clarity

Steps are sequenced (Analysis Selection → Execution → Reporting) but lack validation checkpoints for an audit that surfaces findings and remediation, and the Instructions section is generic boilerplate — above the missing-sequence anchor but below the explicit-validation one.

2 / 3

Progressive Disclosure

Real bundle files exist (scripts/security_scan.py and three asset templates) but are not linked from the body, while the body instead references nonexistent 'agents'; structure is present but navigation is mis-signaled and content that should be split stays inline.

2 / 3

Total

6

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is well-constructed: it states concrete capabilities, gives explicit 'Use when' trigger guidance with natural user phrases, and occupies a clear niche. It satisfies the top anchor on all four dimensions.

DimensionReasoningScore

Specificity

The description names concrete actions across a defined domain — "vulnerability scanning, compliance checking, and cryptography review" on "code, infrastructure, and configurations" — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

It explicitly answers both what it does ("conducting comprehensive security audits" with named sub-tasks) and when to use it ("Use when assessing security or running audits. Trigger with phrases like..."), the top anchor.

3 / 3

Trigger Term Quality

It lists natural phrases a user would actually say — "'security scan', 'audit', or 'vulnerability'" — giving good coverage of common utterances rather than technical jargon.

3 / 3

Distinctiveness Conflict Risk

The security-audit niche with plugin-specific tool framing and distinct trigger phrases is unlikely to fire for unrelated skills, matching the 'clear niche with distinct triggers' anchor.

3 / 3

Total

12

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
jeremylongshore/claude-code-plugins-plus-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.