CtrlK
BlogDocsLog inGet started
Tessl Logo

backend-security-coder

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

39

Quality

37%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-awesome-skills-claude/skills/backend-security-coder/SKILL.md

The canonical home for this skill is backend-security-coder in sickn33/agentic-awesome-skills

SKILL.md
Quality
Evals
Security

Quality

Content

7%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill reads as a persona description or role-playing prompt rather than an actionable skill document. It exhaustively catalogs security topics Claude already knows well (OWASP Top 10, SQL injection, JWT, etc.) without providing any concrete code examples, specific implementation patterns, or executable guidance. The content is extremely verbose with no token efficiency, and the referenced implementation-playbook.md doesn't exist in the bundle.

Suggestions

Replace the extensive capability/knowledge listings with 3-5 concrete, executable code examples showing secure patterns (e.g., parameterized query in Python, JWT validation middleware, CSP header configuration) — these are what Claude actually needs.

Add explicit validation/verification steps to the workflow, such as specific security testing commands, linting tools (e.g., bandit, semgrep), or checklist items to verify before completing a security implementation.

Remove the 'Behavioral Traits', 'Knowledge Base', 'Capabilities' catalog, and 'Example Interactions' sections — these describe what Claude already knows and waste context window. Focus on project-specific patterns, preferred libraries, and anti-patterns unique to this codebase.

Create the referenced 'resources/implementation-playbook.md' with concrete code templates and include additional reference files for specific security domains (auth, API security, database security) to properly leverage progressive disclosure.

DimensionReasoningScore

Conciseness

Extremely verbose and padded with information Claude already knows. The massive capability listings (OWASP Top 10, SQL injection prevention, JWT handling, etc.) are all well-known concepts to Claude. The 'Behavioral Traits', 'Knowledge Base', 'Example Interactions', and 'Purpose' sections are largely redundant descriptions of what a security expert does rather than actionable instructions. The content could be reduced by 80%+ without losing utility.

1 / 3

Actionability

Despite being a coding-focused skill, there is zero executable code, no concrete commands, no specific examples with input/output, and no copy-paste ready snippets. The content is entirely descriptive ('Implement secure user authentication with JWT') rather than instructive with actual implementation patterns. The 'Response Approach' is a vague 9-step list of abstract actions.

1 / 3

Workflow Clarity

The 'Response Approach' section lists 9 high-level steps but they are abstract and lack any validation checkpoints, error recovery loops, or concrete sequencing. For a skill involving security implementations (which are inherently risky/destructive if done wrong), there are no verification steps, no testing commands, and no feedback loops.

1 / 3

Progressive Disclosure

There is one reference to 'resources/implementation-playbook.md' for detailed examples, which is a good signal. However, no bundle files exist to support this reference, and the massive inline content (capability lists, behavioral traits, knowledge base) should have been split into separate reference files rather than included in the main SKILL.md.

2 / 3

Total

5

/

12

Passed

Description

67%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has a clear structure with both 'what' and 'when' components, which is its strongest aspect. However, it operates at a category level rather than listing specific concrete actions, and its trigger terms, while relevant, miss many natural phrases users would employ when seeking security help. The domain is identifiable but could overlap with adjacent skills.

Suggestions

Add more specific concrete actions, e.g., 'Implements JWT authentication, sanitizes user inputs against SQL injection and XSS, configures rate limiting, reviews code for OWASP Top 10 vulnerabilities'.

Expand trigger terms to include natural user phrases like 'SQL injection', 'XSS', 'CSRF protection', 'OAuth', 'password hashing', 'vulnerability scan', 'OWASP', '.env secrets'.

DimensionReasoningScore

Specificity

Names the domain (backend security) and some actions (input validation, authentication, API security, security code reviews), but these are more like categories than concrete actions. It doesn't list specific tasks like 'sanitize SQL queries, implement JWT token validation, configure CORS headers'.

2 / 3

Completeness

Clearly answers both 'what' (secure backend coding practices specializing in input validation, authentication, and API security) and 'when' (Use PROACTIVELY for backend security implementations or security code reviews), with an explicit trigger clause.

3 / 3

Trigger Term Quality

Includes some relevant keywords like 'input validation', 'authentication', 'API security', and 'security code reviews', but misses many natural user terms like 'SQL injection', 'XSS', 'CSRF', 'OAuth', 'password hashing', 'authorization', 'OWASP', or 'vulnerability'.

2 / 3

Distinctiveness Conflict Risk

The focus on 'backend security' provides some distinctiveness, but terms like 'authentication' and 'API security' could overlap with general backend development skills, API design skills, or broader security skills. The scope is somewhat broad within the security domain.

2 / 3

Total

9

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.