CtrlK
BlogDocsLog inGet started
Tessl Logo

007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

50

Quality

55%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/007/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

43%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, correctly structured pointer that delegates everything to a real detailed guide, but it delegates too much: no workflow, modes, or validation checkpoints appear in the body, the scripts bundle is invisible, and the guide's own reference list includes five broken paths. Surfacing a quick-start mode summary, the scripts, and the real reference files would lift actionability and workflow clarity substantially.

Suggestions

Add a brief quick-start section in the body: the audit modes (audit, threat-model, approve, block, monitor, incident) and how to invoke the scripts, e.g. `python scripts/quick_scan.py` vs `python scripts/full_audit.py`.

Fix or remove the five broken cross-references in the detailed guide (hardening-linux.md, hardening-windows.md, payment-security.md, bot-security.md, compliance-matrix.md) and list the actual reference files in the body so they are discoverable.

Include a short sequenced workflow in the body (map attack surface → threat model → checklists → red team → blue team → verdict) with an explicit validation/checkpoint step, so the multi-phase process does not depend entirely on the external guide.

DimensionReasoningScore

Conciseness

The body is lean with no concept explanations Claude already knows — a short pointer to the detailed guide, trigger lists, and limitations. It falls short of the lean anchor because of mechanical repetition ("or related topics" repeated in all six trigger bullets) and boilerplate filler like "The task is unrelated to 007" and "A simpler, more specific tool can handle the request", which earn little per token.

4 / 5

Actionability

The only concrete instruction in the body is "Read [the detailed guide](references/detailed-guide.md) before executing this skill" — a pointer with no steps, commands, or code, and the body never mentions the executable bundle in scripts/ (full_audit.py, quick_scan.py, score_calculator.py) at all. This matches the anchor of minimal concrete guidance with high-level hints but missing the specific steps to execute; it is above score 1 only because the pointer is an explicit, real, actionable directive.

2 / 5

Workflow Clarity

This skill is a multi-mode, six-phase audit process, yet the body contains no sequenced steps — the entire workflow is delegated to the guide, leaving only a rough read-then-execute order with many gaps. It is not score 1 because the directive to load guide sections for focused work vs. reading completely gives a coherent, if minimal, order; it cannot be higher since no phases, modes, or validation checkpoints appear in the body itself.

2 / 5

Progressive Disclosure

The body's single reference is well-signaled and one level deep (detailed-guide.md exists), but scoring against the actual bundle reveals problems: the guide cross-references 10 files of which 5 do not exist (hardening-linux.md, hardening-windows.md, payment-security.md, bot-security.md, compliance-matrix.md), and the scripts/ directory plus 4 other reference files are never surfaced in the body. This fits the anchor of some structure with organizational gaps — better than buried or monolithic, but not the good-structure anchor given the broken paths and undiscoverable bundle resources.

3 / 5

Total

11

/

20

Passed

Description

67%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong on concrete, framework-specific capabilities and reasonable trigger terms, but it never tells Claude when to activate it and the "for any project" scope plus generic terms like "code review" create real overlap risk with other security and review skills. Adding an explicit "Use when..." clause would resolve the completeness cap.

Suggestions

Append an explicit trigger clause, e.g. "Use when the user asks for a security audit, threat model, pentest, hardening review, or incident response for a codebase or infrastructure."

Trim scope-broadening language like "for any project" and reconsider listing "code review", which conflicts with dedicated code-review skills; keep the distinctive security-specific terms.

Add missing natural synonyms users would say — "pentest", "penetration testing", "vulnerability assessment" — to improve trigger term coverage.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — "Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security" — naming specific frameworks (STRIDE/PASTA, OWASP) rather than generic language. This matches the anchor for comprehensive coverage of specific concrete actions; it is not score 4 because there are no meaningful gaps in the action list, only the breadth qualifier "for any project".

5 / 5

Completeness

The "what" is clear and comprehensive, but there is no "Use when..." clause or equivalent explicit trigger guidance — the description is a pure capability list. Per the judging guidelines, a missing 'Use when' clause caps completeness at 3, which is exactly the anchor for a clear 'what' with 'when' missing or only weakly implied; it cannot be 4 without any explicit 'when'.

3 / 5

Trigger Term Quality

Natural phrases users would say are present ("security audit", "threat model", "hardening", "STRIDE"), giving good keyword coverage. It falls short of the comprehensive anchor because common synonyms such as "pentest", "vulnerability assessment", or "penetration testing" are absent (they appear only in frontmatter tags, not the description).

4 / 5

Distinctiveness Conflict Risk

Distinctive frameworks (STRIDE/PASTA, OWASP, Red/Blue Team) give it a recognizable niche, but "code review" overlaps with general code-review skills, "incident response" and "infrastructure security" are broad, and "for any project" widens the net considerably. This fits the anchor for somewhat specific but still overlapping with similar skills, not the mostly-distinct anchor above.

3 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.