CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-authentication-cross-device

Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy. Native login and external provider configuration retain their own owners.

64

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally dense, actionable reference for a narrow integration: complete caddyfile examples, precise limits and cookie contracts, and a concrete validation path via named tests and make targets. Its only notable weaknesses are a pinned version number outside a deprecation section and a long inline test inventory that could be split into a reference file.

DimensionReasoningScore

Conciseness

The body is dense and fluff-free — no explanation of concepts Claude already knows, every sentence carries a constraint or instruction. The pinned version ("The selected published go-authcrunch v1.3.11") is time-sensitive information outside a deprecated/old-patterns section, which per the rubric warrants a minor penalty from the lean anchor 5.

4 / 5

Actionability

Fully executable guidance throughout: two copy-paste-ready caddyfile blocks, a bash test command, a path/method/behavior routing table, exact constants (300-second lifetime, 4 KiB bound, 1024 per portal, eight per IP, cookie attributes), and named test files. Specific examples cover the common configuration and verification cases.

5 / 5

Workflow Clarity

The sections follow a coherent sequence — configuration, routing, identity/lifecycle, then an explicit "Acceptance and validation" section with a focused test command and `make ci-check` as the full gate. It falls short of anchor 5 because there is no feedback loop for failure recovery and the sequence is implied by section order rather than explicit steps.

4 / 5

Progressive Disclosure

No bundle files exist, and the single-file body is well organized into four clear sections with no nested or buried references. The detailed acceptance-test inventory (~25 lines enumerating test scenarios) is content that could live in a separate reference file, which keeps it at the good-structure-with-minor-gaps anchor rather than anchor 5.

4 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, distinctive description for a narrow Caddy integration niche, written in appropriate third-person imperative voice. Its main weakness is the absence of any "Use when..." trigger clause, which caps completeness, and a few missing natural synonyms like "QR code login".

Suggestions

Append an explicit trigger clause, e.g., "Use when configuring or troubleshooting cross-device login, QR activation, or approval flows in a Caddy authentication portal."

Add natural synonyms users might say, such as "QR code login", "second-device approval", or "approve login from another device".

Rewrite "Native login and external provider configuration retain their own owners" in plainer language (e.g., "Native login and external provider configuration are handled by their own skills") — the current phrasing aids neither triggering nor clarity.

DimensionReasoningScore

Specificity

The description lists several concrete capabilities — "Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy" — with named, specific feature areas rather than vague language. Minor gaps: "lifecycle" is abstract, and routing/testing coverage from the body is not reflected, so it sits just below the comprehensive anchor 5.

4 / 5

Completeness

The "what" is clear (configure and verify cross-device login, QR activation, approval, binding, cancellation, lifecycle), but there is no "Use when..." clause or equivalent trigger guidance; the second sentence about ownership is a boundary statement, not a "when". Per the rubric guideline, a missing explicit trigger clause caps completeness at 3.

3 / 5

Trigger Term Quality

Natural domain phrases a user would say are present: "cross-device portal login", "QR activation", "cancellation", "Caddy". A few natural synonyms are missing (e.g., "QR code login", "second-device approval", "approve login on another device"), matching the good-coverage-with-gaps anchor rather than comprehensive anchor 5.

4 / 5

Distinctiveness Conflict Risk

The description carves a clear niche — optional cross-device login for a Caddy authentication portal — with distinct triggers (QR activation, browser binding, cross-device session) unlikely to fire for unrelated skills. The explicit ownership boundary ("Native login and external provider configuration retain their own owners") further reduces overlap with sibling skills, matching the minimal-conflict anchor 5.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.