CtrlK
BlogDocsLog inGet started
Tessl Logo

octopus-security-audit

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/octopus-security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is actionable and the adversarial workflow is well-sequenced with validation, but it carries notable verbosity and references bundle files that are not present. Progressive disclosure and conciseness are the weakest areas.

Suggestions

Move the Fable 5.1 model-selection caveat and Codex host-adapter notes into referenced files (or trim them) to reduce token overhead in SKILL.md.

Replace the CI/CD comment-only 'dangerous patterns' with executable grep/awk commands so the guidance is copy-paste ready.

Add an explicit validation checkpoint to the Quick scan path (e.g. 'Confirm no false positives above the confidence gate before reporting') so both modes have feedback loops.

DimensionReasoningScore

Conciseness

The body is mostly efficient with concrete commands, but the Codex host blockquote, the MANDATORY Execution Contract, and the dense Fable 5.1 caveat add padding and over-explanation that could be trimmed, matching the 3 anchor rather than 4.

3 / 5

Actionability

It provides copy-paste bash for orchestration, secrets archaeology (git log --pickaxe-regex), and supply-chain checks, but the CI/CD 'dangerous patterns' are listed as comments rather than executable grep commands, leaving a minor gap.

4 / 5

Workflow Clarity

The squeeze workflow sequences Blue Team → Red Team → Remediation → Validation with an explicit validation/retest checkpoint, but the Quick scan path lacks a comparable validation step, so it does not reach 5.

4 / 5

Progressive Disclosure

Section headers give some structure and references are signaled, but the referenced files (skills/blocks/codex-host-adapter.md, agents/personas/security-auditor.md) do not exist in the bundle and large blocks (Fable caveat, OWASP list) are inlined rather than split out, fitting the 3 anchor.

3 / 5

Total

14

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, distinct, and answers both what and when, but the trigger guidance is generic and lacks synonyms that users might naturally say. It is strong but not exemplary.

Suggestions

Add concrete trigger phrases and synonyms, e.g. 'Use when the user asks for a security audit, pentest, vulnerability scan, OWASP review, or red-team testing'.

Expand the 'what' to mention secrets/credential detection and CI/CD review to better reflect the skill's full capability set.

Keep the description tight; avoid adding the host-adapter or Fable-model caveats, which belong in the body.

DimensionReasoningScore

Specificity

Names the security domain and lists three concrete actions — 'OWASP compliance, vulnerability scanning, and adversarial red team testing' — but stops short of the comprehensive coverage (e.g. secrets detection, CI/CD review) shown in the body, so it sits at 4 rather than 5.

4 / 5

Completeness

It states both what (OWASP compliance, vulnerability scanning, red team testing) and when ('use for security reviews'), but the 'when' clause is generic rather than enumerating concrete trigger phrases, matching the 4 anchor better than 5.

4 / 5

Trigger Term Quality

Natural terms like 'security reviews', 'OWASP compliance', 'vulnerability scanning', and 'red team testing' are present, but common synonyms such as 'security audit', 'pentest', or 'security check' are missing, so it does not reach 5.

4 / 5

Distinctiveness Conflict Risk

The OWASP/red-team niche is clearly delimited with distinct triggers and minimal overlap risk with other skills, fitting the 5 anchor; it is not the broader 4 anchor since the domain is tightly scoped.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
nyldn/claude-octopus
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.