CtrlK
BlogDocsLog inGet started
Tessl Logo

security-fix

Orchestrates test-driven fixes for Mattermost security tickets (Jira/Atlassian) with a Staff Security Engineer mindset: failing secure-behavior tests first, then implementation, then security review and edge-case loops, then opening a non-draft PR that follows `.github/PULL_REQUEST_TEMPLATE.md` when present, with a vague public description (no exploit detail). Use when the user invokes /security-fix:security-fix with a mattermost.atlassian.net browse URL, MM-* security work, backend permission or authorization bugs, or asks for this security TDD workflow.

65

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./plugins/security-fix/skills/security-fix/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

70%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body lays out a clearly sequenced, validated TDD workflow with strong actionability and feedback loops. Its main weaknesses are moderate verbosity and an all-inlined structure that misses progressive-disclosure opportunities.

Suggestions

Trim mindset framing and redundant restatements of the orchestrator-only rule to reduce token overhead in the conciseness dimension.

Move the PR description policy table and anti-patterns list into a references/PR_POLICY.md file, signaling it from SKILL.md, to improve progressive disclosure.

Add the concrete test-running command(s) for Phase 1/Phase 2 so the actionability guidance is fully copy-paste ready.

DimensionReasoningScore

Conciseness

Mostly efficient but padded in places—phrases like 'Mindset: Staff Security Engineer writing a regression contract' and repeated restatements of the orchestrator-only rule add tokens Claude does not need; could be tightened.

3 / 5

Actionability

Gives concrete, executable guidance (phase responsibilities, deliverables, explicit template handling, a worked PR-text avoid/prefer table) with only minor gaps such as missing exact test-run commands.

4 / 5

Workflow Clarity

Sequenced phases with explicit validation checkpoints (tests must fail for the right reason in Phase 1, must pass in Phase 2) and a clear feedback loop (Phase 3 failing tests re-trigger Phase 2), plus a numbered orchestrator checklist.

5 / 5

Progressive Disclosure

Well-organized into clear sections with no bundle files, but all content is inlined in SKILL.md with no external references; the PR-policy and anti-pattern material could live in separate reference files for a cleaner overview.

3 / 5

Total

15

/

20

Passed

Description

85%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete, well-scoped, and clearly states both what the skill does and when to invoke it, with strong trigger terms tied to the specific workflow. It is slightly long and could trim some narrative detail without losing clarity.

DimensionReasoningScore

Specificity

Lists several concrete actions ('failing secure-behavior tests first, then implementation, then security review and edge-case loops, then opening a non-draft PR'), with minor gaps in coverage around ticket-fetching mechanics.

4 / 5

Completeness

Explicitly answers both what it does (TDD-orchestrated security fixes) and when to use it via a concrete 'Use when the user invokes...' clause with specific trigger conditions.

5 / 5

Trigger Term Quality

Includes natural triggers like 'MM-* security work', 'backend permission or authorization bugs', and the exact '/security-fix:security-fix' invocation plus Jira browse URL; a few common synonyms are absent but coverage is good.

4 / 5

Distinctiveness Conflict Risk

The Mattermost/Jira security-TDD niche is distinct with clear triggers; minor overlap risk with general fix or PR skills, but the security-TDD framing keeps it mostly separable.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
mattermost/mattermost-ai-marketplace
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.