CtrlK
BlogDocsLog inGet started
Tessl Logo

security-patterns

Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management. TRIGGER when user asks to "configure OAuth scopes", "secure a Foundry app", "handle secrets", "add input validation", or needs to review a Foundry app for security concerns (XSS, CSP, credential management). Also trigger during pre-deployment security reviews.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Well-structured, platform-specific content with concrete code and a disciplined split between overview and the single reference file. The main gaps are small: a comment-only credential example and slight padding.

DimensionReasoningScore

Conciseness

Body is mostly lean — tables, terse bullets, and code with almost no explanation of concepts Claude already knows. Only minor trimming candidates: the sentence 'Foundry apps run on a cybersecurity platform — security is a core requirement' is mild padding, and the manifest scope list mildly repeats the Minimal Scope Principle example. Fits anchor 4, not 5.

4 / 5

Actionability

Mostly executable guidance: copy-paste CLI commands, manifest YAML, JSON schema, CSP config, and a TypeScript origin-validation listener. The credential-security snippet is comment-style only and the error-message guidance ('Return generic error messages') lacks an example, so it falls just short of anchor 5.

4 / 5

Workflow Clarity

A reference/patterns skill rather than a multi-step process, but the Pre-Deployment Checklist provides explicit validation checkpoints and the suite note sequences prerequisites (development-workflow first). No error-recovery feedback loops exist, though none are required (no destructive or batch operations), matching anchor 4.

4 / 5

Progressive Disclosure

Clear overview body with full implementations deferred to a single one-level-deep reference (references/security-examples.md, verified to exist), signaled inline at each point of use and indexed by a Reading Guide table. Content split is appropriate and navigation is easy — matches anchor 5.

5 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, explicit what-and-when structure with concrete quoted trigger phrases, and a well-defined niche. Minor room to grow by framing capabilities as actions and adding a few more natural synonyms.

DimensionReasoningScore

Specificity

Enumerates several specific capability areas — 'OAuth scopes, RBAC, input validation, UI security, and credential management' — but these are domain nouns rather than concrete actions, so it matches anchor 4 ('several specific actions; minor gaps') rather than 5.

4 / 5

Completeness

Explicitly answers both 'what' ('Security patterns for Falcon Foundry apps including OAuth scopes, RBAC, input validation, UI security, and credential management') and 'when' (a TRIGGER clause with concrete quoted phrases and a second trigger context), matching the anchor-5 example structure; 4 would require a weaker 'when' clause.

5 / 5

Trigger Term Quality

Quotes natural user phrases ('configure OAuth scopes', 'secure a Foundry app', 'handle secrets', 'add input validation') plus 'pre-deployment security reviews', giving good coverage; a few common synonyms (e.g., 'harden', 'permissions', 'authentication') are missing, so 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

Clear niche (Falcon Foundry app security) with distinct triggers scoped to that platform ('secure a Foundry app', 'configure OAuth scopes'), minimizing conflict risk with other skills; nothing generic remains.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
CrowdStrike/foundry-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.