CtrlK
BlogDocsLog inGet started
Tessl Logo

backend-security-coder

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

48

Quality

52%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/backend-security-coder/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

35%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-organized but verbose capability catalogue that mostly restates security knowledge Claude already has, with no executable code or concrete commands and only a high-level workflow lacking validation checkpoints. It would benefit from trimming the enumeration and pointing to reference files for detail.

Suggestions

Replace the long capability/knowledge enumerations with a concise core of non-obvious guidance, and move the detailed technique lists into reference files linked one level deep.

Add executable examples or concrete commands (e.g., a parameterized-query snippet, a CSP header configuration) instead of only describing the practices.

Insert explicit validation/feedback checkpoints into the Response Approach workflow (e.g., 'run security lint/test, if failures found fix and re-run') so review and implementation steps have retry loops.

DimensionReasoningScore

Conciseness

The body is a noticeably verbose enumeration of security concepts Claude already knows (OWASP Top 10, parameterized queries, bcrypt/Argon2, HSTS, CSP), padded with long capability lists that restate common knowledge rather than adding novel guidance.

2 / 5

Actionability

It names specific technologies (bcrypt, Argon2, JWT, PKCE, CSP nonces) but provides no executable code, commands, or concrete step-by-step instructions — the Response Approach is high-level hints like 'Implement input validation with comprehensive sanitization' rather than copy-paste-ready guidance.

2 / 5

Workflow Clarity

The Response Approach gives a 9-step numbered sequence, but validation/verification is reduced to a single vague final step ('Review and test security controls') with no checkpoints or fix-retry feedback loops, which caps security-review workflows at 3.

3 / 5

Progressive Disclosure

The content is well-sectioned with headers, but with no bundle files present the entire capability inventory, behavioral traits, and knowledge base are inlined in one ~145-line file rather than split into one-level-deep reference files.

3 / 5

Total

10

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly states both what the skill does and when to use it with reasonably natural trigger phrases, and it carves out a recognizable backend-security niche. Its main weakness is naming capability categories rather than concrete actions and keeping the trigger scenarios to just two.

DimensionReasoningScore

Specificity

Names the domain ('secure backend coding practices') and several sub-areas ('input validation, authentication, and API security'), but these are categories rather than concrete executable actions like 'configure CSP headers' or 'implement parameterized queries'.

3 / 5

Completeness

It answers both 'what' (expert in secure backend coding specializing in input validation, authentication, API security) and 'when' ('Use PROACTIVELY for backend security implementations or security code reviews'), but the 'when' lists only two scenarios and could be more specific.

4 / 5

Trigger Term Quality

'backend security implementations' and 'security code reviews' are phrases a user would naturally say, giving good keyword coverage, though common variations like 'vulnerability', 'OWASP', or 'penetration testing' are missing.

4 / 5

Distinctiveness Conflict Risk

'Secure backend coding' focused on input validation, authentication, and API security is a mostly distinct niche with minor overlap risk against a closely related security-auditor skill.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.