CtrlK
BlogDocsLog inGet started
Tessl Logo

security-auditor

Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response. Use PROACTIVELY for security audits, DevSecOps, or compliance implementation.

53

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/security-auditor/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

20%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body reads as a persona/resume rather than actionable guidance: it is verbose with tool lists Claude already knows, provides no executable code or commands, and lacks validation checkpoints despite covering risky security operations. Structure exists but the capability catalog should be offloaded to reference files.

Suggestions

Replace the inline Capabilities/Behavioral Traits/Knowledge Base catalogs with a concise overview and move the detailed tool and standard lists into reference files under references/, keeping SKILL.md under ~50-80 lines.

Add concrete, executable guidance — example scan commands, sample SAST/DAST invocations, or a threat-modeling template — instead of abstract steps like 'Run targeted scans and manual verification'.

Insert explicit validation/verification checkpoints into the workflow (e.g., confirm authorization before intrusive testing, verify findings against false positives, re-test after remediation) to satisfy the feedback-loop requirement for risky security operations.

DimensionReasoningScore

Conciseness

The body is padded with material Claude already knows — a Capabilities catalog enumerating SonarQube/Checkmarx/Veracode/Semgrep/CodeQL, OWASP ZAP, Burp Suite, plus a Knowledge Base and Behavioral Traits restating standard security principles — matching the verbose 'explains concepts Claude knows' anchor rather than the tighter anchor 2.

1 / 3

Actionability

There is no executable code, no concrete commands, and no specific tool invocations; 'Instructions' and 'Response Approach' are abstract lists like 'Confirm scope, assets, and compliance requirements', matching the 'describes rather than instructs' anchor and falling short of anchor 2's partial concrete guidance.

1 / 3

Workflow Clarity

A numbered sequence exists (Instructions 1-5, Response Approach 1-9) but it has no validation checkpoints or feedback loops for inherently risky security testing, which caps the score per the rubric; it is above anchor 1 only because steps are actually listed and ordered.

2 / 3

Progressive Disclosure

The skill has no bundle files yet dumps a multi-hundred-line capability catalog inline with clear section headings; it is not the monolithic-nested anchor 1, but the inline catalog is content that should live in separate reference files, matching anchor 2's 'content that should be separate is inline'.

2 / 3

Total

6

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: third-person voice, concrete capability list, and an explicit proactive trigger clause covering both what and when. Minor risk is the broad 'comprehensive cybersecurity' phrasing and a somewhat narrow trigger set, but it clears each dimension.

DimensionReasoningScore

Specificity

The description lists many concrete actions and domains — 'vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation' and 'DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response' — matching the anchor for multiple specific concrete actions, not merely a named domain.

3 / 3

Completeness

It explicitly answers both what ('Masters...', 'Handles...') and when ('Use PROACTIVELY for security audits, DevSecOps, or compliance implementation'), matching the anchor that requires an explicit 'Use when'-style trigger, so it is not capped at 2.

3 / 3

Trigger Term Quality

The trigger clause 'Use PROACTIVELY for security audits, DevSecOps, or compliance implementation' uses natural terms a user would actually say; it would not score below 2 because the keywords are genuine user language rather than technical jargon.

3 / 3

Distinctiveness Conflict Risk

Security auditing framed around DevSecOps, compliance, and security audits is a clear niche with distinct triggers unlikely to fire for unrelated skills; it is not the generic 'helps with code and documents' anchor (1) nor merely 'works with document files' (2).

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.