CtrlK
BlogDocsLog inGet started
Tessl Logo

007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

60

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/007/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

62%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is well-structured into a clear phased workflow with concrete playbooks and scoring, but it is over-long and monolithic, uses non-portable hardcoded script paths, and ships broken reference links.

Suggestions

Replace hardcoded "C:\\Users\\renat\\skills\\007\\scripts\\..." paths with portable relative paths (e.g. "scripts/quick_scan.py") so commands are executable everywhere.

Move the full STRIDE/PASTA tables, OWASP checklists, and incident playbooks into the existing reference files and leave concise inline pointers (e.g. "See [references/incident-playbooks.md]"), then remove the 5 referenced files that do not exist or create them.

Cut the generic "Best Practices", "Common Pitfalls", "Related Skills", and "Limitations" boilerplate and the duplicated Overview/"## 007" sections to reduce token weight.

DimensionReasoningScore

Conciseness

The body is mostly efficient domain reference material, but at ~630 lines it duplicates the Overview/header, repeats the "## 007" title, and carries generic boilerplate ("Best Practices", "Common Pitfalls", "Related Skills", "Limitations") that could be trimmed; not a 1 because it avoids explaining basic concepts Claude already knows.

2 / 3

Actionability

Provides concrete checklists, playbook templates, and a scoring rubric, but the automation commands hardcode Windows paths ("C:\\Users\\renat\\skills\\007\\scripts\\...") that are not copy-paste executable on other machines, falling short of fully executable guidance.

2 / 3

Workflow Clarity

The 6-phase process is clearly sequenced with an explicit phase diagram and a quantitative scoring/verdict checkpoint in Fase 6, and the incident playbooks follow a consistent CONTER→AVALIAR→REMEDIR→PREVENIR sequence with documented confirmation for destructive actions.

3 / 3

Progressive Disclosure

Reference files are listed, but the body is a monolithic wall that inlines full STRIDE/PASTA tables, checklists, and playbooks that overlap the separate reference files; references are listed at the end rather than signaled inline, and 5 of the 10 referenced files (hardening-linux/windows, payment-security, bot-security, compliance-matrix) do not exist.

2 / 3

Total

9

/

12

Passed

Description

82%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and rich in natural trigger terms with a clear, distinctive niche, but it omits an explicit "Use when..." trigger clause, which caps completeness at 2.

Suggestions

Add an explicit trigger clause, e.g. ". Use when the user asks for a security audit, threat modeling, hardening, or incident response." to satisfy the completeness dimension.

Consider mirroring one or two of the strongest natural triggers (e.g. "penetration test", "pentest") that users may say but are currently absent from the description.

DimensionReasoningScore

Specificity

Lists multiple concrete actions and domains — "Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security" — matching the anchor for enumerating several specific actions.

3 / 3

Completeness

Clearly answers "what" but lacks an explicit "Use when..." trigger clause in the description itself; the when-guidance lives only in the body, so per the rubric completeness is capped at 2.

2 / 3

Trigger Term Quality

Includes natural terms a user would say ("security audit", "threat model", "STRIDE", "hardening", "OWASP checks") with good coverage of common variations; not just jargon.

3 / 3

Distinctiveness Conflict Risk

The security-audit/threat-modeling niche with STRIDE/PASTA and OWASP triggers is clearly distinct and unlikely to fire for unrelated skills.

3 / 3

Total

11

/

12

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (656 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 5 missing

Warning

Total

13

/

16

Passed

Repository
sickn33/antigravity-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.