CtrlK
BlogDocsLog inGet started
Tessl Logo

goth-echo-security

This skill should be used when the user asks to "integrate goth with echo", "oauth echo framework", "echo authentication", "goth session management", "oauth security", "secure oauth", "gorilla sessions", or needs help with session storage, security patterns, or Echo framework integration for Goth.

60

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/goth-oauth/skills/goth-echo-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a rich, actionable catalog of goth+Echo integration and security patterns with real code, but it is somewhat redundant, lacks explicit validation feedback loops in its workflows, and points to reference files that are missing from the bundle.

Suggestions

Create the referenced `references/session-storage-options.md` and `references/security-checklist.md` files (or remove the dangling references) so navigation is not broken.

Consolidate the four overlapping handleCallback examples into one progressively annotated version to reduce redundancy.

Add an explicit ordered integration workflow with validation checkpoints (configure store → wire routes → verify callback → test session) rather than only topic-grouped snippets.

DimensionReasoningScore

Conciseness

Mostly code with tight one-line intros, but it repeats handleCallback across four overlapping variants (basic, session-store, CSRF-logging, session-regeneration) and includes light concept restatement ("Goth automatically handles the OAuth state parameter", "In production, always use HTTPS") that could be tightened.

3 / 5

Actionability

Concrete, largely copy-paste-ready Go code covers the common cases (route setup, provider extraction, session stores, token refresh, security checklist), with minor gaps such as omitted imports in some blocks and a questionable `r.URL.Query().Get(":provider")` call.

4 / 5

Workflow Clarity

The skill is a pattern catalog rather than a sequenced workflow; a closing security checklist provides some validation, but the code flows lack explicit validate→fix→retry checkpoints for sensitive auth/session operations, which caps clarity at 3.

3 / 5

Progressive Disclosure

Section headers and signaled references ("See references/session-storage-options.md", "See references/security-checklist.md") give some structure, but those referenced files do not exist in the bundle, so navigation is broken, and substantial store/security content remains inlined rather than split out.

3 / 5

Total

13

/

20

Passed

Description

86%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is trigger-rich, distinctive, and uses appropriate third-person voice with an explicit 'use when' clause. Its main weakness is the absence of a clean standalone 'what it does' statement, leaving capabilities implicit inside the trigger list.

Suggestions

Lead with a concise capability sentence (e.g. "Integrates github.com/markbates/goth with the Echo framework and implements secure session management.") before the 'use when' clause to make the 'what' explicit.

Consider adding "oauth2" and "gothic" as additional natural trigger synonyms users may say.

DimensionReasoningScore

Specificity

Lists several specific capabilities — "integrate goth with echo", "echo authentication", "goth session management", "oauth security", "gorilla sessions", "session storage" — framed as user requests rather than a standalone capability statement, leaving minor gaps in coverage phrasing.

4 / 5

Completeness

Explicit "should be used when the user asks to..." clause clearly answers 'when', and the 'what' is embedded in the trigger list, but there is no separate standalone statement of what the skill does.

4 / 5

Trigger Term Quality

Comprehensive natural trigger phrases with synonyms ("oauth security"/"secure oauth", "gorilla sessions", "echo authentication") that users would plausibly say when needing this skill.

5 / 5

Distinctiveness Conflict Risk

A clearly distinct niche (goth + Echo integration with session/security patterns) with specific triggers like "gorilla sessions" and "oauth echo framework" that minimize overlap with other skills.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 4 missing

Warning

Total

14

/

16

Passed

Repository
freightCognition/linehaulai-claude-marketplace
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.