CtrlK
BlogDocsLog inGet started
Tessl Logo

backend-security-coder

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

39

Quality

37%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/backend-security-coder/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

20%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is a long persona/capability catalog with almost no executable guidance and no real bundle files behind its one reference. It needs concrete code patterns and a working reference file to become actionable.

Suggestions

Replace the enumerated capability and knowledge catalogs with concise, executable patterns (e.g. parameterized-query snippets, CSP header examples, CSRF token code).

Remove the triple repetition of the persona (Instructions preamble, Purpose, Behavioral Traits) and keep only task-relevant guidance to cut token weight.

Either create the referenced resources/implementation-playbook.md or drop the reference, and split the large inline catalogs into clearly signaled one-level reference files.

DimensionReasoningScore

Conciseness

The body is padded with enumerated categories Claude already knows (HTTP headers, CSRF, OAuth, OWASP Top 10) and restates the same persona three times (Instructions line 26, Purpose, Behavioral Traits), spending many tokens on background rather than task-specific guidance.

1 / 3

Actionability

It is almost entirely descriptive — bullet lists of capabilities and concepts like 'parameterized queries' and 'CSP implementation' with no executable code, commands, or concrete patterns Claude could apply directly.

1 / 3

Workflow Clarity

The Response Approach gives a 9-step sequence and Instructions mention 'validate outcomes' and 'verification', but there are no explicit validation checkpoints, error-recovery loops, or verification commands, which the rubric caps at 2 for risky/destructive contexts.

2 / 3

Progressive Disclosure

It signals a one-level reference ('open resources/implementation-playbook.md'), but that file does not exist and the bulk of the content is a monolithic inline capability catalog that should itself be split into references, so structure is present but poorly organized.

2 / 3

Total

6

/

12

Passed

Description

55%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is competent and covers both what and when, but reads more as a terse capability tag than a user-trigger-oriented sentence. Strengthening trigger phrasing and listing a couple more concrete actions would lift it.

Suggestions

Rewrite the trigger clause in third person around natural user phrasing, e.g. 'Use when the user asks to implement or review secure backend code, authentication, or API security.'

Add one or two more concrete actions (e.g. 'prevents injection attacks, hardens authentication') to move from a domain summary to a list of specific actions.

Add a short disambiguator against the security-auditor skill so it is less likely to trigger for audit/compliance requests.

DimensionReasoningScore

Specificity

It names a domain (secure backend coding) and several concrete sub-areas ('input validation, authentication, and API security'), but is a single-sentence summary rather than a list of multiple distinct concrete actions, matching the 'names domain and some actions' anchor.

2 / 3

Completeness

It clearly states what the skill does, and 'Use PROACTIVELY for backend security implementations or security code reviews' gives explicit when-guidance, but the trigger is framed as a directive to Claude rather than a natural user-need clause, leaving completeness just short of the strongest anchor.

2 / 3

Trigger Term Quality

It includes relevant natural keywords ('backend security', 'security code reviews', 'API security'), but phrases like 'Use PROACTIVELY' are authoring instruction rather than a user-natural trigger, and common variations ('secure coding', 'vulnerability', 'authentication') are only partially covered.

2 / 3

Distinctiveness Conflict Risk

It carves a niche ('secure backend coding' vs auditing) but overlaps meaningfully with a sibling security-auditor skill and general coding skills, so it could still trigger for related-but-wrong tasks.

2 / 3

Total

8

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/antigravity-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.