CtrlK
BlogDocsLog inGet started
Tessl Logo

secrets

Declaratively register API keys and service credentials a template needs so they appear on Settings › API keys and in the onboarding checklist. Use before adding any third-party credential or setup UI so API keys, OAuth connections, and scoped configuration use the correct shared primitive.

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/secrets/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is exceptionally concrete and framework-specific, with executable code, commands, routes, and validation checkpoints that would genuinely prevent the failure modes it describes. Its weaknesses are structural: it is a monolithic 625-line reference with no progressive disclosure, and several operational sections could be substantially tightened or split into reference files.

Suggestions

Split reference-grade sections (HTTP routes, ad-hoc key API, Registered options table, model-provider key policy, Builder.io connections, encryption-key ladder) into one-level-deep files under references/ (e.g. references/http-routes.md, references/builder-connections.md), leaving SKILL.md as a registration-and-read overview with pointers.

Tighten the longest prose passages — the Builder.io role/permission rules and the Google OAuth triage narrative both repeat constraints that could be condensed to tables or short bullet rules.

Add a short ordered 'Quick start' sequence (preflight catalog check → register with kind/scope/validator → verify with doctor) so a first-time user gets a linear path before diving into the reference material.

DimensionReasoningScore

Conciseness

Nearly every line is framework-proprietary knowledge Claude cannot know (vault scopes, resolver order, route contracts), so there is no generic padding — but the body is ~625 lines of dense reference prose loaded on every invocation, and long passages like the Builder.io role rules, Google OAuth triage, and Netlify deploy caveats could be tightened. Mostly earns its tokens, but the sheer volume is a real context cost.

3 / 5

Actionability

Fully executable guidance throughout: copy-paste-ready `registerRequiredSecret` and `defineAction`/`readAppSecret` code samples, concrete commands (`npx agent-native doctor --only no-env-credentials`, `pnpm check:google-redirect-uris -- --env all`, curl probes with jq filters), and exact HTTP routes with request bodies and error semantics. Covers the common cases end to end.

5 / 5

Workflow Clarity

Not a linear numbered workflow (it is a reference skill), but explicit validation checkpoints are embedded where they matter: preflight catalog inspection before registering, `check-provider-key` before saving a user-supplied key, `preview-secret-removal` plus user confirmation before deletes, `doctor` before finishing credential changes, and a triage table mapping observation to next action. Minor gap: no single getting-started sequence tying registration to first read.

4 / 5

Progressive Disclosure

No references/, scripts/, or assets/ exist — everything is inlined in one 625-line SKILL.md. Section headers are clear and navigation within the file is easy, but large reference blocks (HTTP routes, ad-hoc key API, options table, model-provider key policy, Builder.io connection reference, encryption-key ladder) clearly belong in separate one-level-deep reference files. Some structure, but no offloading at all.

3 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states concrete actions with named UI surfaces, gives an explicit and well-timed use-trigger, and carves out a distinct niche among neighboring skills. The only gaps are missing synonym coverage (secrets, tokens, webhooks) relative to its own name.

DimensionReasoningScore

Specificity

"Declaratively register API keys and service credentials", "appear on Settings › API keys and in the onboarding checklist", and "API keys, OAuth connections, and scoped configuration use the correct shared primitive" name several concrete actions and surfaces. Not 5 because it omits capabilities the skill actually covers (reading, validating, rotating, ad-hoc keys); not 3 because multiple specific actions are explicitly listed.

4 / 5

Completeness

Explicitly answers both parts: what — "Declaratively register API keys and service credentials a template needs so they appear on Settings › API keys and in the onboarding checklist"; when — "Use before adding any third-party credential or setup UI". The when-clause is a concrete trigger condition, matching the top anchor; third-person voice throughout, no voice penalty applies.

5 / 5

Trigger Term Quality

Natural terms users would say are present: "API keys", "service credentials", "third-party credential", "setup UI", "OAuth connections". Not 5 because common synonyms are missing — notably "secrets" and "tokens" (the skill itself is named secrets, yet that word never appears) and "webhook secrets".

4 / 5

Distinctiveness Conflict Risk

Clear niche (the shared credential registry primitive vs. related skills like onboarding, actions, authentication, security) with distinct triggers around registration and Settings › API keys. Minor overlap risk remains on generic "credential" phrasing that could also point at the authentication skill; not 5 for that reason, not 3 since the registration framing is distinctive.

4 / 5

Total

17

/

20

Passed

Validation

75%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 12 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (638 lines); consider splitting into references/ and linking

Warning

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

12

/

16

Passed

Repository
BuilderIO/agent-native
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.