CtrlK
BlogDocsLog inGet started
Tessl Logo

code-vuln-audit

Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. Use when the user mentions security scans, vulnerability detection, secret leaks, API keys, OWASP, npm audit, pip-audit, hardcoded passwords, or code security checks.

77

Quality

96%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered reference for a bundled scanner: fully executable commands verified against the actual script, complete flag and exit-code documentation, and zero general-knowledge padding. The only structural improvement would be moving the per-pattern detection tables into a references file to keep SKILL.md closer to a lean overview.

DimensionReasoningScore

Conciseness

The body is dense and tool-specific: every table documents what the bundled scanner actually detects (regex patterns, OWASP mappings, CLI flags, exit codes) rather than explaining concepts Claude already knows. There is no padding, no library tutorials, and no general security-education prose, matching the 'every token earns its place' anchor.

5 / 5

Actionability

The Quick Start gives copy-paste-ready commands covering all common cases (all-checks scan, each individual mode, JSON output with a file path, severity filtering), and the Parameters table documents every flag the bundled script actually supports (verified against scripts/security_scan.py). Output examples make result interpretation concrete. This matches the fully executable, common-cases-covered anchor.

5 / 5

Workflow Clarity

This is a single-action, read-only skill (run one scanner command) and the single action is unambiguous, which per the simple-skill guideline can score 5. Checkpoints are present in the forms that matter here: the Exit Codes table (0/1/2) defines feedback semantics, the Prerequisites section explains the degrade gracefully path when npm/pip-audit is missing, and severity/format flags let the user control results. No destructive or batch mutation is involved, so the validation cap does not apply.

5 / 5

Progressive Disclosure

Structure is good: clear sections (Quick Start, module details, Parameters, Output Format, Exit Codes, Prerequisites) and the only bundle file, scripts/security_scan.py, is real and referenced directly in executable commands. However, the module-detail tables (secret regex patterns, OWASP mappings) are inline reference material that could live in a references/ file, and at ~150 lines the body is somewhat heavier than a pure overview — 'most content appropriately placed, minor organization gaps' fits anchor 4 better than anchor 5's clean overview-plus-split-references shape.

4 / 5

Total

19

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that names three concrete capabilities with their detection methods and provides an explicit, well-populated 'Use when...' trigger clause in third person. The only weakness is mild overlap risk between its generic trigger phrases ('security scans', 'code security checks') and general security/code-review skills.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions: 'dependency vulnerabilities (npm/pip audit)', 'secret leaks (regex and entropy analysis)', and named OWASP anti-patterns 'SQL injection, XSS, or command injection'. It uses third person voice ('Scan code') and matches the comprehensiveness of the score-5 anchor ('Extract text and tables from PDF files, fill forms, merge documents') with no over-claims or buzzwords.

5 / 5

Completeness

It explicitly answers 'what' (three named scanning capabilities with parenthetical methods) and 'when' via an explicit 'Use when the user mentions...' clause with concrete trigger phrases, exactly matching the score-5 anchor pattern. A score of 4 would require the 'when' to be less explicit, which it is not.

5 / 5

Trigger Term Quality

'security scans, vulnerability detection, secret leaks, API keys, OWASP, npm audit, pip-audit, hardcoded passwords, or code security checks' covers natural phrasings users would actually say, including tool names ('npm audit', 'pip-audit'), category terms, and concrete leak types. Coverage is comparable to the anchor example's 'PDF files, PDFs, forms, document extraction, .pdf' breadth; not below it since both technical and colloquial variants are present.

5 / 5

Distinctiveness Conflict Risk

It has a clear niche (static code security scanning) with distinct triggers like 'OWASP', 'npm audit', 'pip-audit', but generic triggers such as 'security scans' and 'code security checks' carry minor overlap risk with broader code-review or general security-audit skills. Mostly distinct with minor overlap risk fits anchor 4 better than anchor 5's 'minimal conflict risk'.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.