CtrlK
BlogDocsLog inGet started
Tessl Logo

octopus-security-audit

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content with concrete executable commands and useful tables, but it carries boilerplate and redundant inline material, time-sensitive model identifiers, and references external files that are not present in the skill bundle.

Suggestions

Trim the Codex host-adapter preamble and MANDATORY execution-contract boilerplate, and merge the overlapping Capabilities and OWASP Top 10 lists into one to reduce redundancy.

Move the Fable 5 / model-name guidance into a dedicated 'model selection' reference file or a clearly marked notes section so time-sensitive identifiers do not pad the main body.

Either ship the referenced files (codex-host-adapter.md, security-auditor.md, fable5-prompting.md) as bundle files under references/ or restate their key content inline, so progressive-disclosure links actually resolve.

Add an explicit validation checkpoint to the Quick-scan workflow (e.g., verify findings against the confidence gate before reporting) to lift workflow clarity above 2.

DimensionReasoningScore

Conciseness

Mostly efficient with concrete commands, but includes boilerplate (Codex host-adapter preamble, the MANDATORY execution contract) and redundant lists (Capabilities overlaps the OWASP Top 10 list), plus time-sensitive model identifiers ("claude-fable-5", "claude-opus-5", "gpt-5.2-codex") outside any deprecated section, so it could be tightened.

2 / 3

Actionability

Provides fully executable, copy-paste-ready commands (git log secret searches, find .github/workflows, grep patterns, orchestrate.sh invocations) plus concrete STRIDE and severity tables, matching the 'fully executable code/commands' anchor.

3 / 3

Workflow Clarity

The 4-phase squeeze cycle and confidence gates give some sequencing, but the primary Quick-scan flow is a mode table without explicit validate-then-proceed checkpoints, and batch codebase scanning should cap at 2 without verification steps.

2 / 3

Progressive Disclosure

Well-sectioned headers and signaled references exist, but the referenced paths (skills/blocks/codex-host-adapter.md, agents/personas/security-auditor.md) do not resolve to any bundle files (no references/scripts/assets dirs), and content that could be split (OWASP list, capabilities, STRIDE) is inline, so it is not the clear one-level-deep reference structure of a 3.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, specific description that names three concrete security actions and provides an explicit use-trigger, clearly answering both what the skill does and when to invoke it.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "OWASP compliance, vulnerability scanning, and adversarial red team testing" — matching the anchor for several specific concrete actions rather than vague language.

3 / 3

Completeness

Explicitly answers what (OWASP/vulnerability/red-team testing) and when ("use for security reviews"), an explicit trigger clause equivalent to 'Use when...', so it is not capped at 2.

3 / 3

Trigger Term Quality

Covers natural terms a user would actually say ("OWASP", "vulnerability scanning", "adversarial red team testing", "security reviews"), giving good domain coverage; it is above the 'some relevant keywords but missing variations' anchor.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear security-audit niche with distinct triggers unlikely to fire for unrelated skills, matching the 'clear niche with distinct triggers' anchor.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
nyldn/claude-octopus
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.