CtrlK
BlogDocsLog inGet started
Tessl Logo

secure-at-inception

Proactive security scanning for newly generated or modified code. Intelligently detects changes, runs appropriate scans (SAST, SCA, IaC), filters to only NEW issues, and prevents vulnerabilities at the source. Use this skill when: - Agent generates new code files - Agent modifies existing code - User asks to "scan for security issues" or "check my changes" - Before committing changes - User mentions "secure at inception", "proactive scan", or "security check"

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body with a clear phased workflow, concrete commands, parameters, and error-handling feedback loops. Its main weakness is progressive disclosure: the provided reference files are never linked from the body, which instead inlines duplicate condensed versions, hiding deeper material like Audit Mode.

Suggestions

Replace the inlined File Type → Scan Type and severity-mode tables with pointers to references/supported-languages.md and references/severity-thresholds.md, keeping only a minimal operational summary in the body — this would surface details like Audit Mode that are currently undiscoverable.

Specify a concrete cache mechanism for the 'Cache results keyed by file + content_hash with a 12-hour TTL' guidance (e.g., where the cache is stored and how to check it), or drop the caching instruction if no persistent mechanism is intended.

Trim the opening paragraph, which restates the frontmatter description almost verbatim, to reclaim tokens without losing information.

DimensionReasoningScore

Conciseness

The body is information-dense with almost no explanation of concepts Claude already knows — every table and command earns its place — but the opening paragraph largely restates the frontmatter description and the file-type/threshold tables duplicate material already in the reference files, leaving minor trimmable content short of the lean level-5 anchor.

4 / 5

Actionability

Concrete, mostly executable guidance throughout: exact git commands ('git diff --name-only HEAD', 'git diff -U0'), named MCP tools with parameters ('severity_threshold: "medium"', 'all_projects: true'), hunk-range parsing ('@@ -X,Y +A,B @@'), and a copy-ready '.snyk' policy YAML. The gap is 'Cache results keyed by file + content_hash with a 12-hour TTL', which specifies no storage mechanism, fitting level 4 rather than fully executable level 5.

4 / 5

Workflow Clarity

Five clearly sequenced phases (change detection → scans → filter → report/decision → metrics) with explicit block decision logic and genuine feedback loops: 'Retry once with smaller scope' for timeouts, auth error retry via 'snyk_auth', and suppress-then-'re-run to verify' for false positives. The skill is explicitly non-destructive ('Never modify code, only report findings'), so the batch-operation cap does not apply.

5 / 5

Progressive Disclosure

The body is well-sectioned, but the two actual bundle files (references/severity-thresholds.md and references/supported-languages.md) are never mentioned anywhere in the body — instead condensed duplicates of both (the File Type → Scan Type table and the severity mode table) are inlined, and content such as Audit Mode exists only in the unreferenced file. This matches the level-3 anchor: references present but not clearly signaled, content that should be separate is inline.

3 / 5

Total

16

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that explicitly covers both capability and invocation triggers with concrete, natural language. Its main weaknesses are mild buzzword padding ('Intelligently', 'prevents vulnerabilities at the source') and a few broad triggers that could collide with adjacent review/commit skills.

DimensionReasoningScore

Specificity

Lists several concrete actions ('Intelligently detects changes, runs appropriate scans (SAST, SCA, IaC), filters to only NEW issues') with comprehensive scope, but buzzword padding ('Intelligently', 'prevents vulnerabilities at the source') keeps it just below the level-5 anchor of clean comprehensive coverage.

4 / 5

Completeness

Explicitly answers both what ('detects changes, runs appropriate scans (SAST, SCA, IaC), filters to only NEW issues') and when, with a concrete five-item 'Use this skill when' trigger list — a clear match for the level-5 anchor requiring concrete trigger phrases.

5 / 5

Trigger Term Quality

Good natural trigger phrases users would actually say ('scan for security issues', 'check my changes', 'Before committing changes'), but misses common synonyms like 'vulnerability scan', 'security audit', or 'security review', fitting the level-4 'good coverage, a few natural terms missing' anchor rather than comprehensive level 5.

4 / 5

Distinctiveness Conflict Risk

The proactive new-code security scanning niche is mostly distinct with specific triggers ('secure at inception', 'proactive scan'), but generic triggers like 'check my changes' and 'Before committing changes' carry minor overlap risk with code-review and commit-message skills, matching level 4 rather than the minimal-conflict level 5.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.