CtrlK
BlogDocsLog inGet started
Tessl Logo

aif-security-checklist

Security audit checklist based on OWASP Top 10 and best practices. Covers authentication, injection, XSS, CSRF, secrets management, and more. Use when reviewing security, before deploy, asking "is this secure", "security check", "vulnerability".

63

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/aif-security-checklist/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable security checklist with excellent executable examples and a well-structured bundle of real reference files. Its weaknesses are length and duplication (verbose config/i18n policy, repeated logging/error items) and a main audit workflow that is implied across sections rather than presented as one explicit sequenced procedure.

Suggestions

Consolidate the main audit into one numbered "Audit workflow" section (read config → read SECURITY.md → run audit.sh → grep checks → findings + Ignored Items → gate-result JSON) so the sequence and its checkpoints are explicit rather than scattered.

Deduplicate the client-logging and raw-error guidance that appears in both the Pre-Deployment Checklist and the API "Client-Facing Logging & Errors" section, keeping one canonical location with a pointer from the other.

Tighten the Config/i18n section by stating the resolution rules once in a compact form, and move detailed category code (e.g., XSS output encoding, API error normalization) into the existing references/ files to keep SKILL.md a lean overview.

DimensionReasoningScore

Conciseness

The body is mostly checklists and executable code with little conceptual explanation Claude already knows, but at ~600 lines it could be tightened: the Config/i18n policy section is verbose and repetitive, and client-logging/error items are duplicated between the Pre-Deployment Checklist and the API "Client-Facing Logging & Errors" section. Anchor 3 ("mostly efficient but... could be tightened") fits; not anchor 4 given the padding and duplication.

3 / 5

Actionability

Copy-paste-ready material throughout: parameterized-query and zod-validation TypeScript, helmet header settings, concrete grep audit commands, git-history cleanup commands, and a runnable audit.sh script, with examples covering the common cases per category. Matches anchor 5; not anchor 4 because the examples are complete and executable rather than having minor gaps.

5 / 5

Workflow Clarity

The audit flow (read config FIRST, always read SECURITY.md, run audit.sh, grep checks, report with Ignored Items section, append gate-result JSON) is present but scattered across sections rather than given as one ordered sequence; only the ignore flow is numbered. Anchor 3 ("steps listed but... checkpoints missing or implicit") fits; not anchor 4 because the primary audit workflow must be assembled from multiple sections rather than followed directly.

3 / 5

Progressive Disclosure

Three real, clearly signaled, one-level-deep references ("→ read `references/AUTH-PATTERNS.md`" etc.) plus scripts/audit.sh, all verified to exist with no nested references. Anchor 4 ("good structure; most content appropriately placed; references mostly clear") fits; not anchor 5 because substantial category detail (XSS output encoding, secrets, API error-handling code) is inlined where the established reference-file pattern would keep the overview leaner, and not anchor 3 because references are clearly signaled and well organized.

4 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly states what the skill covers and when to invoke it, with natural trigger phrases. The main weaknesses are the slightly vague "and more" tail and missing common synonyms such as "audit" or "hardening" in the trigger list.

DimensionReasoningScore

Specificity

"Covers authentication, injection, XSS, CSRF, secrets management, and more" names several concrete coverage areas within the security-audit domain. It falls short of anchor 5 because it enumerates topics rather than concrete actions, and 'and more' is slightly padded; it exceeds anchor 3 because multiple specific areas are listed, not just 1-2.

4 / 5

Completeness

It explicitly answers both "what" ("Security audit checklist based on OWASP Top 10... Covers authentication, injection, XSS, CSRF, secrets management") and "when" with concrete quoted trigger phrases. This matches anchor 5; it is not anchor 4 because the "when" clause is fully explicit rather than merely present or imprecise.

5 / 5

Trigger Term Quality

"Use when reviewing security, before deploy, asking \"is this secure\", \"security check\", \"vulnerability\"" includes natural phrases a user would actually say. Not anchor 5 because common synonyms such as "audit", "pentest", "hardening", or "OWASP" are missing; clearly above anchor 3's partial keyword coverage.

4 / 5

Distinctiveness Conflict Risk

The security-audit niche with specific trigger phrases ("is this secure", "vulnerability", "before deploy") is mostly distinct. Not anchor 5 because "reviewing security" has minor overlap risk with generic code-review or security-review skills; well above anchor 3's broad overlap.

4 / 5

Total

17

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (610 lines); consider splitting into references/ and linking

Warning

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

13

/

16

Passed

Repository
lee-to/ai-factory
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.