CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-crypto

Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys. Use for signing/verification compatibility and rotation.

68

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A high-quality reference body: executable examples throughout, no padding or basic-concept explanations, accurate progressive disclosure to a real bundle reference, and strong diagnostic feedback loops. The only refinements are minor cross-section repetition and the absence of an explicit ordered validate-after-configuring step.

DimensionReasoningScore

Conciseness

The body is dense with project-specific behavior Claude could not infer (raw-line resolution pipeline, ES512 auto-generation defaults, KID filename normalization, EdDSA label semantics) and explains nothing Claude already knows, but auto-generation and volatile-state details are repeated across Mental Model and Defaults and could be trimmed slightly.

4 / 5

Actionability

Copy-paste-ready Caddyfile blocks cover the common cases — a full portal/policy pairing config, HMAC shared secrets, PEM file and directory loading, both env forms, secrets-manager wiring, and cookie-name mirroring — plus a complete grammar of accepted directive forms.

5 / 5

Workflow Clarity

Failure Patterns supply genuine error-recovery feedback loops (e.g. "If login succeeds but protected routes redirect to auth, suspect token source or access-token cookie name mismatch before suspecting ACLs") and provisioning diagnostics, but there is no explicitly sequenced configuration workflow with a post-configuration validation checkpoint.

4 / 5

Progressive Disclosure

System API key details are correctly deferred to a real, clearly signaled, one-level-deep reference (references/system-api-keys.md, verified to exist), core crypto material stays inline, and cross-skill links plus well-organized sections make navigation easy.

5 / 5

Total

18

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete, comprehensive on the 'what', explicit trigger guidance, third-person voice, and a clearly distinguishable niche. The main gap is that the 'Use for...' clause is narrower than the capability list, and a few natural synonyms (JWKS, PEM, HMAC) are absent.

Suggestions

Broaden the 'Use for...' trigger clause to cover the remaining capability areas, e.g. "Use for signing/verification compatibility, key rotation, public JWKS discovery, or token name/lifetime configuration."

Add common synonyms users would naturally say — "JWKS", "PEM", "HMAC shared secret" — to the capability list so the description triggers on those phrasings.

DimensionReasoningScore

Specificity

"Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys" lists multiple concrete capability areas that comprehensively match the body's scope, matching the top anchor rather than the 'minor gaps' of 4.

5 / 5

Completeness

The 'what' is explicit and concrete and an explicit "Use for signing/verification compatibility and rotation" trigger clause exists, but the 'when' covers only two of the five capability areas (nothing about discovery or token-name scenarios), so it sits between anchors 4 and 5 — noticeably above the midpoint.

4 / 5

Trigger Term Quality

Natural domain terms are present ("JWT keys", "signing/verification", "rotation", "token... lifetimes") but common synonyms and format terms a user would say ("JWKS", "PEM", "HMAC", "shared secret") are missing, placing it at good-but-incomplete keyword coverage.

4 / 5

Distinctiveness Conflict Risk

"portal/policy JWT keys" and "System API encryption keys" carve a clear niche that is distinct from sibling authentication, authorization, and secrets skills, with minimal conflict risk.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 7 suspicious

Warning

referenced_paths_exist

Referenced path issues: 1 missing, 1 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.