CtrlK
BlogDocsLog inGet started
Tessl Logo

spring-security-configuration

Creates a Spring Security configuration class with authentication, authorization, and HTTP protection setup. Use this skill when a security configuration needs to be created, either standalone or as part of a larger task (e.g. adding authentication to a REST API, configuring OAuth2/OIDC login, setting up JWT resource server).

61

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/spring-security-configuration/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The SKILL.md body is a well-structured, prescriptive workflow with good sequencing, version gating, and an anti-hallucination checklist. Its main weakness is that the core generation path relies on example/fragment/bean/dependency/properties files that are not present in the bundle, leaving the actual code-generation step non-executable and the reference graph partially broken.

Suggestions

Bundle the missing example trees (examples/_skeletons, _fragments, _beans, _dependencies, _properties) or replace the "Read ... file" instructions with inline skeletons/fragments so the generation step is executable as written.

Deduplicate the context-first guidance: Step 0 restates the Decision-making principle (levels 1–3) almost verbatim — consolidate into a single canonical statement and cross-reference it.

Add a concrete, runnable validation step (e.g. a refresh_build_system_model output check or a compile/parse verification command) to close the validation loop rather than relying solely on the static anti-hallucination checklist.

DimensionReasoningScore

Conciseness

Mostly efficient and well-organized with tables and checklists, but the Defaults/decision-making/Step 0 sections repeat the same "derive from context, skip already-answered questions" guidance several times (e.g. Step 0 restates principles 1–3 verbatim), which could be tightened without losing clarity.

3 / 5

Actionability

The instructions are concrete and prescriptive (named MCP tools, exact reference mappings, numbered generation steps), but the central generation step delegates to files the bundle does not contain — Step 4 says "Read skeleton from examples/_skeletons/{lang}.md" and fragments/beans/dependencies/properties, none of which exist, so Claude cannot actually execute the core code generation as written.

3 / 5

Workflow Clarity

Clear Step 0–5 sequence with explicit checkpoints (existing-config collision warning, bootMajor version gating for Authorization Server, an anti-hallucination checklist, and "STOP and ask user" when no matching example exists); the only gap is that the validation loop is an instruction-level checklist rather than an executable verify command, since the example files needed to perform the generation are missing.

4 / 5

Progressive Disclosure

The body points one level deep to real reference files (references/jwt.md, common-dsl.md, etc. all exist), but those references in turn point to a second level (_fragments/, _beans/, _dependencies/, _properties/, _skeletons/) that is not bundled, creating broken multi-level navigation; the guideline scores against actual bundle structure, and the referenced paths are largely absent.

3 / 5

Total

13

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that concretely states what the skill creates and gives explicit, natural "Use when..." triggers covering the main Spring Security variants. It is specific, complete, and well-scoped; only marginally broader trigger synonym coverage keeps it just below a perfect profile.

DimensionReasoningScore

Specificity

Lists several concrete actions ("authentication", "authorization, and HTTP protection setup") and enumerates concrete scenarios ("adding authentication to a REST API, configuring OAuth2/OIDC login, setting up JWT resource server"), missing only a broader action set like bean/property generation to reach comprehensive coverage.

4 / 5

Completeness

Explicitly answers both: what ("Creates a Spring Security configuration class with authentication, authorization, and HTTP protection setup") and when ("Use this skill when a security configuration needs to be created, either standalone or as part of a larger task"), with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural trigger terms ("authentication", "OAuth2/OIDC login", "JWT resource server", "REST API") that users would actually say; a few common synonyms/variations (e.g. "Spring Security", "login", "token") are not all present, so it stops short of 5.

4 / 5

Distinctiveness Conflict Risk

A clearly niched Spring Security configuration skill with distinct triggers (OAuth2/OIDC/JWT/authorization-server); minimal overlap risk with unrelated skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Amplicode/spring-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.