CtrlK
BlogDocsLog inGet started
Tessl Logo

backend-security-coder

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

48

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/backend-security-coder/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

31%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a descriptive capability manifest rather than actionable guidance: it catalogs well-known security best practices at length, provides no executable instructions, and its only external reference is dangling. The one redeeming feature is a coherent high-level 9-step Response Approach sequence.

Suggestions

Replace the generic Capabilities/Behavioral Traits/Knowledge Base catalogs with skill-specific, actionable guidance (e.g., concrete validation patterns, code snippets, or checklists Claude wouldn't produce on its own).

Fix the dangling reference: either create `references/implementation-playbook.md` with the detailed material or remove the pointer to the nonexistent `resources/` path.

Move the bulk of the enumerated capability detail into a one-level-deep reference file and keep SKILL.md as a lean overview with clearly signaled links.

Add explicit validation checkpoints (e.g., how to verify auth flows, query parameterization, or header configuration) to the Response Approach workflow.

DimensionReasoningScore

Conciseness

The "Capabilities", "Behavioral Traits", and "Knowledge Base" sections spend ~130 lines restating standard secure-coding knowledge Claude already has ("OWASP Top 10 and secure coding guidelines", "Uses parameterized queries and prepared statements exclusively"), fitting the "noticeably verbose; several padded sections" anchor rather than the severely expository anchor 1.

2 / 5

Actionability

Guidance is high-level ("Apply relevant best practices and validate outcomes", "Implement input validation with comprehensive sanitization") with no code, commands, or specific steps; the only concrete pointer, `resources/implementation-playbook.md`, references a file that does not exist. The Response Approach provides high-level hints, placing it between the purely descriptive anchor 1 and anchor 2's minimal-guidance level.

2 / 5

Workflow Clarity

The "Response Approach" section lists a coherent ordered 9-step sequence ending in "Review and test security controls", but validation checkpoints are implicit and unoperationalized, matching the "steps listed but validation gaps" anchor rather than anchor 4's mostly-present checkpoints.

3 / 5

Progressive Disclosure

No bundle files exist at all, and the body inlines ~130 lines of capability catalogs that belong in separate reference files, while its single reference points to a nonexistent `resources/implementation-playbook.md` directory. This matches anchor 2's "content that clearly belongs in separate files is inlined" despite the presence of section headers.

2 / 5

Total

9

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with a clear "what" and an explicit "Use PROACTIVELY" trigger clause, naming three concrete specialization areas in third person. Its main gaps are missing common trigger synonyms and a "when" clause that could enumerate more concrete user scenarios.

Suggestions

Expand the trigger clause with concrete user phrasings, e.g. "Use when implementing authentication, fixing injection vulnerabilities, hardening APIs, or reviewing backend code for security issues".

Add natural keyword variations users would actually say — "vulnerabilities", "secure coding", "OWASP", "hardening" — to improve trigger recall.

Consider narrowing or clarifying the "security code reviews" trigger to reduce overlap with dedicated security-audit skills.

DimensionReasoningScore

Specificity

"specializing in input validation, authentication, and API security" lists several concrete focus areas beyond naming the domain, though they are topics rather than concrete action verbs, so it falls short of the comprehensive anchor 5.

4 / 5

Completeness

It answers both "what" ("Expert in secure backend coding practices specializing in input validation, authentication, and API security") and "when" ("Use PROACTIVELY for backend security implementations or security code reviews"), but the "when" clause could name more concrete user triggers, matching anchor 4 rather than 5.

4 / 5

Trigger Term Quality

"backend security implementations", "security code reviews", and "input validation" are natural phrases users would say, but common variations like "vulnerabilities", "secure coding", "hardening", or "injection" are missing, which matches anchor 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

"secure backend coding" carves out a mostly distinct niche, but the "security code reviews" trigger invites overlap with closely related security-audit skills, fitting anchor 4 rather than the minimal-conflict anchor 5.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.