CtrlK
BlogDocsLog inGet started
Tessl Logo

security-fix

Orchestrates test-driven fixes for Mattermost security tickets (Jira/Atlassian) with a Staff Security Engineer mindset: failing secure-behavior tests first, then implementation, then security review and edge-case loops, then opening a non-draft PR that follows `.github/PULL_REQUEST_TEMPLATE.md` when present, with a vague public description (no exploit detail). Use when the user invokes /security-fix:security-fix with a mattermost.atlassian.net browse URL, MM-* security work, backend permission or authorization bugs, or asks for this security TDD workflow.

69

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered orchestration skill: phases are clearly sequenced with explicit red/green validation gates, a hardening loop, and an anti-patterns section that reinforces the policy. Its only weaknesses are mild redundancy between the checklist, phases, and anti-patterns, and a few places where concrete commands are left implicit.

DimensionReasoningScore

Conciseness

The body assumes Claude's competence with no basic-concept padding and every section carries operational instructions, but the orchestrator checklist restates phase details and the anti-patterns section repeats earlier PR-policy statements, leaving minor trimming opportunities (anchor 4, not 5).

4 / 5

Actionability

Concrete, executable-for-an-instruction-skill guidance throughout: an exact invocation example, single-responsibility phases with explicit deliverables, a template-existence check, and an avoid/prefer table for PR wording. Minor gaps remain (no concrete test-run commands; Jira fetch left as 'Atlassian MCP (or the project's configured Jira integration)'), so it sits below fully copy-paste-ready anchor 5.

4 / 5

Workflow Clarity

Clear phased sequence with explicit validation checkpoints (Phase 1 tests must 'fail for the right reason'; Phase 2 must make them pass), a documented feedback loop (Phase 3 findings re-spawn Phase 2 until no new gaps), and an orchestrator checklist — exactly the anchor-5 pattern of explicit validation, error-recovery loops, and a checklist.

5 / 5

Progressive Disclosure

No bundle files exist and the single-file body is well organized with clear section headers, but at ~95 lines it exceeds the under-50-line simple-skill case that earns a 5; the PR-template policy and examples table could plausibly live in a reference file, matching anchor 4's minor organization gaps.

4 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit what/when structure and a clearly distinct Mattermost security-TDD niche. It is let down slightly by verbosity and a couple of missing natural trigger synonyms.

DimensionReasoningScore

Specificity

Lists multiple concrete sequenced actions ('failing secure-behavior tests first, then implementation, then security review and edge-case loops, then opening a non-draft PR that follows `.github/PULL_REQUEST_TEMPLATE.md`'), but density is diluted by filler like 'with a Staff Security Engineer mindset', placing it just below the anchor-5 example of comprehensive, cleanly enumerated actions.

4 / 5

Completeness

Explicitly answers both 'what' (orchestrated TDD fix pipeline through a non-draft PR) and 'when' ('Use when...' with concrete trigger phrases), matching the anchor-5 example; not 4 because the when-clause is fully explicit rather than merely present.

5 / 5

Trigger Term Quality

'Use when the user invokes /security-fix:security-fix with a mattermost.atlassian.net browse URL, MM-* security work, backend permission or authorization bugs, or asks for this security TDD workflow' covers good natural triggers (security tickets, Jira, MM-*, permission/authorization bugs) but misses common synonyms such as 'vulnerability' or 'CVE'.

4 / 5

Distinctiveness Conflict Risk

Highly niche triggers ('Mattermost security tickets (Jira/Atlassian)', 'mattermost.atlassian.net browse URL', 'MM-* security work') make confusion with other skills very unlikely; matches the clear-niche anchor 5.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
mattermost/mattermost-ai-marketplace
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.