CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

70

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a dense, highly actionable review playbook with a clear gated workflow and well-structured one-level-deep references. The two costs are duplicated guidance that inflates token usage and three dangling language/infrastructure reference paths that would fail when loaded.

Suggestions

Deduplicate: keep the research-before-flagging guidance in the Review Process (step 4) and reference it from the Scope section instead of restating it; likewise keep a single canonical reference-file listing rather than repeating it in both the 'Detect Context' table and the 'Reference Files' section.

Fix dangling references: either add 'languages/python.md', 'languages/javascript.md', and 'infrastructure/docker.md' to the bundle, or rewrite those rows to the 'No bundled guide; use official documentation' pattern already used for Go, Rust, Java, and Kubernetes so steps 2 and 3 never point Claude at nonexistent files.

Consolidate the repeated SSRF/path-traversal server-vs-attacker examples into the 'Check Context First' quick-patterns section and point the earlier 'Server-Controlled Values' section at it, trimming roughly 25-30% of the body without losing any actionable guidance.

DimensionReasoningScore

Conciseness

The body never over-explains concepts Claude already knows (it assumes competence about what XSS or SSRF is) and is dense with tables and pattern examples, but it carries real redundancy: research-before-flagging guidance appears near-verbatim in the 'Scope' section and again in Review Process step 4, the reference file set is listed both in the 'Detect Context' table and the 'Reference Files' section, SSRF server-vs-attacker examples appear twice, and the 'No bundled guide...' caveat repeats six times. It could be tightened by roughly a quarter, matching the 'mostly efficient but could be tightened' anchor rather than the 'minor instances' of the score-4 anchor.

3 / 5

Actionability

Fully concrete and executable: exact unsafe APIs to flag ('{{ var|safe }}', 'dangerouslySetInnerHTML={{__html: userInput}}', 'v-html', '.raw()', 'yaml.load' vs 'safe_load'), vulnerable-vs-safe code contrasts, a copy-paste output format template, and decision tables for confidence and severity. Specific examples cover the common cases, matching the top anchor.

5 / 5

Workflow Clarity

A clear six-step numbered review process with explicit validation gates: the confidence table routes each finding to Report/Note/Do-not-report, step 4's research questions ('Where does this value actually come from?', 'Is there validation... elsewhere?') act as checkpoints, and the 'Needs Verification' output section provides a feedback path for uncertain findings. This is a read-only review, so the destructive-operation cap does not apply, and the sequence matches the top anchor's explicit-validation-and-checkpoints pattern.

5 / 5

Progressive Disclosure

Good overview-plus-references structure: SKILL.md stays an index, all 17 core references exist, are one level deep, and are well-signaled with coverage descriptions. Not a 5 because three referenced paths ('languages/python.md', 'languages/javascript.md', 'infrastructure/docker.md') do not exist in the bundle even though Review Process steps 2 and 3 instruct loading them — a navigation break for those code types. It is clearly above the score-3 anchor, since the split and signaling are otherwise appropriate.

4 / 5

Total

17

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete, third-person, with explicit 'Use when...' triggers covering natural user phrasings. The only weaknesses are a single-action core 'what' with minor coverage gaps and slight overlap risk with general code-review skills.

DimensionReasoningScore

Specificity

The description names the domain and several concrete capabilities ('review code for injection, XSS, authentication, authorization, cryptography issues', 'systematic review with confidence-based reporting'), but the core action is a single review task over a vulnerability-class list with minor gaps (no mention of remediation guidance or report format). It lists several specific actions with minor gaps — matching the score-4 anchor — rather than the multiple distinct concrete actions of the score-5 anchor.

4 / 5

Completeness

It explicitly answers both 'what' ('Security code review for vulnerabilities... Provides systematic review with confidence-based reporting') and 'when' ('Use when asked to...' with concrete trigger phrases), matching the top anchor exactly. Third-person voice is used throughout.

5 / 5

Trigger Term Quality

Five natural quoted trigger phrases ('security review', 'find vulnerabilities', 'check for security issues', 'audit security', 'OWASP review') plus vulnerability-class keywords give comprehensive natural-term coverage with synonyms users would actually say. Nothing significant is missing for this domain, matching the score-5 anchor.

5 / 5

Distinctiveness Conflict Risk

A clear security niche with distinct security-specific triggers ('security review', 'find vulnerabilities', 'audit security', 'OWASP review'). Minor residual overlap risk with a generic code-review skill via the 'review code for ... issues' phrasing keeps it just below the minimal-conflict score-5 anchor.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
joe-bell/cva
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.