CtrlK
BlogDocsLog inGet started
Tessl Logo

security-audit

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

57

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/security-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

47%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The command catalog is concrete and executable, but the body squanders tokens duplicating the frontmatter, provides no workflow sequencing or validation checkpoints for batch/destructive security operations, and all of its file references point to nonexistent or wrong paths. It reads as a command menu rather than a guided skill.

Suggestions

Replace the flat command catalog with a sequenced workflow (e.g., full scan -> triage findings by severity -> targeted re-checks -> remediate -> re-scan to verify the fix), with explicit validation checkpoints before and after any remediation step.

Fix the bundle paths so the Scripts table points to 'scripts/security-scan.sh' and 'scripts/cve-remediate.sh' (not '.agents/scripts/'), and either create the referenced 'docs/security-checklist.md' and 'docs/owasp-top10.md' or remove the References table.

Delete the Purpose, When to Trigger, and When to Skip sections (they restate the frontmatter description verbatim) and the redundant first command example, keeping only the Best Practices items that are specific to this skill.

DimensionReasoningScore

Conciseness

The command catalog itself is lean and assumes Claude's competence, but there is substantial unnecessary content: the Purpose, When to Trigger, and When to Skip sections repeat the frontmatter description almost verbatim, the first command's 'Example' merely reprints it with one extra flag, and Best Practices is generic filler ('Use hierarchical topology for coordination') — matching anchor 3's 'mostly efficient but includes some unnecessary... could be tightened'. Not a 2 because there is no explanation of concepts Claude already knows and the core content (commands) is efficient.

3 / 5

Actionability

Commands are fully executable copy-paste-ready npx invocations with concrete examples covering common cases ('security scan --depth full --output security-report.json', 'cve --scan --severity high') — matching anchor 4's 'mostly executable guidance; concrete code or commands with minor gaps'. Not a 5 because several checks (path traversal, SQL injection, XSS, threat modeling, secrets) lack examples and no output or interpretation guidance is given for any command.

4 / 5

Workflow Clarity

There is no sequence at all — the body is a flat catalog of nine commands with no recommended order, no guidance on interpreting results, and no validation checkpoints, while the operations are batch/destructive-leaning (scanning a codebase, auto-remediating CVEs), which caps the score at 3 and the near-total absence of a defined workflow matches anchor 2's 'rough sequence present but many gaps; steps poorly defined; validation absent'. It does not reach 3 because not even an implicit step order or checkpoint exists in the body.

2 / 5

Progressive Disclosure

Scored against the actual bundle: the Scripts table points to '.agents/scripts/security-scan.sh' and '.agents/scripts/cve-remediate.sh' but the real files live at 'scripts/', and the References table points to 'docs/security-checklist.md' and 'docs/owasp-top10.md' which do not exist anywhere — every cross-reference is broken, making navigation impossible and matching anchor 2 ('references are buried/minimal effective structure'). Section headers exist (which keeps it above 1), but it cannot score 3 or higher when following every referenced path fails.

2 / 5

Total

11

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it explicitly answers both what the skill does and when to use/skip it, with concrete capability lists and natural trigger phrases in third person. The main gaps are missing synonyms for well-known security terms (SQL injection, XSS, secrets) that users commonly say when they need this skill.

DimensionReasoningScore

Specificity

Lists several concrete actions — 'input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement' — matching the 'lists several specific actions; minor gaps in coverage' anchor. It falls short of 5 because coverage is not comprehensive (no mention of secrets detection, SQL injection, or XSS, all of which the skill body actually performs) and 'Comprehensive security scanning and vulnerability detection' is somewhat broad; it is clearly above anchor 3 because more than 1-2 concrete actions are named.

4 / 5

Completeness

Both questions are explicitly answered with concrete trigger phrases: 'Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection...' states what it does, 'Use when: authentication implementation, authorization logic, payment processing...' gives concrete triggers, and a 'Skip when' clause adds exclusion guidance — directly matching anchor 5. It is not a 4 because the 'when' is already explicit and specific rather than merely present.

5 / 5

Trigger Term Quality

Trigger phrases like 'authentication implementation', 'payment processing', 'file upload handling', 'database queries' are natural terms users would say when needing this skill — good keyword coverage per anchor 4. Not a 5: common variations and synonyms users would actually say are missing ('SQL injection', 'XSS', 'vulnerability', 'security review', 'secrets/credentials'), several of which correspond to the skill's own checks.

4 / 5

Distinctiveness Conflict Risk

The security-audit niche with security-specific triggers (payment processing, file upload handling, CVE detection) is mostly distinct with only minor overlap risk against general code-review or testing skills — matching anchor 4. Not a 5 because triggers like 'API endpoint creation' and 'database queries' could reasonably fire general code-review or database skills too.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ruvnet/ruflo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.