CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-credentials

Configure reusable named username/password credentials for messaging consumers, including optional domains and runtime values. LDAP bind credentials belong to identity stores.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

93%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a strong example of a single-purpose configuration skill: concrete syntax, explicit required/optional and matching rules, crisp credentials-vs-secrets disambiguation, and a fixtures section that honestly states what the existing tests do and do not verify. The only meaningful gap is that validation is referenced (test/fixture names) rather than prescribed as an explicit step.

DimensionReasoningScore

Conciseness

The body is lean and project-specific throughout — "The Caddyfile block label becomes authcrunch's required credential `name`", "Do not add `name` or `kind` inside the block; caddy-security injects `name` from `<label>`, and unsupported inner keys fail parsing" — with no explanation of concepts Claude already knows. Every section (Purpose, Credentials vs Secrets, Shape, Guidance, Fixtures) earns its tokens.

5 / 5

Actionability

Guidance is fully executable: a complete copy-paste Caddyfile block ("credentials smtp_root { username root ... domain example.com }"), the exact accepted directives ("username <username>", "password <password>", "domain <name>"), and both common password patterns ("{env.SMTP_PASSWORD}" and "secrets:smtp:password") plus quoting rules ("Quote values containing spaces").

5 / 5

Workflow Clarity

For a single-purpose configuration skill the task is unambiguous: shape, required vs optional fields ("`username` and `password` are required... `domain` is optional"), and matching rules ("a messaging provider's `credentials <credential_name>` value must match the resolved credentials block label") are all explicit. It falls short of 5 because validation is described via named fixtures rather than an explicit run-the-tests checkpoint in the workflow itself.

4 / 5

Progressive Disclosure

No bundle files exist, and none are needed: the ~110-line body is well organized into clear sections, with one-level-deep, clearly signaled sibling references ("[configuration-secrets](../configuration-secrets/SKILL.md) owns manager blocks and lookup rules", "[runtime resolution](../configuration-runtime-resolution/SKILL.md#what-gets-resolved)", "[configuration-messaging](../configuration-messaging/SKILL.md)") each deferring detail the body doesn't duplicate. Navigation is easy and no content that belongs in a separate file is inlined.

5 / 5

Total

19

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete and tightly scoped, with an explicit boundary carve-out for LDAP identity stores. Its main weakness is the complete absence of a "Use when..." trigger clause and of common natural trigger terms (SMTP, email), which limits discoverability and caps completeness.

Suggestions

Add an explicit trigger clause, e.g. "Use when a Caddyfile consumer (such as an SMTP or messaging provider) needs a named username/password credential."

Include natural synonyms users would actually say — "SMTP", "email provider", "Caddyfile", "bind" — to improve trigger term coverage.

Add a one-clause boundary against the sibling secrets capability (e.g. "secret lookups belong to configuration-secrets") to match the LDAP exclusion and further reduce conflict risk.

DimensionReasoningScore

Specificity

"Configure reusable named username/password credentials for messaging consumers, including optional domains and runtime values" names the domain (credential configuration for messaging consumers) and enumerates concrete specifics (named credentials, username/password, optional domains, runtime values), leaving only minor coverage gaps. It is not a 5 because a single action verb ("Configure") is given rather than multiple distinct concrete actions.

4 / 5

Completeness

The "what" is clear and concrete (configure reusable named credentials with optional domains and runtime values), but there is no "Use when..." clause or equivalent explicit trigger guidance; the LDAP sentence is a boundary redirect, not a usage trigger. Per the judging guideline, a missing 'Use when...' clause caps completeness at 3.

3 / 5

Trigger Term Quality

Natural terms present include "username/password", "credentials", "messaging consumers", "domains", and "LDAP bind credentials" — good keyword coverage for the niche. A few natural terms users would say are missing, such as "SMTP", "email", or "Caddyfile", keeping it below a 5.

4 / 5

Distinctiveness Conflict Risk

"Configure reusable named username/password credentials for messaging consumers" carves a clear niche, and "LDAP bind credentials belong to identity stores" explicitly steers a neighboring use case away. It is not a 5 because the description does not mention the adjacent secrets-lookup capability, leaving minor overlap risk with sibling configuration skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 suspicious

Warning

Total

15

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.