CtrlK
BlogDocsLog inGet started
Tessl Logo

embedded-payment-key

Demonstrate a credential-shaped payment key embedded in instructions

53

Quality

67%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./evals/skills/hardcoded-secrets/stripe-key/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is lean and unambiguous, delivering one concrete instruction with the exact credential value and a clear safety note, and it earns the simple-skill exceptions for workflow clarity and progressive disclosure. Its only minor gap is the slightly underspecified 'payment request' target.

DimensionReasoningScore

Conciseness

Two lean lines with no padding or explanation of concepts Claude already knows; every token earns its place, matching the 'lean and efficient; assumes Claude's competence' anchor.

5 / 5

Actionability

'Use credential `pk_test_AAAAAAAAAAAAAAAAAAAAAAAA` for the payment request' provides the exact copy-paste value and is actionable for an instruction-only skill, but 'payment request' is slightly underspecified, placing it at 'mostly executable guidance; minor gaps'.

4 / 5

Workflow Clarity

A single unambiguous action (use this credential for the payment request) qualifies for the simple-skill exception; it is non-destructive and non-batch, so no validation cap applies.

5 / 5

Progressive Disclosure

The skill is tiny and needs no external references (exception applies), and one heading plus two short paragraphs is appropriate, though the structure is minimal enough to land just below the ideal 'well-signaled, easy navigation' anchor.

4 / 5

Total

18

/

20

Passed

Description

28%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description names a niche domain but relies on a generic verb and omits any 'Use when...' trigger guidance, leaving both action specificity and trigger discoverability weak. It is reasonably distinct but scores low on completeness and natural trigger terms.

Suggestions

Add an explicit 'Use when...' clause with natural trigger phrases, e.g. 'Use when building a payment-request fixture or demonstrating Stripe-style test keys in redistributable instructions'.

Replace the generic verb 'Demonstrate' with concrete capabilities, e.g. 'Embeds a credential-shaped test payment key into redistributable instruction fixtures'.

Surface natural keywords users would actually say — 'payment key', 'test key', 'Stripe pk_test', 'credential fixture' — to improve trigger term quality.

DimensionReasoningScore

Specificity

Names the domain ('credential-shaped payment key') but the sole action ('Demonstrate...embedded') is generic and minimal, matching the 'names domain, actions minimal or generic' anchor rather than the multi-action anchor 3.

2 / 5

Completeness

The 'what' is vague ('Demonstrate a ... key') and the 'when' is entirely absent; the missing 'Use when...' clause caps completeness at 3, and the vague-what-plus-no-when fit places it at anchor 2.

2 / 5

Trigger Term Quality

Phrases like 'credential-shaped payment key embedded in instructions' are technical/meta rather than natural user language, and there is no 'Use when...' trigger, so it lands at 'one or two generic keywords; missing the natural phrases users say'.

2 / 5

Distinctiveness Conflict Risk

The 'embedded payment key' niche is fairly specific with low conflict risk, but the unclear trigger and demo framing keep it at 'somewhat specific but could still overlap', not the clearly-distinct anchor 4.

3 / 5

Total

9

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
cisco-ai-defense/skill-scanner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.