CtrlK
BlogDocsLog inGet started
Tessl Logo

security-review

Security-focused code review checklist for identifying vulnerabilities

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./templates/template-github-review-agent/workspace/skills/security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The SKILL.md body is an efficient, well-structured checklist: terse actionable security checks organized by category, a severity taxonomy, and a correctly signaled one-level-deep reference file that exists in the bundle. Its only weakness is minor — no explicit guidance on how to act on or report findings after classification.

DimensionReasoningScore

Conciseness

The body is a lean, checklist-style reference ('SQL injection: Look for string concatenation in database queries') with no padding and no explanations of concepts Claude already knows. Every bullet adds a check Claude would not otherwise be told to perform, so every token earns its place.

5 / 5

Actionability

Most checks are concrete and specific ('unsanitized input passed to shell commands (`exec`, `spawn`)', 'password/token comparison uses constant-time comparison'), and as an instruction-only skill the absence of code is not penalized. A few items such as 'Look for privilege escalation paths' remain high-level without how-to detail, keeping it just below fully executable guidance.

4 / 5

Workflow Clarity

This is a single-task skill whose action ('check each category below') is unambiguous, and the severity-level taxonomy tells Claude how to classify findings. However, there is no guidance on what to do after a finding (fix it vs. report it, or in what order), which is a minor gap that keeps it below 5.

4 / 5

Progressive Disclosure

The body is a well-organized overview that appropriately externalizes the detailed checklist to a single one-level-deep, clearly signaled reference (`references/security-checklist.md`), which exists in the bundle and contains the complementary detailed checklist. Content is appropriately split and navigation is easy.

5 / 5

Total

18

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and names a clear niche, but it omits any 'when to use' trigger guidance and lists only one generic capability. Adding a 'Use when...' clause with natural trigger phrases (e.g., security audit, find vulnerabilities, secure coding) would raise both completeness and trigger-term quality.

Suggestions

Add a 'Use when...' clause with concrete trigger phrases, e.g., 'Use when reviewing code for security issues, auditing for vulnerabilities, or investigating injection, authentication, or secret-exposure risks.'

Enumerate 2-3 concrete capability areas (e.g., 'checks for injection flaws, authentication/authorization gaps, hardcoded secrets, and data exposure') to strengthen specificity.

Include common user phrasings and synonyms such as 'security audit', 'find vulnerabilities', and 'secure coding' to improve natural trigger-term coverage.

DimensionReasoningScore

Specificity

The description names the domain ('security-focused code review') and one concrete action ('identifying vulnerabilities'), matching the anchor for a domain plus 1-2 actions that is not comprehensive. It does not list specific checks (injection, authentication, secrets), so it falls short of the several-actions anchor at 4.

3 / 5

Completeness

It has a clear 'what' (a security-focused code review checklist for identifying vulnerabilities) but no 'Use when...' clause or any equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. It is not a 2 because the 'what' half is clear and specific rather than vague.

3 / 5

Trigger Term Quality

'Security', 'code review', and 'vulnerabilities' are natural phrases users would say when needing this skill, giving good keyword coverage. A few common variations ('security audit', 'find vulnerabilities', 'secure coding') are missing, so it sits between the 3 and 4 anchors, noticeably above the midpoint.

4 / 5

Distinctiveness Conflict Risk

'Security-focused' carves out a clear niche distinct from general code-review or document skills, but the shared 'code review' phrasing creates minor overlap risk with generic code-review skills. It lacks the distinct trigger phrases of the anchor 5 example, so it fits 'mostly distinct; minor overlap risk'.

4 / 5

Total

14

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

13

/

16

Passed

Repository
mastra-ai/mastra
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.