CtrlK
BlogDocsLog inGet started
Tessl Logo

nodejs-keccak256

Prevent Ethereum hashing bugs in JavaScript and TypeScript. Node's sha3-256 is NIST SHA3, not Ethereum Keccak-256, and silently breaks selectors, signatures, storage slots, and address derivation. Use when hashing for Ethereum in JavaScript or TypeScript, or when a selector, signature, storage slot, or derived address is wrong.

76

Quality

96%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An excellent, lean skill body: executable examples for all three major Ethereum JS libraries, a proof-of-divergence snippet, common patterns for selectors/storage slots/address derivation, audit greps, and an explicit closing rule. The only structural improvement is moving the multi-library Examples into a references file for progressive disclosure.

Suggestions

Move the Examples section (ethers/viem/web3.js variants and common patterns) into references/examples.md and keep one quick-start snippet inline in SKILL.md, improving progressive disclosure while trimming the body.

Consider adding a one-line note on how to verify a hash is correct Keccak-256 (e.g., compare against a known test vector such as the empty-input hash c5d2460186f7233c927e7db2dcc703c0e500b653ca82273b7bfad8045d85a470) to give reviewers a validation checkpoint.

DimensionReasoningScore

Conciseness

No padding and no explanation of concepts Claude already knows; every section earns its place — the divergence demo proves the core claim, the examples cover three libraries, and the audit greps are immediately usable. Matches 'lean and efficient; every token earns its place.'

5 / 5

Actionability

Copy-paste-ready executable code for ethers v6, viem, and web3.js, plus selector/typeHash/mapping-slot patterns, address derivation, and runnable grep commands for auditing a codebase. Specific examples cover the common cases.

5 / 5

Workflow Clarity

A simple, single-purpose skill whose single action is unambiguous: 'never use crypto.createHash(\u0027sha3-256\u0027). Use Keccak-aware helpers from ethers, viem, web3, or another explicit Keccak implementation', reinforced with audit commands. The audit greps are read-only, so the destructive/batch validation cap does not apply.

5 / 5

Progressive Disclosure

Well-organized sections with clear headers and everything inline is navigable, but the body is ~95 lines — above the under-50-line exception — and the Examples section (five subsections across three libraries plus patterns) is content that could be split into a references file to keep SKILL.md a leaner overview.

4 / 5

Total

19

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states the precise failure mechanism, enumerates the affected artifacts, and provides explicit, natural 'Use when…' triggers covering both proactive hashing and debugging scenarios. Third-person voice and concise phrasing with no fluff or over-claims.

DimensionReasoningScore

Specificity

Names the domain ('Ethereum hashing bugs in JavaScript and TypeScript'), the exact mechanism ('Node's sha3-256 is NIST SHA3, not Ethereum Keccak-256'), and concrete failure surfaces ('selectors, signatures, storage slots, and address derivation'). It lists several specific capabilities but centers on a single 'Prevent…' action rather than the multiple concrete actions of anchor 5.

4 / 5

Completeness

Explicitly answers both what ('Prevent Ethereum hashing bugs… silently breaks selectors, signatures, storage slots, and address derivation') and when ('Use when hashing for Ethereum in JavaScript or TypeScript, or when a selector, signature, storage slot, or derived address is wrong') with concrete trigger phrases, matching the anchor-5 example.

5 / 5

Trigger Term Quality

Covers natural phrases users would say when they need this skill — 'hashing for Ethereum', 'selector', 'signature', 'storage slot', 'derived address' — plus synonyms ('JavaScript or TypeScript', 'Keccak-256', 'sha3-256') and both proactive and debugging triggers ('when a selector, signature, storage slot, or derived address is wrong').

5 / 5

Distinctiveness Conflict Risk

A clear niche — the Keccak-256 vs NIST SHA3 divergence in Node for Ethereum work — with triggers specific to that exact bug, so it is unlikely to fire for generic hashing or JavaScript skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.