CtrlK
BlogDocsLog inGet started
Tessl Logo

secure-at-inception

Proactive security scanning for newly generated or modified code. Intelligently detects changes, runs appropriate scans (SAST, SCA, IaC), filters to only NEW issues, and prevents vulnerabilities at the source. Use this skill when: - Agent generates new code files - Agent modifies existing code - User asks to "scan for security issues" or "check my changes" - Before committing changes - User mentions "secure at inception", "proactive scan", or "security check"

77

Quality

96%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced, token-efficient skill body with strong validation checkpoints. Its main weakness is progressive disclosure: it duplicates reference-file content inline rather than linking to the existing bundle files.

Suggestions

Replace the inline severity-threshold table in Phase 4.1 with a one-line pointer to references/severity-thresholds.md, which already contains the full four-mode plus per-scan-type detail.

Trim the inline File Type -> Scan Type table and point to references/supported-languages.md for the exhaustive language/manifest/IaC list, keeping only a minimal mapping in SKILL.md.

Add explicit markdown links (e.g. 'See [supported-languages.md](references/supported-languages.md)') so the existing bundle files are clearly signaled and navigable.

DimensionReasoningScore

Conciseness

Dense, reference-style body of tables, parameters, and decision logic that assumes Claude's competence and does not explain what SAST/SCA/IaC or basic concepts are; nearly every token earns its place.

5 / 5

Actionability

Provides fully executable guidance — exact git diff commands, MCP tool names with concrete parameters (path, severity_threshold, all_projects), hunk-parsing syntax, a copy-paste report template, and a .snyk policy YAML example covering the common cases.

5 / 5

Workflow Clarity

Clear five-phase sequence with explicit validation checkpoints (SAST hunk-range filtering, SCA Net Improvement Rule, IaC new-resource-block filter, Block Decision Logic) and feedback loops for error recovery and false-positive suppression.

5 / 5

Progressive Disclosure

The body is well-sectioned and real reference files exist (severity-thresholds.md, supported-languages.md), but they are never linked or signaled from the body — instead their content is partly duplicated inline, so content that belongs in separate files is inlined and references are buried.

3 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-structured description that clearly states concrete capabilities and provides explicit, natural-language trigger guidance. It concisely answers both what the skill does and when to invoke it.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'detects changes', 'runs appropriate scans (SAST, SCA, IaC)', 'filters to only NEW issues', 'prevents vulnerabilities at the source' — giving comprehensive coverage of the scan workflow rather than vague abstractions.

5 / 5

Completeness

Explicitly answers both 'what' (proactive security scanning, change detection, scan execution, new-issue filtering) and 'when' via a concrete 'Use this skill when:' clause with five trigger bullets.

5 / 5

Trigger Term Quality

Includes natural user phrases with synonyms — 'scan for security issues', 'check my changes', 'Before committing changes', 'secure at inception', 'proactive scan', 'security check' — covering the ways a user would actually request this skill.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (Snyk-backed proactive new-code scanning) with distinctive trigger phrases like 'secure at inception', giving minimal overlap with other skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.