CtrlK
BlogDocsLog inGet started
Tessl Logo

octopus-security-audit

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

56

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/skill-security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is strong on executable commands and the adversarial workflow includes a genuine validation loop, but it is padded with concepts Claude already knows (OWASP category enumeration, STRIDE definitions) and duplicated usage examples. Referenced detail files are absent from the bundle, so the skill reads as an inlined monolith rather than an overview pointing to references.

Suggestions

Remove or move the OWASP Top 10 category list and the STRIDE threat table into a reference file — Claude already knows both frameworks; keeping them inline wastes context.

Consolidate the three separate orchestrate.sh example blocks (Usage, Adversarial Mode, Advanced Options) into a single usage section to eliminate repetition.

Ship the referenced bundle files (skills/blocks/fable5-prompting.md, agents/personas/security-auditor.md) or remove the dangling references, so every cited path resolves.

Tighten the Model Selection Caveat section — its dense policy text mixes time-sensitive model IDs with routing rules that could be shortened to the decision rule plus the reference pointer.

DimensionReasoningScore

Conciseness

The body inlines concepts Claude already knows — the full OWASP Top 10 category list and a six-row STRIDE table ('Spoofing | Can an attacker impersonate a user or component?') — and repeats orchestrate.sh usage examples three times (Usage, Adversarial Mode, Advanced Options). This is noticeably verbose with several padded sections, below the 'mostly efficient' midpoint.

2 / 5

Actionability

Provides concrete, executable commands throughout — 'git log --all -p -S 'AKIA' --pickaxe-regex', 'orchestrate.sh squeeze --loop --quality 100', the CI/CD find command. Not a 5 because the CI/CD 'Check for dangerous patterns' block is descriptive commentary rather than executable checks, leaving minor gaps.

4 / 5

Workflow Clarity

The squeeze workflow is a clearly sequenced 4-phase cycle (Blue Team, Red Team, Remediation, Validation) with an explicit feedback loop — 'Antigravity re-tests, confirms fixes or fails' — and the mode auto-escalation rules are unambiguous. Not a 5 because Quick mode lacks report-format or follow-up guidance and the document's duplicated structure scatters the two entry points.

4 / 5

Progressive Disclosure

No bundle files exist, yet the body references 'skills/blocks/fable5-prompting.md' and 'agents/personas/security-auditor.md' — paths that do not resolve in this bundle. Inline reference material (OWASP list, STRIDE table, git-history commands) should live in separate files. Some structure exists via sections and tables, but organization into one-level-deep references is absent.

3 / 5

Total

13

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, well-formed description that names concrete capabilities and includes an explicit use-for clause. It sits solidly at the 'good' level across all dimensions, falling short of excellent only on breadth of trigger synonyms and specificity of the when-clause.

DimensionReasoningScore

Specificity

Names three concrete capabilities — 'OWASP compliance', 'vulnerability scanning', 'adversarial red team testing' — with only minor coverage gaps (no mention of secrets detection or CI/CD auditing). Not a 3 because it lists several specific actions rather than 1-2; not a 5 because coverage is not comprehensive.

4 / 5

Completeness

Has a clear 'what' (three named capabilities) and an explicit 'when' ('use for security reviews'). Not a 5 because the when-clause is generic and lacks concrete trigger phrases; not a 3 because both what and when are explicitly present.

4 / 5

Trigger Term Quality

Includes natural phrases users would say: 'vulnerability scanning', 'red team testing', 'security reviews', 'OWASP'. Not a 5 because common variations like 'pentest', 'security audit', and 'find vulnerabilities' are absent.

4 / 5

Distinctiveness Conflict Risk

The security niche is well-differentiated via distinct triggers ('OWASP', 'adversarial red team'), with only minor overlap risk against generic code-review or dependency-audit skills. Not a 5 because 'security reviews' is broad enough to collide with adjacent security-adjacent skills.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
nyldn/claude-octopus
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.