CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/checkov-policy

Configures Checkov for IaC security scanning across Terraform, CloudFormation, Kubernetes, Helm, ARM, Serverless, AWS CDK - `pip install checkov`, custom Python checks, SARIF / JUnit output, and `--baseline` gating so CI fails only on new findings in legacy code. Use for the broadest built-in rule set with Python custom checks; for a consolidated new-project scanner (and the tfsec successor) use trivy-config.

68

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A solid, actionable CLI skill body with well-sequenced steps, a useful Worked example, and an Anti-patterns checklist. It lands at strong-but-not-perfect due to mild redundancy, one abstract 'combine' step, and a combined-purpose reference file.

Suggestions

Give Step 9 a concrete merge command or snippet (e.g. a jq/python one-liner that unifies the three JSON reports) instead of the abstract 'unified verdict' phrasing.

Split references/custom-checks-and-ci.md into separate custom-checks and ci-integration files, or add in-section anchors, so Steps 5 and 8 link to distinct destinations.

Trim the 'How to use' summary or the Worked example's recap of Steps 1-4 to reduce overlap with the detailed step sections.

DimensionReasoningScore

Conciseness

Largely efficient and command-driven without explaining concepts Claude already knows, but the 'How to use' summary restates the step sections and the Worked example re-walks Steps 1-4, leaving minor trims possible.

4 / 5

Actionability

Mostly copy-paste ready commands across 8 of 9 steps (install, run, output, skip, baseline, CI), but Step 9's 'Combine the three reports into a unified verdict' gives no concrete command or script — a minor gap.

4 / 5

Workflow Clarity

Clear 9-step sequence with a soft/hard-fail gating pattern and a Worked example that demonstrates a find→fix→re-scan feedback loop, though the numbered steps themselves lack explicit validate-checkpoints between them.

4 / 5

Progressive Disclosure

Good structure with a real one-level-deep reference (references/custom-checks-and-ci.md) linked from Steps 5 and 8, but that single file bundles two topics (custom checks + CI), a minor organization gap versus fully separated concerns.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-crafted description that concretely states capabilities, gives explicit use-when guidance, and actively disambiguates from a sibling skill. The only minor gap is a few missing natural synonyms (e.g. 'misconfigurations') and file extensions.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'IaC security scanning across Terraform, CloudFormation, Kubernetes, Helm, ARM, Serverless, AWS CDK', 'pip install checkov', 'custom Python checks', 'SARIF / JUnit output', '--baseline gating' — giving comprehensive coverage of capabilities.

5 / 5

Completeness

Explicitly answers both what ('Configures Checkov for IaC security scanning...') and when ('Use for the broadest built-in rule set with Python custom checks') with a concrete trigger phrase, plus when-not-to-use disambiguation toward trivy-config.

5 / 5

Trigger Term Quality

Strong natural keywords across all supported framework names plus 'IaC security scanning', 'SARIF / JUnit', and 'baseline', but omits common variations like 'misconfigurations' and any file extensions, leaving a few natural terms missing.

4 / 5

Distinctiveness Conflict Risk

Carves a clear niche ('broadest built-in rule set with Python custom checks', baseline gating for legacy code) and explicitly contrasts against trivy-config / tfsec successor, minimizing conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

15

/

16

Passed

Reviewed

Table of Contents