CtrlK
BlogDocsLog inGet started
Tessl Logo

secure-code-review

Systematically reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities, providing vulnerable code examples and ready-to-use remediation guidance. Trigger this skill when users ask for a security review, vulnerability scan, or penetration testing assistance, or mention keywords like OWASP, SQL injection, XSS, code audit, or security checklist.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured OWASP checklist with executable vulnerable/remediation code, but it is long and monolithic with no progressive disclosure or finding-verification feedback loop.

Suggestions

Move the per-category detail (A01-A10 vulnerable/remediation examples) into one-level-deep reference files and keep SKILL.md as a concise overview with a quick-reference table and links, improving progressive_disclosure.

Add an explicit finding-verification step to the Review Process SOP (e.g., confirm each finding is reproducible/exploitable before reporting) to add a feedback loop for the batch review workflow.

Trim the per-category 'Risk:' explanations that restate well-known vulnerability concepts to improve token efficiency.

DimensionReasoningScore

Conciseness

Mostly efficient with concrete code throughout, but the per-category 'Risk:' blurbs restate well-known vulnerability concepts Claude already knows, and the 565-line body could be tightened; not a 3 because of this padding, not a 1 because the bulk is actionable code rather than explanatory prose.

2 / 3

Actionability

Every category ships fully executable vulnerable and remediation code plus specific commands (pip audit, npm audit) and a copy-paste report template, matching the score-3 anchor for executable, copy-paste-ready guidance.

3 / 3

Workflow Clarity

The Review Process SOP gives a clear sequence with a full-coverage check and risk classification, but for a batch review operation there is no explicit verify-finding/feedback-loop checkpoint, capping this at 2 per the rubric guidance.

2 / 3

Progressive Disclosure

Sections are well organized, but the body is a single 565-line monolithic file with no reference bundle; the per-category detail that could be split into one-level-deep reference files is inline, fitting the score-2 anchor.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that is specific, uses natural trigger terms, and explicitly states both capabilities and activation conditions in third-person voice. No significant weaknesses.

DimensionReasoningScore

Specificity

Lists multiple concrete actions—'reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures' plus 'providing vulnerable code examples and ready-to-use remediation guidance'—matching the score-3 anchor of multiple specific concrete actions.

3 / 3

Completeness

Explicitly answers both what (systematically reviews code for OWASP Top 10 vulnerabilities with remediation) and when via the explicit 'Trigger this skill when...' clause, satisfying the score-3 anchor.

3 / 3

Trigger Term Quality

Natural user-facing terms are well covered: 'security review, vulnerability scan, or penetration testing assistance, or mention keywords like OWASP, SQL injection, XSS, code audit, or security checklist.'

3 / 3

Distinctiveness Conflict Risk

The OWASP Top 10 security-review niche with distinct trigger keywords is clearly distinguishable and unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (572 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.