CtrlK
BlogDocsLog inGet started
Tessl Logo

springboot-security

Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. Use when reviewing Spring Security authn/authz, validation, CSRF, secrets, headers, or rate limiting.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/springboot-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-organized Spring Security reference: nearly every topic has concrete, mostly executable Java/YAML examples and BAD/GOOD contrasts, with only minor fragment gaps and light redundancy. Its weaknesses are structural — it is a monolithic topic catalog rather than a sequenced review workflow with explicit checkpoints, and all detail is inlined in SKILL.md with no progressive disclosure via reference files.

Suggestions

Add a short ordered review workflow (e.g., 1. locate the security config and auth paths, 2. assess each topic section, 3. validate findings against the release checklist) so the checklist acts as an explicit checkpoint instead of a standalone list.

Split code-heavy sections (JWT filter, rate-limit filter, CORS/security-header configuration) into references/ files, keeping SKILL.md as a lean overview with clearly signaled one-level-deep links.

Trim redundancy: merge 'When to Activate' with the frontmatter description's scope and drop the closing 'Remember' summary line that restates rules already covered.

DimensionReasoningScore

Conciseness

The body is dominated by terse bullet rules and complete code examples with almost no explanation of concepts Claude already knows; only minor padding remains — the "When to Activate" section largely restates the frontmatter description, and the closing "**Remember**: Deny by default..." line summarizes rules already given. Fits anchor 4 ('efficient; minor instances of over-explanation that could be trimmed'), not 5 where every token earns its place.

4 / 5

Actionability

Nearly every section supplies concrete, mostly copy-paste-ready guidance: a complete `JwtAuthFilter` class, `@PreAuthorize` usage, a validated `CreateUserDto` record, parameterized `@Query` examples, a `PasswordEncoder` bean, a `CorsConfigurationSource` bean, and a full Bucket4j `RateLimitFilter`. It falls short of anchor 5 only because a few snippets ("http.csrf(...)", "http.headers(...)" in Security Headers) are lambda fragments without the surrounding `SecurityFilterChain` bean, and the SQL-injection BAD example is an illustrative annotation fragment.

4 / 5

Workflow Clarity

The skill is organized by topic rather than as a sequenced review workflow; the closing "Checklist Before Release" provides a verification artifact, but there is no ordered process (e.g., locate auth config → assess each area → validate against checklist) and checkpoints remain implicit. This matches anchor 3 ('sequence present but checkpoints missing or implicit') rather than 4's 'clear sequence with most checkpoints present'.

3 / 5

Progressive Disclosure

The body is well-sectioned with clear headers, but it is a single ~270-line monolithic file with no bundle files and no external references — detailed, code-heavy material (e.g., the JWT filter, rate-limit filter, CORS configuration) is inlined where reference files would keep the overview lean. This matches anchor 3's pattern ('content that should be separate is inline'), not 4-5, which expect content appropriately split across files.

3 / 5

Total

14

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with explicit 'what' and 'when' clauses, a clear framework-specific niche, and good coverage of security topics. Its main weaknesses are trigger-term narrowness (abbreviated 'authn/authz' instead of natural synonyms like authentication/authorization/JWT/OAuth2) and a 'when' clause limited to reviewing rather than also covering implementation contexts.

DimensionReasoningScore

Specificity

The description enumerates several specific areas — "authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services" — giving broad, concrete coverage, but the action itself ("best practices for") is generic rather than naming concrete operations, so it does not fully match the level-5 'multiple specific concrete actions' anchor.

4 / 5

Completeness

It clearly answers 'what' ("Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security") and explicitly answers 'when' ("Use when reviewing Spring Security..."). Not a 5 because the 'when' clause repeats the topic list nearly verbatim and covers only the reviewing scenario, omitting when-building scenarios (adding auth, configuring endpoints) that the body itself lists — 'when' could be more explicit and varied.

4 / 5

Trigger Term Quality

Triggers like "Spring Security", "CSRF", "secrets", "rate limiting", "validation" are natural terms a user would say, but common variations are missing: "authentication"/"authorization" only appear in abbreviated form (authn/authz), and terms like JWT, OAuth2, login, permissions, or dependency CVEs never appear. This fits anchor 4 ('good keyword coverage; a few natural terms missing') rather than 5's 'comprehensive coverage including synonyms'.

4 / 5

Distinctiveness Conflict Risk

"Spring Security... in Java Spring Boot services" carves out a clear niche with distinct, framework-specific triggers (Spring Security, CSRF, Spring Boot), matching anchor 5's 'clear niche with distinct triggers; minimal conflict risk'. Only a hypothetical generic Java-security skill would overlap.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.