CtrlK
BlogDocsLog inGet started
Tessl Logo

cc-skill-security-review

This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints.

50

Quality

55%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/cc-skill-security-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete code and per-category verification checklists, which is its core strength. But it is badly imbalanced for progressive disclosure: SKILL.md carries ~460 lines of example code Claude largely already knows, while the reference file duplicates the checklists instead of holding the detail. Condensing the body to a compact review workflow plus checklists, and moving the code examples into the reference, would fix both the conciseness and structure problems at once.

Suggestions

Cut the body to a short ordered review procedure (read guide -> work through categories -> run the pre-deployment checklist -> report findings), moving the per-category code examples into references/detailed-guide.md.

Trim or remove code demonstrations of practices Claude already knows (httpOnly cookies, parameterized queries, zod, DOMPurify, npm audit); the verification checklists alone carry the value.

Fix the non-executable examples: replace the fabricated '@solana/web3.js' verify usage and the unspecified '@/lib/csrf' import with working code or drop those sections.

DimensionReasoningScore

Conciseness

The ~460-line body extensively demonstrates practices Claude already knows (parameterized queries, httpOnly cookies, zod validation, DOMPurify, npm audit), and references/detailed-guide.md largely duplicates the body's verification checklists. It is noticeably verbose with several sections that could be reduced to their checklists alone; it escapes a 1 only because there is little prose explanation, just over-long demonstration.

2 / 5

Actionability

Nearly all guidance is concrete, executable TypeScript, SQL, and bash with per-section verification checklists. Minor gaps keep it below 5: the Solana example uses a non-existent '@solana/web3.js' verify export and invented Transaction fields, and the CSRF example imports an unspecified '@/lib/csrf' helper.

4 / 5

Workflow Clarity

Sections are numbered and each ends with verification checklists (good checkpoints), but there is no overall sequenced review procedure, no prioritization, and no feedback loop tying the checklists into an ordered process. The pre-deployment checklist that would serve as the workflow is buried in the reference file rather than surfaced as steps.

3 / 5

Progressive Disclosure

The reference is real, one level deep, and clearly signaled ('Read the detailed guide before executing this skill'), but the split is inverted: nearly all detailed material (full code examples per category) is inlined in SKILL.md while the reference adds only a redundant checklist and links. Content that clearly belongs in the reference is inline, matching anchor 3 rather than 4.

3 / 5

Total

12

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly follows the what/when pattern with explicit, natural trigger phrases, which is its main strength. However, the capability statement is generic security-speak without a single concrete action, and its broad 'all code' framing creates overlap risk with general code-review skills. Adding one or two concrete capabilities (e.g., 'audits for hardcoded secrets, SQL injection, XSS') would lift it substantially.

Suggestions

Replace the generic 'ensures all code follows security best practices' with 2-3 concrete capabilities, e.g., 'Audits code for hardcoded secrets, injection flaws, and XSS; verifies auth checks and rate limiting'.

Broaden trigger coverage with common user phrasings like 'secrets', 'credentials', 'security review', or 'vulnerabilities' to reduce missed activations.

Narrow the scope claim from 'all code' to the listed scenarios to reduce conflict with general code-review skills.

DimensionReasoningScore

Specificity

The description names the security domain but its actions ('ensures all code follows security best practices', 'identifies potential vulnerabilities') are generic; no concrete capabilities such as auditing for hardcoded secrets, SQL injection, or XSS are stated. It is not a 3 because no specific concrete action is actually named, only abstract guarantees.

2 / 5

Completeness

Both 'what' ('ensures all code follows security best practices and identifies potential vulnerabilities') and 'when' ('Use when implementing authentication...') are explicitly present. Not 5 because the 'what' is high-level rather than concrete, and not 3 because the 'when' clause is explicit with multiple triggers.

4 / 5

Trigger Term Quality

Triggers like 'implementing authentication or authorization', 'handling user input or file uploads', and 'creating new API endpoints' are natural phrases users would say. It falls short of 5 because common variations such as 'secrets', 'credentials', 'security review', 'SQL injection', or 'XSS' are absent.

4 / 5

Distinctiveness Conflict Risk

'All code follows security best practices' is broad and would overlap with general code-review and security-audit skills, though the auth/input/endpoint triggers add some distinctiveness. It sits between anchor 2's high overlap risk and anchor 4's minor overlap, closer to the middle.

3 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.