CtrlK
BlogDocsLog inGet started
Tessl Logo

springboot-security

Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

81

1.29x
Quality

72%

Does it follow best practices?

Impact

96%

1.29x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/ja-JP/skills/springboot-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, actionable reference that stays lean and assumes Claude's competence, closing with a strong release checklist that serves as a validation gate. The main gaps are fragment-style config snippets lacking full SecurityFilterChain context and the absence of any feedback-loop guidance for failed checklist items.

DimensionReasoningScore

Conciseness

The body is lean bullet-point guidance with no concept padding (it never explains what CSRF or JWT is) and every section carries project-specific preferences. Not 5 because the full ~20-line JwtAuthFilter class is boilerplate Claude already knows how to write and could be trimmed to the salient pattern.

4 / 5

Actionability

Concrete, executable guidance throughout: named annotations (`@EnableMethodSecurity`, `@PreAuthorize("hasRole('ADMIN')")`, `@Valid`, `@NotBlank`), named tools (Bucket4j, OWASP Dependency Check, Snyk), and a complete JwtAuthFilter implementation. Not 5 because the security-config snippets (`http.csrf(...)`, `http.headers(...)`) are fragments without the surrounding SecurityFilterChain method context, so they are not copy-paste ready.

4 / 5

Workflow Clarity

Sections are coherent and the closing "リリース前チェックリスト" provides ten explicit verification checkpoints covering every prior section. Not 5 because there is no explicit sequence or feedback loop for how to proceed when a check fails (e.g. 'fix, then re-run the checklist'); not 3 because the checklist supplies concrete checkpoints and the structure is easy to follow.

4 / 5

Progressive Disclosure

The body (~120 lines) is well-organized into short, clearly-headed sections with no monolithic wall of text and no nested or buried references (no bundle files exist to reference). Not 5 because the skill exceeds the under-50-line simple-skill threshold and some deeper material (e.g. complete SecurityFilterChain configuration, CSRF token setup) could be split into one-level-deep reference files.

4 / 5

Total

16

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific, and distinctive description that clearly states what the skill covers, but it omits any 'Use when...' trigger clause, capping completeness and weakening its discoverability. Adding explicit usage triggers and a few natural synonyms (authentication, JWT, login) would raise it further.

Suggestions

Add an explicit trigger clause, e.g. "Use when writing or reviewing authentication, authorization, or security configuration in Java Spring Boot services."

Spell out "authentication/authorization" alongside "authn/authz" and add common trigger terms users actually say (e.g. JWT, login, Spring Security config).

Consider phrasing the domain list as actions ("configure, audit, and harden...") rather than a purely topical list to sharpen specificity.

DimensionReasoningScore

Specificity

The description lists several concrete, specific security domains — "authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services" — with a clear platform qualifier. It falls short of 5 because these are topical areas rather than concrete actions (no verbs like 'review', 'configure', 'audit'), and short of anchor 5's 'multiple specific concrete actions'.

4 / 5

Completeness

The 'what' is clear and specific (best practices across named security domains for Spring Boot services), but there is no 'Use when...' clause or equivalent explicit trigger guidance. Per the judging guidelines, a missing 'when' clause caps completeness at 3.

3 / 5

Trigger Term Quality

Good natural keyword coverage: "Spring Security", "CSRF", "secrets", "rate limiting", "dependency security", "Java Spring Boot" — phrases users would plausibly say. Not 5 because common variations like "authentication", "authorization" (spelled out), "JWT", "login" are missing, and the abbreviated jargon "authn/authz" is less natural than what a user would actually type.

4 / 5

Distinctiveness Conflict Risk

The description carves out a clear niche — "Spring Security... in Java Spring Boot services" — with domain-specific terms (CSRF, authn/authz, Spring Security) that minimize overlap with general coding, validation, or secret-management skills.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.