CtrlK
BlogDocsLog inGet started
Tessl Logo

secure-code-review

Systematically reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities, providing vulnerable code examples and ready-to-use remediation guidance. Trigger this skill when users ask for a security review, vulnerability scan, or penetration testing assistance, or mention keywords like OWASP, SQL injection, XSS, code audit, or security checklist.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured security review checklist whose main costs are token weight and monolithic layout. The code examples are excellent, but redundant risk explanations, a duplicated quick-reference table, and the absence of any reference-file split mean the whole 19KB body loads into context every invocation.

Suggestions

Move the per-category vulnerable/remediation code examples into one-level-deep reference files (e.g., references/A01-access-control.md ... A10-ssrf.md) and keep only the Quick Reference table, SOP, and report template in SKILL.md.

Delete the per-category 'Risk:' paragraphs and the Quick Reference table's overlap with the detailed checkpoints — keep one of the two, since Claude already knows what each OWASP category is.

Add a verify step to the SOP (e.g., 're-confirm each RED finding by reading the cited file:line in full context before writing the report') to close the workflow's validation gap.

DimensionReasoningScore

Conciseness

The bulk of the body is concrete vulnerable/fixed code pairs that earn their tokens, but the per-category 'Risk:' statements (e.g., 'Users can access other users' data or perform unauthorized operations') re-explain OWASP concepts Claude already knows, and the Quick Reference table duplicates the A01–A10 checkpoint content almost verbatim. Mostly efficient but could be tightened by cutting the risk prose and the redundant table.

3 / 5

Actionability

Every category ships complete, executable vulnerable-vs-fixed code pairs (parameterized queries, bcrypt hashing, `is_safe_url` SSRF guard), plus runnable scan commands (`pip audit`, `npm audit`) and a fill-in report template with required fields. This is fully copy-paste ready guidance covering the common cases.

5 / 5

Workflow Clarity

The 'Review Process SOP' gives a clear 5-step sequence with a full-coverage requirement ('Every item must appear in the report... mark items with no findings as pass'), a RED/YELLOW/GREEN severity scheme, mandated `file:line_number` references, and a structured output template — most checkpoints are present. Minor gap: no verify step for re-confirming RED findings against actual code context before reporting, which slightly inflates false positives.

4 / 5

Progressive Disclosure

The skill has no bundle files at all (no references/, scripts/, or assets/), so all ~570 lines live inline in SKILL.md. Section headers and the quick-reference table provide reasonable navigation, but the per-category detail (code examples), the report template, and the tools table are prime candidates for one-level-deep reference files that would shrink the always-loaded overview.

3 / 5

Total

15

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete about what it does and what it delivers, with an explicit trigger clause listing natural user phrases and keywords. The only soft spot is slight overlap risk with general code-review skills via generic terms like 'code audit'.

DimensionReasoningScore

Specificity

It names multiple concrete capabilities — 'reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities' — plus two concrete deliverables ('vulnerable code examples and ready-to-use remediation guidance'). Coverage is comprehensive across the skill's domain, matching the top anchor; nothing here is vague filler.

5 / 5

Completeness

It explicitly answers both questions: what ('Systematically reviews code for... vulnerabilities, providing vulnerable code examples and ready-to-use remediation guidance') and when ('Trigger this skill when users ask for a security review... or mention keywords like...'). Both are concrete and explicit, matching the top anchor exactly.

5 / 5

Trigger Term Quality

It lists the natural phrases users would say — 'security review, vulnerability scan, or penetration testing assistance' — plus keyword synonyms 'OWASP, SQL injection, XSS, code audit, or security checklist'. This is comprehensive coverage including synonyms, matching the top anchor rather than the 'a few natural terms missing' level below.

5 / 5

Distinctiveness Conflict Risk

The niche is clear (security-focused code review) with distinct security-specific triggers, but terms like 'code audit' and 'reviews code' leave minor overlap risk with general code-review/quality skills, so it sits between 'mostly distinct; minor overlap risk' (4) and 'clear niche with minimal conflict' (5).

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (572 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.