CtrlK
BlogDocsLog inGet started
Tessl Logo

springboot-security

Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。

87

1.08x
Quality

70%

Does it follow best practices?

Impact

100%

1.08x

Average score across 6 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/zh-CN/skills/springboot-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable security reference: nearly every section pairs crisp bullets with executable BAD/GOOD code and it closes with a useful pre-release checklist. Its main structural weakness is monolithic delivery — roughly 270 lines of inline detail with no progressive disclosure, where an overview plus one-level-deep reference files would better respect the context window.

Suggestions

Split the heavier per-topic code examples (rate limiting filter, CORS bean, security headers, JWT filter) into references/*.md files, keeping SKILL.md as a lean overview with clearly signaled one-level-deep links.

Add the surrounding SecurityFilterChain @Bean context to the `http -> ...` lambda fragments so every snippet is fully copy-paste executable.

Tighten boilerplate (e.g. drop the JwtAuthFilter constructor injection, trim the CORS registration ceremony) to push conciseness toward the top anchor.

DimensionReasoningScore

Conciseness

Each section is a tight bullet list plus one compact code block with BAD/GOOD contrasts, and it never explains concepts Claude already knows (no 'what is CSRF' padding). Minor trimming opportunities remain — the full JwtAuthFilter class boilerplate (constructor injection), the CORS bean's full registration ceremony, and the closing '记住' line — which keeps it at anchor 4 rather than the every-token-earns-its-place anchor 5.

4 / 5

Actionability

Most guidance is executable, copy-paste-ready Java/YAML: the JwtAuthFilter, the @PreAuthorize controller, the CreateUserDto record with @Valid, the parameterized @Query, the BCrypt bean, and the Bucket4j filter. Minor gaps: the `http -> ...` lambda fragments (CSRF, headers, CORS) omit the surrounding SecurityFilterChain/@Bean context, and the BAD @Query line is a fragment without a method signature, so it is 'mostly executable' (anchor 4) rather than fully executable (anchor 5).

4 / 5

Workflow Clarity

This is an advisory best-practices skill, and it closes with an explicit validation artifact — the 10-item '发布前检查清单' — plus a '何时激活' section that sequences when to apply each practice. It is not a destructive or batch operation, so the validation cap does not apply, and the checklist supplies most checkpoints; what keeps it below anchor 5 is the absence of any fix-and-recheck feedback loop or ordering among the topic sections.

4 / 5

Progressive Disclosure

The body is well-organized with clear single-level section headers and no dead references, but at ~270 lines with ten full code blocks it is the complete detailed material inlined in SKILL.md, not an overview pointing to detailed files — there are no references/, scripts/, or assets/ bundles at all. That matches anchor 3 ('content that should be separate is inline') better than anchor 4, since the per-topic deep-dive code (rate limiting, CORS, security headers) is exactly the material a references/ split would hold.

3 / 5

Total

15

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, domain-specific description that clearly states what the skill covers with a good spread of natural trigger terms. Its main weakness is the absence of an explicit 'Use when...' trigger clause in the description itself, leaving the activation guidance implicit.

Suggestions

Append an explicit trigger clause to the description, e.g. '在添加身份验证、配置 CORS/CSRF、处理密钥或扫描依赖 CVE 时使用' — this would raise completeness to the top anchor.

Add one or two high-frequency synonyms users actually say ('JWT', 'OAuth2', '登录', '安全加固') to broaden trigger term coverage.

Convert part of the topic enumeration into concrete actions (e.g. '审查并加固…') to move from topic listing toward explicit capability statements.

DimensionReasoningScore

Specificity

The description names the domain ('Java Spring Boot 服务中...Spring Security 最佳实践') and enumerates several concrete capability areas: '认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性'. It stays at the level of topic enumeration rather than listing multiple concrete actions (no verbs like 'review', 'configure', 'harden'), which keeps it just below the comprehensive anchor 5.

4 / 5

Completeness

The 'what' is clear (Spring Security best practices across the listed areas). The 'when' is only weakly implied — there is no explicit 'Use when...' clause in the description itself (the trigger guidance lives in the body: '在添加身份验证、处理输入、创建端点或处理密钥时使用'). Per the boundary guidance this sits between anchor 3 (clear what, when missing) and anchor 5 (explicit what and when), and slightly above the midpoint because the topic enumeration strongly implies the triggering scenarios.

4 / 5

Trigger Term Quality

Natural trigger terms are present and specific: 'Spring Boot', 'Spring Security', '认证/授权', 'CSRF', '速率限制', '密钥', '依赖安全性'. Common variations a user would actually say are still missing — e.g. 'JWT', 'OAuth2', 'login', '安全加固' (hardening), 'penetration/vulnerability' — so it fits anchor 4 rather than the comprehensive-synonym coverage of anchor 5.

4 / 5

Distinctiveness Conflict Risk

The scope is tightly pinned to 'Java Spring Boot 服务' and 'Spring Security', giving it a clear niche with distinct triggers and minimal overlap risk with generic security or other language/framework skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.