CtrlK
BlogDocsLog inGet started
Tessl Logo

007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

50

Quality

55%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/agentic-awesome-skills-claude/skills/007/SKILL.md

The canonical home for this skill is 007 in sickn33/antigravity-awesome-skills

SKILL.md
Quality
Evals
Security

Quality

Content

43%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body functions as a lean activation pointer to a detailed guide, which is good for token efficiency, but it provides almost no executable guidance or workflow in the body itself and relies on a guide whose reference chain contains broken links. The bundled scripts are not surfaced at all.

Suggestions

Add a short inline workflow skeleton (e.g., the 6 audit phases with a validation checkpoint) so the body is actionable without forcing a full guide load.

Fix or remove the missing reference files cited in detailed-guide.md (hardening-linux.md, hardening-windows.md, payment-security.md, bot-security.md, compliance-matrix.md).

Mention the bundled scripts/ (quick_scan.py, full_audit.py, score_calculator.py) with one-line usage so the automation is discoverable from SKILL.md.

DimensionReasoningScore

Conciseness

The ~25-line body is lean and delegates detail to the guide, with only minor generic boilerplate in the "Do Not Use" and "Limitations" sections that could be trimmed.

4 / 5

Actionability

The body offers only high-level direction ("Read [the detailed guide]") and activation triggers; no concrete code, commands, or specific execution steps appear in the body itself, and the available scripts/ are not even mentioned.

2 / 5

Workflow Clarity

No multi-step audit sequence or validation checkpoints are present in the body; the 6-phase workflow lives entirely in the delegated guide, and for a destructive/batch-oriented audit skill the absence of inline validation guidance is a notable gap.

2 / 5

Progressive Disclosure

SKILL.md cleanly signals one-level-deep references to detailed-guide.md (which exists), but the guide's reference list then cites five files absent from the bundle (hardening-linux.md, hardening-windows.md, payment-security.md, bot-security.md, compliance-matrix.md), leaving navigation partially broken.

3 / 5

Total

11

/

20

Passed

Description

67%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is information-dense and names concrete capabilities, but it omits any explicit "Use when…" trigger guidance, which both limits completeness and leaves activation to inference. Trigger-term coverage is good but not comprehensive.

Suggestions

Add a "Use when the user asks for a security audit, threat model, pentest, hardening review, or incident response" clause so both what and when are explicit.

Include natural synonyms users actually say (pentest, vulnerability scan, hardening) alongside the methodology names.

Narrow "infrastructure security for any project" to a more distinctive scope to reduce overlap with generic code-review skills.

DimensionReasoningScore

Specificity

The description lists multiple concrete capabilities — "Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security" — giving comprehensive coverage of the domain.

5 / 5

Completeness

The "what" is clearly stated, but there is no "Use when…" clause or equivalent explicit trigger guidance, which per the rubric caps completeness at 3.

3 / 5

Trigger Term Quality

Natural keywords like "security audit", "threat model", "STRIDE", and "OWASP" are present and would be said by users, but common synonyms (pentest, vulnerability scan, hardening review) are not fully covered.

4 / 5

Distinctiveness Conflict Risk

Named methodologies (STRIDE/PASTA, Red/Blue Team, OWASP) give it a recognizable niche, but the broad phrasing "infrastructure security for any project" creates overlap risk with other security and code-review skills.

3 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/antigravity-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.