CtrlK
BlogDocsLog inGet started
Tessl Logo

secret-handling

Never read .env files or write secrets to .squad/ committed files

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.copilot/skills/secret-handling/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

70%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, concrete security skill with exemplary workflow validation (explicit stop conditions, fail-loud error handling, remediation paths) and highly actionable patterns. Its weaknesses are redundancy between the Patterns, Examples, and Anti-Patterns sections, a sample scan script that omits its own most important regex, and a fully-inlined ~200-line body that could offload reference material to bundle files.

Suggestions

Make the sample PowerShell scan list match the full regex table — the omitted connection-string pattern (`(?:postgres|mysql|mongodb)://[^@]+@...`) guards the exact violation the skill's own ✗ example demonstrates.

Trim the Anti-Patterns entries that restate rules already stated verbatim in Patterns (e.g. the .env-schema and scan-before-commit duplicates) to cut redundancy.

Move the regex scanning table, example transcripts, and remediation runbook into references/ files (e.g. references/patterns.md, references/remediation.md) with clear one-level links from SKILL.md.

DimensionReasoningScore

Conciseness

Mostly operational content that earns its tokens (regex table, procedures, templates), but the Anti-Patterns section re-states rules already given (e.g. reading .env "just to check the schema" repeats the earlier NEVER assume line) and the multi-transcript Examples could be tightened. This is "could be tightened" territory (anchor 3), more than minor trimming (anchor 4).

3 / 5

Actionability

Guidance is highly concrete: exact file names, a full regex scanning table (`AKIA[0-9A-Z]{16}|aws_secret_access_key=[^\s]+`), copy-paste report templates, and commands (`git reset HEAD <file>`). Not anchor 5 because the sample PowerShell scan list includes only 3 of the 7 patterns and omits the connection-string regex — even though a leaked `DATABASE_URL=postgres://...` connection string is the skill's own canonical violation example — leaving a real gap for an implementer.

4 / 5

Workflow Clarity

The Scribe pre-commit workflow is a clear numbered sequence with explicit validation checkpoints and stop conditions ("Scan all staged files", "If secrets detected: STOP the commit", "Run validation AFTER staging, BEFORE calling git commit", "Exit with error"), and the remediation runbook adds error-recovery paths and a do-not-proceed gate. This matches anchor 5, including the destructive-operation validation requirement.

5 / 5

Progressive Disclosure

No bundle files exist and all ~200 lines live in SKILL.md. Section headers are well organized, but the regex table, full example transcripts, and the remediation runbook are content that could sit in separate reference files — "some structure but could be better organized" (anchor 3) rather than anchor 4, since there are no references at all.

3 / 5

Total

15

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, highly distinctive description with two concrete prohibitions, but it lacks any 'when to use' trigger guidance and has thin synonym coverage, which drags specificity, trigger quality, and completeness to the middle anchor. Adding an explicit trigger clause and a couple of natural terms would lift it substantially.

Suggestions

Add a 'Use when...' clause, e.g. 'Use when spawned agents handle configuration, credentials, or before Scribe commits .squad/ files.'

Include natural trigger terms users would actually say — 'credentials', 'API keys', 'git commit', 'leak' — alongside '.env' and 'secrets'.

Optionally surface one more concrete capability from the body, such as scanning staged files for secret patterns before commits.

DimensionReasoningScore

Specificity

"Never read .env files or write secrets to .squad/ committed files" names two concrete, verifiable actions, but coverage is not comprehensive — scanning, pre-commit validation, and remediation from the body are absent. This matches anchor 3 (domain plus 1-2 concrete actions) rather than 4, which requires several specific actions.

3 / 5

Completeness

The description has a clear "what" (two explicit prohibitions) but no "Use when..." or equivalent trigger clause; the "when" is entirely absent rather than weakly implied, matching anchor 3 and capping completeness per the rubric guideline.

3 / 5

Trigger Term Quality

".env", "secrets", and ".squad/" are natural terms a user would say, but common variations and synonyms ("credentials", "API keys", "leak", "commit") are missing. Relevant keywords exist, so it is above anchor 2, but coverage is too thin for anchor 4.

3 / 5

Distinctiveness Conflict Risk

"Never read .env files or write secrets to .squad/ committed files" targets a clear niche with highly distinct triggers (.env, .squad/); it is unlikely to fire for any unrelated skill, matching anchor 5.

5 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
bradygaster/squad
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.