CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

91

1.11x
Quality

88%

Does it follow best practices?

Impact

97%

1.11x

Average score across 3 eval scenarios

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is highly actionable with a clear, validated review workflow, but is held back by repetition of the attacker-vs-server-controlled guidance and by references to language and infrastructure guide files that are not present in the bundle.

Suggestions

Consolidate the attacker-controlled vs. server-controlled tables into a single authoritative section to remove the repetition across 'Do Not Flag', step 4, and step 5.

Either add the missing `languages/*.md` and `infrastructure/*.md` reference files to the bundle or remove those load instructions and tables so navigation is not broken.

Tighten the Quick Patterns Reference so it does not restate patterns already covered in the framework-mitigated and 'Check Context First' tables.

DimensionReasoningScore

Conciseness

The body is dense reference material (tables and code) rather than padded prose, but the attacker-controlled vs. server-controlled distinction is restated across multiple sections ("Do Not Flag", step 4, step 5) and could be tightened. It is not a 3 because of this repetition; not a 1 because it avoids explaining concepts Claude already knows.

2 / 3

Actionability

It provides executable code snippets, explicit flag/safe pattern pairs, a copy-paste output format template, and concrete severity criteria — fully actionable guidance. It is not a 2 because the examples are real and complete rather than pseudocode.

3 / 3

Workflow Clarity

The six-step Review Process is clearly sequenced with explicit validation checkpoints (confidence levels gating what to report, 'Research Before Flagging', 'Verify Exploitability'). It is not a 2 because feedback loops and gating checkpoints are explicit, not implicit.

3 / 3

Progressive Disclosure

Core references are one-level deep and well-signaled with a context-to-reference mapping table, but the body directs Claude to load `languages/*.md` and `infrastructure/*.md` paths that do not exist in the bundle — broken navigation. It is not a 3 because of these missing referenced files; not a 1 because the core references that do exist are clearly organized.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: concrete capabilities, natural trigger terms, explicit 'Use when' guidance, and a clearly distinct security niche. No changes needed.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions such as "review code for injection, XSS, authentication, authorization, cryptography issues" and "confidence-based reporting", matching the 'Lists multiple specific concrete actions' anchor.

3 / 3

Completeness

It clearly answers both 'what' ("Security code review for vulnerabilities... systematic review with confidence-based reporting") and 'when' with an explicit 'Use when...' clause, matching the anchor for clearly answering both what AND when.

3 / 3

Trigger Term Quality

It provides natural phrases users would actually say — "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review" — giving good coverage of common variations. It is not a 2 because the trigger set is broad and natural rather than sparse.

3 / 3

Distinctiveness Conflict Risk

The security-vulnerability niche is clear and the triggers are distinct from general code-review skills, making it unlikely to fire for the wrong skill. It is not a 2 because the scope is sharply scoped to security/exploitability rather than overlapping generic review.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
joe-bell/cva
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.