CtrlK
BlogDocsLog inGet started
Tessl Logo

review-security

Review a code change for injection, authentication and authorization bypasses, secrets in code or logs, insecure deserialization, SSRF, path traversal, cryptographic failures, feature-gate leaks, and protections disabled in production config. Use when reviewing for security, vulnerabilities, access control, or exploitable attack paths.

77

Quality

97%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exemplary single-file instruction skill: dense, concrete, and immediately usable, with named sinks, algorithms, and CWE mappings instead of generic advice. The threshold section's explicit include/exclude rules give the review process clear decision criteria, and nothing here is padded or redundant.

DimensionReasoningScore

Conciseness

The ~35-line body is lean and dense: it never explains concepts Claude already knows (it does not define SQL injection, SSRF, or CSRF, it only lists which patterns to look for), and every sentence carries actionable signal. This matches the 'every token earns its place' anchor; there are no over-explanation instances to trim, so score 4 does not apply.

5 / 5

Actionability

Guidance is fully concrete for an instruction-only skill: exact sinks are named ("untrusted input passed to pickle, Marshal, unserialize"), exact weak algorithms ("MD5, SHA-1, or unsalted SHA-256 instead of a purpose-built KDF"), an explicit method (trace "untrusted data from where it enters to the dangerous sink", compare gated paths with siblings), and a specific reporting format (title with OWASP/CWE, entry point, path, sink, impact, fix). Per the scoring notes for instruction-only skills, concrete specific guidance here earns the top anchor.

5 / 5

Workflow Clarity

This is a single-purpose skill under 50 lines, so the simple-skill exception applies: the Scope → Method → Threshold → Reporting sequence is unambiguous, with explicit decision rules (report unconfirmed critical patterns while stating what could not be confirmed; a concrete list of exclusions in the Threshold section). It is not a destructive or batch operation, so no validation loop is required.

5 / 5

Progressive Disclosure

No bundle files exist and none are needed at this size; the four well-organized sections (Scope, Method, Threshold, Reporting) carry the whole skill. Per the under-50-line guideline, well-organized sections alone merit the top score.

5 / 5

Total

20

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete, comprehensive capability list grounded in recognizable vulnerability classes, paired with an explicit 'Use when' trigger clause. The only weakness is that the trigger list could include a few more natural synonyms users might say when asking for a security pass.

DimensionReasoningScore

Specificity

The description lists nine concrete review capabilities — "injection, authentication and authorization bypasses, secrets in code or logs, insecure deserialization, SSRF, path traversal, cryptographic failures, feature-gate leaks, and protections disabled in production config" — which is comprehensive coverage of the security-review domain, matching the score-5 anchor rather than the 'minor gaps in coverage' of score 4.

5 / 5

Completeness

It explicitly answers both what ("Review a code change for injection, ... protections disabled in production config") and when ("Use when reviewing for security, vulnerabilities, access control, or exploitable attack paths") with concrete trigger phrases, exactly matching the score-5 anchor.

5 / 5

Trigger Term Quality

Trigger terms are natural phrases users would say ("reviewing for security, vulnerabilities, access control, or exploitable attack paths"), giving good keyword coverage. A few natural synonyms are missing (e.g., 'threats', 'penetration testing', 'is this code safe'), so it falls between the good-coverage anchor (4) and the comprehensive-synonyms anchor (5), and fits 4 better because the coverage is strong but not exhaustive.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear niche (security-focused review of code changes) with distinct trigger terms that select for security specifically, so conflict risk with general code-review or other skills is minimal — the score-5 anchor.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
perihelionhq/perihelion-platform-context
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.