CtrlK
BlogDocsLog inGet started
Tessl Logo

security-patterns

Implements authentication, authorization, encryption, secrets management, and security hardening patterns. Use when designing auth flows, managing secrets, configuring CORS, implementing rate limiting, or when asked about JWT, OAuth, password hashing, API keys, RBAC, or security best practices.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, code-dense reference whose examples are executable and current, with an explicit workflow checklist and validation table. Its weaknesses are structural: a ~495-line monolithic body that should split detailed topics into reference files, and a workflow that lists steps with a validation checkpoint but no error-recovery loop.

Suggestions

Split per-topic deep dives (e.g., OAuth/OIDC flows, encryption details, CORS and rate-limit variants) into one-level-deep files under references/ (e.g., references/auth.md, references/crypto.md), keeping SKILL.md as a concise overview with clearly signaled links — the ten-topic, ~495-line body currently sits entirely inline.

Add a feedback loop to the workflow checklist: after 'Step 8: Validate against anti-patterns checklist', instruct to fix any violated rows and re-validate before marking complete, mirroring the fix-and-retry pattern.

Trim redundancy to reclaim tokens: the 'Common Anti-Patterns Summary' table restates rules already annotated inline — either cut the inline WRONG comments or reduce the table to rows not already covered, and drop the manual HTTPS-redirect/HSTS middleware in favor of a one-line note that helmet() sets HSTS.

DimensionReasoningScore

Conciseness

The body is dense, code-first, and assumes Claude's competence (no 'what is JWT' explanations), with terse WRONG/CORRECT annotations. Not 5 because the anti-patterns summary table recapitulates rules already shown inline (JWT localStorage, cors wildcard, generic login error), and the HTTPS-redirect plus HSTS middleware partially duplicates helmet's coverage — minor trimming opportunities.

4 / 5

Actionability

Copy-paste-ready executable code across all common cases: JWT sign/verify with pinned algorithms, RBAC middleware, bcrypt with dummy-hash anti-enumeration, AES-256-GCM encrypt/decrypt, explicit-origin CORS, express-rate-limit with Redis, helmet CSP, and zod validation. The few non-code sections (OAuth flow summary, secrets-manager pointers, rotation steps) are inherently procedural topics, not pseudocode substitutes.

5 / 5

Workflow Clarity

An 8-step "Security Implementation Progress" checklist with an explicit validation step ("Step 8: Validate against anti-patterns checklist") backed by a concrete anti-patterns table at the end. Not 5 because there is no error-recovery feedback loop (no 'if validation fails, fix and re-check' guidance) and the checklist steps are not linked to the body's sections.

4 / 5

Progressive Disclosure

No bundle files exist (no references/, scripts/, or assets/), and ~495 lines covering ten distinct topics all live inline in a single file. Section headers make it scannable, but per-topic deep dives (OAuth flows, crypto details, CORS/rate-limit variants) clearly belong in one-level-deep reference files — matching the 3 anchor ('content that should be separate is inline'), not 4 (no references at all) or 2 (structure is present, not minimal).

3 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: it states concrete capabilities in third person, provides an explicit 'Use when...' clause with the natural trigger terms users would actually say, and carves out a distinct, low-conflict niche. Both the 'what' and 'when' questions are answered clearly and specifically.

DimensionReasoningScore

Specificity

"Implements authentication, authorization, encryption, secrets management, and security hardening patterns" plus "designing auth flows, managing secrets, configuring CORS, implementing rate limiting" lists multiple concrete actions with comprehensive coverage of the security domain. Matches the 5 anchor rather than 4 because there are no meaningful gaps — headers and input validation are subsumed under 'security hardening patterns'.

5 / 5

Completeness

Explicitly answers 'what' ("Implements authentication, authorization, encryption, secrets management, and security hardening patterns") and 'when' ("Use when designing auth flows, managing secrets, configuring CORS, implementing rate limiting, or when asked about JWT, OAuth..."). This is a textbook match for the 5 anchor with concrete trigger phrases.

5 / 5

Trigger Term Quality

"JWT, OAuth, password hashing, API keys, RBAC", "CORS", "rate limiting", and "auth flows" are the exact natural terms and synonyms users say when they need this skill. Comprehensive keyword coverage including the common acronyms; not 4 because no common variation is missing.

5 / 5

Distinctiveness Conflict Risk

A clear security niche with distinct trigger vocabulary (JWT, OAuth, RBAC, CORS, password hashing) that is unlikely to fire for unrelated skills. Uses third person ('Implements') as required, so no voice penalty applies.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
CloudAI-X/claude-workflow-v2
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.