CtrlK
BlogDocsLog inGet started
Tessl Logo

octopus-security-audit

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/skill-security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with concrete executable commands and a well-sequenced adversarial workflow, but it is padded with security concepts Claude already knows and inlines material that would benefit from separate reference files.

Suggestions

Move the OWASP Top 10 category list and the STRIDE threat-modeling table into a reference file, keeping only a one-line pointer in SKILL.md, to cut concept re-explanation Claude doesn't need.

Add an explicit validation step to the Quick scan path (e.g. verify findings against the changed-file scope before reporting) so both modes have checkpoints.

Split the secrets-archaeology and CI/CD audit command blocks into a dedicated references file and link to them, improving progressive disclosure and reducing SKILL.md length.

DimensionReasoningScore

Conciseness

The body is mostly concrete commands, but it inlines concepts Claude already knows — a full OWASP Top 10 category list and a STRIDE table that re-explains each category with definitional questions — which could be trimmed for token efficiency.

3 / 5

Actionability

Provides copy-paste-ready, fully executable commands throughout (orchestrate.sh spawn/squeeze/auto invocations, git log pickaxe searches for secrets, find/grep patterns for CI/CD and supply-chain audits) covering the common cases.

5 / 5

Workflow Clarity

The squeeze workflow is a clearly sequenced 4-phase cycle (Blue → Red → Remediation → Validation) with an explicit validation feedback loop, but the default Quick scan path has no validation checkpoint, leaving a minor gap.

4 / 5

Progressive Disclosure

Sections and tables provide structure and external references (persona file, fable5-prompting.md) are signaled, but reference-style content (OWASP list, STRIDE table, secrets-archaeology commands) is inlined in SKILL.md rather than split into bundle files.

3 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, distinct, and answers both what the skill does and when to use it. Its main weakness is a generic 'use for security reviews' clause that lacks concrete trigger phrases and slightly incomplete capability coverage.

Suggestions

Expand the 'when' clause with concrete trigger phrases, e.g. 'Use when the user asks to find vulnerabilities, run a security audit, pentest an API, or check for OWASP issues'.

Add the missing core capabilities (secrets/credential detection, security configuration review) to the 'what' list for more comprehensive coverage.

Include common synonyms like 'pentest' and 'security audit' alongside 'red team testing' to broaden natural trigger term coverage.

DimensionReasoningScore

Specificity

Names the security domain and lists three concrete actions ('OWASP compliance, vulnerability scanning, and adversarial red team testing'), but omits capabilities covered in the body like secrets detection and config review, leaving minor gaps.

4 / 5

Completeness

Has both a clear 'what' (the three actions) and an explicit 'when' clause ('use for security reviews'), but the 'when' is generic rather than enumerating concrete trigger phrases, falling short of a 5.

4 / 5

Trigger Term Quality

Includes natural phrases users say ('vulnerability scanning', 'red team testing', 'OWASP', 'security reviews') with good coverage, but omits common synonyms like 'pentest' and 'security audit' that appear only in the trigger field.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear security-audit niche with distinctive triggers (OWASP, red team, vulnerability scanning) that are unlikely to fire for unrelated skills, giving minimal conflict risk.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
nyldn/claude-octopus
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.