CtrlK
BlogDocsLog inGet started
Tessl Logo

007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

52

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

—

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./skills/007/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

35%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is comprehensive in scope but severely over-engineered for a SKILL.md file. It inlines content that belongs in reference files (full playbooks, detailed checklists, complete framework explanations), resulting in a massive document that wastes context window. The hardcoded Windows paths, unverifiable script references (no bundle provided), and extensive explanation of concepts Claude already understands (STRIDE categories, PASTA stages) significantly reduce its effectiveness.

Suggestions

Move the detailed playbooks, checklists, STRIDE/PASTA explanations, and scoring tables into the referenced files (references/*.md) and keep only a concise summary with links in SKILL.md — this could reduce the file by 60-70%.

Replace hardcoded Windows paths (C:\Users\renat\skills\007\scripts\) with relative paths or a configurable base path variable.

Add explicit validation/completion criteria between the 6 phases (e.g., 'Phase 1 is complete when the attack surface JSON is generated and reviewed') to create proper feedback loops.

Remove explanations of well-known concepts (what STRIDE letters stand for, what PASTA stages are) and instead just reference the framework with a link to the detailed guide in references/.

DimensionReasoningScore

Conciseness

Extremely verbose at 400+ lines. Explains concepts Claude already knows (what STRIDE stands for, what PDF is equivalent explanations for security concepts). Contains massive checklists, full playbook text, and extensive tables that could be in reference files. Hardcoded Windows file paths (C:\Users\renat\...) add noise. The 'When to Use' and 'Do Not Use' sections are boilerplate. Much content repeats what's in the referenced files.

1 / 3

Actionability

Provides concrete checklists, structured playbooks, and specific script commands, which is good. However, the scripts referenced (surface_mapper.py, threat_modeler.py, etc.) are not provided in the bundle, making them unverifiable. The hardcoded Windows paths reduce portability. The playbooks give step-by-step procedures but are more procedural guidance than executable code.

2 / 3

Workflow Clarity

The 6-phase analysis process is clearly sequenced with a visual flow diagram, and each phase is well-defined. However, there are no explicit validation checkpoints between phases — the skill says '007 nunca pula fases' but doesn't define what constitutes completion of each phase or how to verify before proceeding. The incident playbooks have good step sequences but lack verification steps.

2 / 3

Progressive Disclosure

References to 10+ reference files and multiple scripts are listed at the bottom, which is good structure. However, the main SKILL.md is a monolithic wall of text that inlines enormous amounts of content (full playbooks, complete checklists, detailed STRIDE/PASTA explanations) that should be in those reference files. The references section exists but the body doesn't effectively delegate content to them.

2 / 3

Total

7

/

12

Passed

Description

82%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description excels at listing specific, concrete security capabilities with strong domain-specific trigger terms that users would naturally use. Its main weakness is the absence of an explicit 'Use when...' clause, which would help Claude know precisely when to select this skill. The breadth of security topics covered ('for any project') is both a strength in coverage and slightly risky in being overly broad.

Suggestions

Add a 'Use when...' clause such as 'Use when the user asks about security vulnerabilities, penetration testing, threat analysis, compliance checks, or securing code/infrastructure.'

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions: security audit, hardening, threat modeling with named frameworks (STRIDE/PASTA), Red/Blue Team exercises, OWASP checks, code review, incident response, and infrastructure security.

3 / 3

Completeness

Clearly answers 'what does this do' with a comprehensive list of security capabilities, but lacks an explicit 'Use when...' clause or equivalent trigger guidance, which caps this at 2 per the rubric guidelines.

2 / 3

Trigger Term Quality

Includes strong natural keywords users would say: 'security audit', 'threat modeling', 'OWASP', 'code review', 'incident response', 'Red/Blue Team', 'hardening', 'STRIDE', 'PASTA'. These cover a wide range of security-related terms users would naturally use.

3 / 3

Distinctiveness Conflict Risk

The security domain is clearly defined with distinct terminology (STRIDE, PASTA, OWASP, Red/Blue Team) that is unlikely to conflict with non-security skills. The combination of these specific security frameworks and activities creates a clear niche.

3 / 3

Total

11

/

12

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 9 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (656 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

9

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.