CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/tfsec-policy

Configures tfsec for Terraform-specific security scanning - covers AWS / Azure / GCP / Kubernetes / OpenStack / Oracle / DigitalOcean / CloudStack, custom YAML rules, and SARIF / JUnit / Markdown output. Note: tfsec is transitioning to Trivy per Aqua Security, so new projects evaluate that first. Use for an existing Terraform-only tfsec stack; for the consolidated forward-path scanner use trivy-config, for the broadest multi-framework checks use checkov-policy, and for wider platform breadth use kics-policy.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Overview
Quality
Evals
Security
Files

Quality

Content

85%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable body with a clear sequenced workflow, an explicit verification feedback loop, and appropriate one-level-deep reference offloading. Its main weakness is mild redundancy and time-sensitive details that could be consolidated into a deprecation note.

Suggestions

Trim the final References section — it restates cloud-provider and output-format coverage already detailed in Step 7 and the description; keep only the external link and the sister-skill pointers.

Isolate time-sensitive details (the v1.28.13-pinned tfsec URL and the '2026+' adoption date) into a single 'Deprecation / migration' note rather than scattering them across Overview, Step 8, and Anti-patterns.

Consolidate the repeated Trivy-transition messaging (Overview, When-to-use, Step 8, Anti-patterns, Limitations) into one authoritative note to reduce redundancy.

DimensionReasoningScore

Conciseness

Mostly lean and tool-specific with no padding of general concepts, but the final References section restates cloud/output coverage already detailed in Step 7, and a version-pinned URL (v1.28.13) plus a '2026+' date are time-sensitive details not isolated in a deprecated section.

2 / 3

Actionability

Fully executable commands throughout ('brew install tfsec', 'tfsec . -f sarif -O tfsec.sarif', 'tfsec . -e aws-s3-*') plus complete custom-rules and CI YAML in the referenced bundle file — copy-paste ready.

3 / 3

Workflow Clarity

An eight-step sequence with an explicit verification loop in Step 5 ('assert it reports no HIGH findings before merging; if any remain, fix or justify-ignore them and re-run'), reinforced by the worked example.

3 / 3

Progressive Disclosure

The overview stays inline while the heaviest detail (custom-rules YAML, CI YAML) is offloaded to a real one-level-deep reference (references/custom-rules-and-ci.md) via clearly signaled links.

3 / 3

Total

11

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that states concrete capabilities, an explicit 'Use for...' trigger, and clear routing to sister skills. It satisfies all four dimensions with no vague fluff or over-claims.

DimensionReasoningScore

Specificity

Lists multiple specific concrete capabilities — 'Configures tfsec for Terraform-specific security scanning', 'custom YAML rules', and 'SARIF / JUnit / Markdown output' — matching the multi-action anchor rather than vague language.

3 / 3

Completeness

Explicitly states what it does and when to use it via 'Use for an existing Terraform-only tfsec stack', satisfying both the 'what' and the 'when' with an explicit trigger clause.

3 / 3

Trigger Term Quality

Includes natural terms a user would say ('tfsec', 'Terraform-specific security scanning', 'SARIF', 'custom YAML rules') with good coverage, not just internal jargon.

3 / 3

Distinctiveness Conflict Risk

Clearly routes to adjacent skills ('for the consolidated forward-path scanner use trivy-config, for the broadest multi-framework checks use checkov-policy...'), carving a distinct niche unlikely to trigger the wrong skill.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents