CtrlK
BlogDocsLog inGet started
Tessl Logo

top-web-vulnerabilities

This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "review access control weaknesses", "analyze API security issues", "assess security misconfigurations", "understand client-side vulnerabilities", "examine mobile and IoT security flaws", or "reference the OWASP-aligned vulnerability taxonomy". Use this skill to provide comprehensive vulnerability definitions, root causes, impacts, and mitigation strategies across all major web security categories.

55

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/top-web-vulnerabilities/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

42%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured but bloated reference catalog: nearly all 100 vulnerability definitions and their root causes restate knowledge Claude already has, while the genuine value-add (numbering, OWASP mapping, mitigation specifics) is buried in a monolithic 24KB body. It needs aggressive trimming and splitting into per-category reference files to be usable as a skill.

Suggestions

Strip the Definition/Root Cause lines for well-known vulnerabilities (SQLi, XSS, CSRF, session hijacking) — Claude already knows these; keep only the taxonomy numbering, the OWASP mapping, and non-obvious mitigation specifics to lift the conciseness score.

Split the 15-phase catalog into per-category reference files (e.g., references/injection.md, references/api-security.md) with SKILL.md reduced to an index plus the quick-reference and OWASP mapping tables, so content is loaded on demand.

Add executable guidance for the verification techniques table — actual example payloads, Burp/ZAP command invocations, or concrete test steps per vulnerability class — so the assessment workflow has actionable checkpoints rather than descriptions.

DimensionReasoningScore

Conciseness

The ~540-line body largely re-explains vulnerabilities Claude already knows (e.g., "SQL Injection: Malicious SQL code inserted into input fields to manipulate database queries"), so most of the token budget restates common knowledge rather than adding the skill's actual value (the numbering scheme, OWASP mapping, category structure). This matches the noticeably-verbose anchor rather than the mostly-efficient one.

2 / 5

Actionability

Mitigations name concrete controls ("parameterized queries/prepared statements", "X-Frame-Options, CSP frame-ancestors") and the Critical Security Headers block is copy-pasteable, but the guidance mostly describes rather than instructs — no payloads, tool commands, or executable verification steps are provided. This fits the some-concrete-but-incomplete anchor, not the mostly-executable one.

3 / 5

Workflow Clarity

The 15 "phases" are category groupings rather than a sequenced assessment procedure, and there are no validation checkpoints or feedback loops; the Verification Techniques table gestures at checking ("payload testing with encoded variants") without how to do it. This matches the steps-listed-but-checkpoints-missing anchor.

3 / 5

Progressive Disclosure

The catalog is entirely inlined in SKILL.md with no bundle files at all, but section headers, a category summary table, and the OWASP mapping provide genuine structure and navigation. This fits the some-structure-but-inline-content anchor; it avoids anchor 2 only because the body is well-headered rather than an unstructured wall.

3 / 5

Total

11

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with explicit third-person trigger guidance and a clear statement of what the skill provides. Its main weaknesses are mild over-claim padding ("comprehensive", "all major") and a few missing natural synonyms security practitioners commonly use.

DimensionReasoningScore

Specificity

The description lists four concrete deliverable types ("vulnerability definitions, root causes, impacts, and mitigation strategies") matching the several-specific-actions anchor, but "comprehensive" and "all major web security categories" are padded over-claims that keep it below the comprehensive anchor 5.

4 / 5

Completeness

It explicitly answers both questions: an explicit trigger clause ("This skill should be used when the user asks to...") with concrete quoted phrases, and a clear what ("provide comprehensive vulnerability definitions, root causes, impacts, and mitigation strategies"), matching the anchor for both what and when with concrete triggers.

5 / 5

Trigger Term Quality

Ten quoted natural trigger phrases spanning categories ("identify web application vulnerabilities", "learn about injection attacks", "review access control weaknesses") plus the OWASP taxonomy reference give good keyword coverage, but common user phrasings like "security audit", "penetration testing", and "OWASP Top 10" are missing, so it falls just short of the comprehensive-synonyms anchor.

4 / 5

Distinctiveness Conflict Risk

The web vulnerability taxonomy niche is distinct with category-specific triggers, but phrases like "explain common security flaws" are broad enough to overlap with general security-skimming skills, fitting the mostly-distinct anchor rather than the minimal-conflict anchor.

4 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (544 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.