CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-authentication-cookies

Configure portal cookie names, prefixes, domains, paths, attributes, and refresh overrides. Use for cookie precedence and coordination with authorization token discovery.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable reference: every code example is executable and the validation command is concrete. Its weaknesses are inlined deep-dive material that belongs in separate reference files (no bundle files exist at all) and some rule repetition across sections.

Suggestions

Move the Placeholders and JSON section's codec/roundtrip details and the Reserved-Prefix Compatibility rules into reference files under references/ (e.g. references/json-and-placeholders.md, references/reserved-prefixes.md), keeping a one-line well-signaled link in SKILL.md.

Deduplicate rules stated multiple times — the __Host- requirements appear in the cross-device paragraph, the Reserved-Prefix section, and again in the failure-behavior paragraph; consolidate each rule into one canonical location.

Split the Validation section's per-file test inventory into a reference file and keep only the runnable `go test` command inline, reducing the main file to what an agent needs at configuration time.

DimensionReasoningScore

Conciseness

The body is exceptionally lean with zero padding and no explanations of concepts Claude already knows, but several rules are repeated across sections (the __Host- requirements and refresh-cookie details each appear two or three times), so a few tokens could be trimmed. Not 5 because of that repetition; not 3 because there is no genuinely unnecessary explanation.

4 / 5

Actionability

Copy-paste-ready Caddyfile blocks for every major case, named Go APIs (SetCookieNamePrefix, PolicyConfig.SessionIDCookieName), and a runnable `go test -run '...'` command make the guidance fully executable and covering the common cases. Not 4 because there are no meaningful gaps in concrete guidance.

5 / 5

Workflow Clarity

Sections are organized by concern with an explicit Validation section and a runnable verification command, giving a real checkpoint, but the skill is largely declarative rather than sequenced and some sections (Placeholders and JSON) describe parser behavior without instruction. Not 5 because there is no explicit step sequence or error-recovery loop; not 3 because validation is present and clearly signaled.

4 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are absent), and all deep-dive material — JSON codec internals, reserved-prefix compatibility rules, and the full validation inventory — is inlined in one ~315-line monolithic file that should partly live in reference files. Not 4 because content that clearly belongs in separate files is inline; not 2 because section headers and cross-links to sibling skills provide genuine structure and navigability.

3 / 5

Total

16

/

20

Passed

Description

80%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete, comprehensive, and explicit about both what it does and when to use it. Its main weakness is a jargon-flavored when-clause that misses the most natural user phrasings for cookie configuration tasks.

DimensionReasoningScore

Specificity

"Configure portal cookie names, prefixes, domains, paths, attributes, and refresh overrides" lists six concrete configuration targets covering the skill's full scope, matching the comprehensive-coverage anchor. It is not 4 because there are no minor gaps in the enumerated actions.

5 / 5

Completeness

Both a clear "what" (configure names, prefixes, domains, paths, attributes, refresh overrides) and an explicit "Use for..." when-clause are present, but the when-clause ("cookie precedence and coordination with authorization token discovery") is abstract rather than concrete user triggers. Not 5 because the "when" could be more explicit and natural; not 3 because the when guidance is explicit, not merely implied.

4 / 5

Trigger Term Quality

Natural terms like "cookie names", "domains", "paths", and "attributes" are present, but jargon-heavy phrases ("authorization token discovery") stand in for plainer user language, and common synonyms (session cookie, Set-Cookie, cookie settings) are absent. Not 3 because keyword coverage is genuinely good rather than partial.

4 / 5

Distinctiveness Conflict Risk

The portal-cookie niche is clear and distinguishable, but "coordination with authorization token discovery" and the configuration-authentication/authorization family create minor overlap risk with closely related sibling skills. Not 5 because of that family overlap; not 3 because the triggers are far more specific than a generic domain skill.

4 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 4 suspicious

Warning

Total

15

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.