CtrlK
BlogDocsLog inGet started
Tessl Logo

coding-directives

Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation. Use for app/plugin boundaries, authcrunch integration, errors, logging, and code conventions.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, highly actionable directives skill: exact identifiers, paths, and commands dominate, and external detail is delegated through clearly signaled one-level-deep references that exist in the bundle. The weaknesses are mild verbosity in the boundary/scope sections and the absence of a single consolidated step-by-step workflow with feedback loops.

DimensionReasoningScore

Conciseness

The body is dense with repo-specific directives Claude could not infer, with no basic-concept padding. Minor trimming is possible — the Repository Scope section and the parser-documentation paragraphs run long and repeat boundary caveats several times — so it is not fully lean.

4 / 5

Actionability

Guidance is concrete throughout: an exact parser signature (`parseCaddyfileSurface(d *caddyfile.Dispenser, cfg *authcrunch.Config)`), specific APIs (`d.RemainingArgs()`, `d.ArgErr()`, `cfgutil.EncodeArgs`, `util.FindReplace`, `normalizeSecurityMetadata`), exact paths (`caddyfile_*_test.go`, `testdata/caddyfile_adapt/`, `<prefix>.json`), and runnable commands (`gofmt`, `make license`). Specific examples cover the common cases.

5 / 5

Workflow Clarity

Sequences with validation checkpoints are present where workflows exist — "run the narrow relevant test first, then broaden", "Before a mutating command, confirm its repository root and working directory, inspect the invoked script's side effects", and "Review any generated diff for unintended changes". It is not a 5 because the skill is topic-organized rather than a single ordered workflow with explicit feedback loops and checklists.

4 / 5

Progressive Disclosure

The body clearly signals one-level-deep references, including the real bundle file ("read [Runtime lifecycle](references/runtime-lifecycle.md)") and well-labeled sibling-skill links for delegated concerns (testing, automation, OIDC contract, browser refresh). Some inlined material — particularly the ~30-line Repository Scope boundary detail — could arguably live in a reference file, keeping it below a 5.

4 / 5

Total

17

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description in third person that clearly states what the skill does and when to use it, anchored to a distinct repository niche. Its main limitation is that the "Use for" clause enumerates topics rather than natural user trigger phrases, and a few obvious domain terms like "Caddyfile" are absent.

DimensionReasoningScore

Specificity

The description lists several specific actions and objects — "Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation" — naming the exact repo and subsystems. It stops short of a 5 because items like "lifecycle" are objects rather than enumerated concrete actions and coverage has minor gaps.

4 / 5

Completeness

Both "what" ("Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation") and "when" ("Use for app/plugin boundaries, authcrunch integration, errors, logging, and code conventions") are present and explicit. The "when" clause lists topics rather than concrete trigger situations, so it is not a 5.

4 / 5

Trigger Term Quality

Keywords such as "caddy-security", "Go code", "Caddy modules", "parsers", "authcrunch", "errors, logging" are terms a user of this repo would naturally say. A few natural variations are missing, notably "Caddyfile" and "middleware", keeping it below comprehensive coverage.

4 / 5

Distinctiveness Conflict Risk

The description carves out a clear niche tied to the specific caddy-security/authcrunch stack, with triggers unlikely to match unrelated skills. Conflict risk with other skills is minimal.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 12 suspicious

Warning

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.