CtrlK
BlogDocsLog inGet started
Tessl Logo

scanning-database-security

Process use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/database/database-security-scanner/skills/scanning-database-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete SQL and grep patterns, but it lacks validation checkpoints in its remediation workflow and fails to leverage the bundled reference, script, and asset files through clear navigation.

Suggestions

Add explicit validation/feedback steps for destructive remediation, e.g., verify findings in a staging session before applying revoke/SSL/auth changes and re-scan to confirm.

Reference the bundled scripts and templates where relevant (e.g., "run scripts/database_scan.py to automate steps 1–9" and point to assets/report_template.html for the report).

Tighten the Examples section to concise finding/remediation pairs and move the external URLs into a reference file to reduce inline length.

DimensionReasoningScore

Conciseness

The core instruction list is lean and concrete, but the narrative Examples section and the supplementary Resources list add length that could be trimmed without losing actionable value, keeping it just below the every-token-earns-its-place anchor.

2 / 3

Actionability

Provides concrete, copy-paste-ready SQL per database, specific grep patterns for SQL injection, and explicit commands, fully matching the executable-guidance anchor.

3 / 3

Workflow Clarity

The 10 steps are clearly sequenced, but the workflow has no validation or feedback checkpoints for the destructive remediation it produces (revoking privileges, changing auth, enabling SSL), which caps it at 2 per the database-operations feedback-loop guidance.

2 / 3

Progressive Disclosure

Sections are well organized, but the body references none of the provided bundle files (scripts/database_scan.py, references/, assets/) and keeps per-database SQL detail inline, so content that should be split out is not navigated to.

2 / 3

Total

9

/

12

Passed

Description

82%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description covers what and when with natural trigger phrases, but is weakened by vague fluff and a lack of database specificity that blurs its distinctiveness from other security skills.

Suggestions

Replace "comprehensive guidance and automation" with the concrete actions the skill performs (e.g., "audit user privileges, network exposure, encryption, and SQL injection vectors").

Add a database qualifier so the description matches the skill scope, e.g., "Audit database security configurations for PostgreSQL, MySQL, and MongoDB."

Fix the malformed opening "Process use when…" to clean third-person voice such as "Use when…".

DimensionReasoningScore

Specificity

Names the domain and two concrete actions ("security scanning and vulnerability detection") but pads with fluff ("comprehensive guidance and automation") and stops short of a comprehensive concrete action list, so it does not reach the multiple-specific-actions anchor.

2 / 3

Completeness

Explicitly answers both what it does ("security scanning and vulnerability detection") and when to use it ("use when you need to work with security and compliance" plus "Trigger with phrases like…"), satisfying the explicit-trigger requirement.

3 / 3

Trigger Term Quality

Includes natural phrases a user would actually say — "scan for vulnerabilities", "implement security controls", "audit security" — giving good coverage of likely trigger terms.

3 / 3

Distinctiveness Conflict Risk

The description is generic "security and compliance" with no database qualifier, so it could overlap with other security skills despite the body being database-specific; it is a niche but not clearly bounded.

2 / 3

Total

10

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
jeremylongshore/claude-code-plugins-plus-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.