CtrlK
BlogDocsLog inGet started
Tessl Logo

security-best-practices

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

82

1.18x
Quality

73%

Does it follow best practices?

Impact

97%

1.18x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No known issues

Fix and improve this skill with Tessl

tessl review fix ./skills/.curated/security-best-practices/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured loader/router for a multi-reference security skill, with strong progressive disclosure and a sound overall workflow. It is held back by verbosity/overlap between sections, implicit rather than crisp validation checkpoints, and the absence of concrete report/finding examples.

Suggestions

Merge the 'Workflow' and 'Workflow Decision Tree' sections to remove overlapping phrasing and tighten prose like 'This skill provides a description of how to...'.

Add a concrete minimal report template (e.g., a short markdown skeleton with an executive summary, severity sections, and a sample finding with ID/impact/line-number) to lift actionability from prose to copy-paste-ready.

Make verification checkpoints explicit in the Fixes flow (e.g., 'run the project's tests; only commit when they pass; report regressions before proceeding') instead of phrasing them as considerations.

DimensionReasoningScore

Conciseness

It largely assumes Claude's competence and avoids explaining basic concepts, but the Workflow and Workflow Decision Tree sections overlap, and several passages ('This skill provides a description of how to...') are padded and could be tightened, keeping it below the lean level-3 anchor.

2 / 3

Actionability

It gives concrete specifics (the `<language>-<framework>-<stack>-security.md` filename convention, `security_best_practices_report.md`, report sections with numeric IDs and line numbers), but lacks any example report/finding template and includes vague fallbacks ('think a little bit about what you know', 'search online'), fitting 'some concrete guidance but incomplete'.

2 / 3

Workflow Clarity

The identify→load→operate→report→fix sequence and decision tree are present, and verification is mentioned (testing flows, regression checks, 'inform the user before making them'), but the checkpoints are phrased as optional considerations rather than explicit validate→fix→retry gates, matching the level-2 anchor.

2 / 3

Progressive Disclosure

The body is a clear overview that routes to a real, one-level-deep references/ directory (11 files matching the documented `<language>-<framework>-<stack>-security.md` and `<language>-general-<stack>-security.md` conventions, including the specifically named `javascript-general-web-frontend-security.md`), with content appropriately split per language/framework.

3 / 3

Total

9

/

12

Passed

Description

90%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: third-person voice, explicit trigger guidance with both positive and negative conditions, and a clearly scoped niche. Its only weakness is moderate specificity — it names the domain and a couple of actions rather than a rich list of concrete capabilities.

DimensionReasoningScore

Specificity

Names the domain ('security best-practice reviews') and two actions ('reviews and suggest improvements') but does not enumerate multiple concrete actions like the level-3 anchor, so it is comprehensive in domain yet limited in action breadth.

2 / 3

Completeness

It answers both what (perform security best-practice reviews and suggest improvements) and when, with an explicit trigger clause ('Trigger only when the user explicitly requests...'), satisfying the level-3 'Use when' equivalent requirement.

3 / 3

Trigger Term Quality

It surfaces natural terms users would actually say ('security best practices guidance', 'a security review/report', 'secure-by-default coding help') plus supported languages and explicit negative triggers ('general code review, debugging, or non-security tasks').

3 / 3

Distinctiveness Conflict Risk

A clear niche (security best practices for python/javascript/typescript/go) with explicit negative triggers ('Do not trigger for general code review, debugging, or non-security tasks') makes conflict with adjacent skills unlikely.

3 / 3

Total

11

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openai/skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.