CtrlK
BlogDocsLog inGet started
Tessl Logo

security-auditor

Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response. Use PROACTIVELY for security audits, DevSecOps, or compliance implementation.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/security-auditor/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

35%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-sectioned persona definition, but it is verbose and largely enumerates knowledge Claude already has while giving only high-level, non-executable process guidance. It also lacks validation checkpoints for its intrusive-testing workflow and inlines a capability catalog that would be better split into a reference file.

Suggestions

Trim the Capabilities section: move the tool/framework enumerations into a references file and keep only the security-specific guidance Claude would not already infer, to improve conciseness.

Make the workflow actionable: replace abstract steps like "Run targeted scans" with concrete examples (specific tools, severity thresholds, report structure) or link to a reference with executable commands.

Add an explicit validation checkpoint to the audit workflow (e.g. validate findings before reporting, re-verify fixes, require written approval before any intrusive test) to satisfy the feedback-loop requirement for destructive operations.

DimensionReasoningScore

Conciseness

The body is noticeably verbose, padding tokens with long enumerations of tools and framework acronyms Claude already knows (e.g. "SonarQube, Checkmarx, Veracode, Semgrep, CodeQL", "GDPR, HIPAA, PCI-DSS, SOC 2, ISO 27001, NIST"), matching the 2 anchor's "several unnecessary padded sections" rather than the 3 anchor's "some".

2 / 5

Actionability

Steps are high-level hints ("Run targeted scans", "Prioritize findings by severity and business impact with remediation steps") with no concrete executable specifics such as which scans, severity thresholds, or report formats, matching the 2 anchor rather than the 3 anchor which requires some concrete guidance.

2 / 5

Workflow Clarity

A clear numbered sequence exists (Instructions 1-5, Response Approach 1-9) but validation checkpoints and feedback loops are absent; because intrusive security testing is a destructive/batch context, workflow_clarity is capped at 3 per the rubric guideline.

3 / 5

Progressive Disclosure

No bundle files exist, and the body has section structure, but the large inlined capability/tool catalog (~75 lines of enumerations) is bulk content that belongs in a separate reference file, matching the 3 anchor rather than the 4 anchor's "mostly appropriately placed".

3 / 5

Total

10

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it explicitly covers both what the skill does and when to use it, with concrete capability areas and natural trigger phrasing. Its main weakness is trigger-term breadth, where a few common synonyms and variations are missing.

DimensionReasoningScore

Specificity

Lists multiple concrete capability areas ("vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation"; "DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response") with comprehensive coverage, matching the 5 anchor rather than the 4 anchor's "minor gaps".

5 / 5

Completeness

Explicitly answers both what ("Expert security auditor... Masters... Handles...") and when ("Use PROACTIVELY for security audits, DevSecOps, or compliance implementation") with concrete trigger phrases, matching the 5 anchor; the 4 anchor requires the "when" to be less explicit, which it is not.

5 / 5

Trigger Term Quality

Includes natural trigger phrases users would say ("security audits, DevSecOps, or compliance implementation", "Use PROACTIVELY") with good keyword coverage, but lacks synonym/variation coverage (e.g. "pentest", "vulnerability scan", "SOC2 audit") that would reach 5.

4 / 5

Distinctiveness Conflict Risk

Has a clear security/DevSecOps/compliance niche with distinct triggers and minimal conflict risk, but the broad "comprehensive cybersecurity" framing leaves minor overlap risk with adjacent skills, keeping it below the 5 anchor's "clear niche with minimal conflict risk".

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.