CtrlK
BlogDocsLog inGet started
Tessl Logo

publish

Share brain pages as beautiful password-protected HTML with zero LLM calls

53

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/publish/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is strongly actionable — every workflow is backed by executable commands and there is a clear output contract. Its weaknesses are a security-relevant validation gap (no check that stripping/encryption actually succeeded before sharing) and redundant repetition of the encryption-default policy.

Suggestions

Add a post-publish verification step, e.g. open the generated HTML (or grep it) to confirm no frontmatter, [Source: ...] citations, or timeline sections remain before sharing — this is the skill's core leak risk and currently has no checkpoint.

State the encryption-default policy once (in the Contract or the 'Default: ALWAYS ENCRYPT' section) and reference it from Anti-Patterns instead of repeating it three times.

Move the crypto parameters (PBKDF2 iterations, salt/IV sizes, SubtleCrypto details) and the four hosting variants into a reference file to slim the main body and improve progressive disclosure.

DimensionReasoningScore

Conciseness

The body is mostly lean commands and a well-chosen table, but the encryption default ('Brain content is private. Default to password-protected unless the user explicitly says open/no password/public') is repeated nearly verbatim in the Contract, the 'Default: ALWAYS ENCRYPT' section, and Anti-Patterns, and the philosophy paragraph with an external link adds little operational value. This matches anchor 3 ('mostly efficient but could be tightened') rather than 2, since the bulk is not padded explanation.

3 / 5

Actionability

The Quick Reference provides copy-paste-ready `gbrain publish` commands covering the common cases (basic, auto-generated password, explicit password, custom title, output path), and the sharing workflows include concrete upload and signed-url commands plus an explicit output format template. This matches anchor 5 ('fully executable; copy-paste ready commands; specific examples cover the common cases').

5 / 5

Workflow Clarity

Sharing workflows A–D are clearly sequenced with update and revoke paths, but no validation checkpoints exist — nothing verifies the output file was created correctly or that private metadata (frontmatter, citations, timeline) actually was stripped before content leaves the system, which is the skill's core risk. This matches anchor 3 ('sequence present but checkpoints missing or implicit') and falls short of 4, which requires most checkpoints present.

3 / 5

Progressive Disclosure

No bundle files exist and the body references none, so there are no dangling or nested references. Sections are well-organized with headers, a table, and clear navigation; the only gap is that ~160 lines of inline crypto detail (PBKDF2 iterations, salt/IV sizes) and four hosting variants could live in a reference file. This matches anchor 4 ('good structure; most content appropriately placed; minor organization gaps') rather than 5, which expects content appropriately split across files.

4 / 5

Total

15

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description gives a clear, concrete picture of what the skill produces, but it omits any guidance on when to invoke it, which is the biggest gap. It is specific enough to avoid conflicts but would benefit from a trigger clause and more natural user phrasing.

Suggestions

Add a 'Use when...' clause with concrete trigger phrases, e.g. 'Use when the user asks to share a brain page, create a shareable link, or send a memo or briefing to someone external.'

Include natural synonyms users would say — 'shareable link', 'send this page', 'publish' — to improve trigger-term coverage.

Consider briefly enumerating the core capabilities (strips private metadata, encrypts with AES-256-GCM, generates self-contained HTML) to raise specificity from one action to several.

DimensionReasoningScore

Specificity

The description names the domain (brain pages) and one concrete action — "Share brain pages as beautiful password-protected HTML with zero LLM calls" — but describes only a single action rather than a comprehensive list (publish, strip metadata, encrypt, host). It matches the anchor 'names domain and 1-2 concrete actions, but not comprehensive', and falls short of anchor 4 which expects several specific actions enumerated.

3 / 5

Completeness

The 'what' is clear (share brain pages as password-protected HTML), but there is no 'when should Claude use it' clause anywhere in the description; per the judging guidelines a missing 'Use when...' caps completeness at 3. It is not a 2 because the 'what' half is concrete, not vague.

3 / 5

Trigger Term Quality

Relevant keywords like "Share", "password-protected", and "HTML" are present, but the natural phrases a user would actually say ("create a shareable link", "send this page to someone", "publish this") are missing from the description. This fits anchor 3 ('some relevant keywords but missing common variations or synonyms') rather than 4, which expects good coverage including natural terms.

3 / 5

Distinctiveness Conflict Risk

The niche — publishing brain pages as password-protected, self-contained HTML — is clearly distinguishable, with only minor overlap risk against generic sharing/export skills. It is not a 5 because 'share' is a broad verb and the description lacks explicit trigger phrases that would make the niche unmistakable.

4 / 5

Total

13

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 1 suspicious

Warning

Total

14

/

16

Passed

Repository
garrytan/gbrain
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.