Security
Author’s activation text, quoted as published
- You MUST use this skill before approving or merging any code that touches auth, input handling, permissions, or external data. Use when the review focus is specifically on security vulnerabilities, attack surface, or compliance — not general code quality. Stronger signals: "security review", "check for vulnerabilities", "is this safe", "audit this", "OWASP", "injection", "auth check", "XSS", "SQL injection", "pentest", "threat model". Can run standalone or as a follow-up after sextant:review-code. Use sextant:review-code instead when the goal is general code quality without a security focus.
Works with: Claude Code (native) · Cursor, Codex CLI (manual)
native: this artifact type is that client's own format
Category: Security — see all ranked ›
Install (Claude Code):
cp -r security ~/.claude/skills/- tashan score: 31.0
- Adoption: 4 repos
- Upkeep: 47.0
- Freshness: 62.0
- Evidence coverage: 84% of the inputs this score can use — the rest are unknown, and the score is discounted for it
- Health: active
- Contributors: 1
- License: MIT
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
Its own instructions
Its SKILL.md says when to use it, shows worked examples, covers setup and states a limitation.
Read from the capability’s own SKILL.md. This is not a grade and does not compare to the instruction-depth verdict on an MCP server — a skill has no tools to document, so that rubric does not apply to it.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
Security scores 31 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down — and tells you the day it moves.
- Every score since we started measuring, for any capability
- The named replacement when something you run is dying — not just that it is
tashan doctorover the config you already have, on your machine
Start a 7-day trial › Everything measured on this page stays free.
source ↗ · skill:hellotern/security
Everything on this page is public evidence and free. What it cannot know is whether you run this — npx tashan-cli doctor reads your own config and names what is wrong in it, also free. tashan Pro tells you the day any of it changes.
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›
Measured 2026-08-14 · scorer s5 · how · something wrong here?