CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-http-integrations

Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata. Use for path conflicts, split hosts, public JWKS, and route ordering.

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable configuration skill: executable Caddyfile examples for every scenario, explicit ordering rules with anti-patterns, and real one-level-deep reference files. Remaining gains are trimming the naming-style prose, moving host-default details to a reference, and inlining the exact validation command.

Suggestions

Condense the naming-style paragraphs into one or two sentences (or a short do/don't pair) to cut tokens without losing the rule.

Replace the delegated validation guidance with the actual command(s) to run and a fix-and-retry loop, instead of pointing to the testing-and-ci and skill-creator skills.

Move the Caddy host defaults detail (header size limits, idle timeouts, dot/underscore headers) into a reference file like edge-trust.md, keeping only the routing-relevant summary in SKILL.md.

DimensionReasoningScore

Conciseness

Dense, expert-level content that assumes competence (no basic-concept explanations), but a few passages could be trimmed — e.g., the two paragraphs of naming-style guidance ("Prefer names that reveal the referenced object type... Avoid 'authentication portal portal'") and prose in 'Caddy Host Defaults'. Matches 'efficient; minor instances of over-explanation'. Not 5 because those passages don't each earn their tokens; not 3 because there is no real padding or explanation of known concepts.

4 / 5

Actionability

Fully executable, copy-paste-ready Caddyfile blocks covering the common cases (same-host portal-before-catch-all, split-host, public JWKS, refresh routing), plus exact matchers, directive names, file paths, and explicit do/don't rules ("Do not generate global Caddy directive-order overrides", "order authenticate before respond" shown as the anti-pattern). Matches the top anchor: specific examples cover the common cases.

5 / 5

Workflow Clarity

Route-sequencing rules are unambiguous (portal before protected catch-all, refresh endpoints on the unstripped route) and a Validation section plus an Acceptance criteria checklist provide checkpoints. Not 5 because validation is delegated by reference ('validate with the narrowest adapt-focused test from testing-and-ci', 'run the skill validator from skill-creator') rather than given as an explicit command with a fix-and-retry loop. Not 3 because checkpoints are present and concrete.

4 / 5

Progressive Disclosure

Both referenced files exist in references/ (edge-trust.md, portal-mounts.md), are one level deep, and are clearly signaled with purpose statements ('Read edge trust for direct/forwarded behavior...'). Some inline material (Caddy Host Defaults header/timeouts detail, browser refresh routing specifics) could live in a reference file, keeping this at 'good structure; minor organization gaps' rather than the fully-split top anchor.

4 / 5

Total

17

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong third-person description with concrete actions and an explicit 'Use for' trigger clause covering specific scenarios. Its only gaps are missing the Caddy/Caddyfile ecosystem terms that would strengthen recognition and separability from sibling configuration skills.

Suggestions

Add 'Caddy' or 'Caddyfile' as trigger terms so users naming the server/platform naturally match this skill.

Mention route-level mounting explicitly in the 'when' clause to further separate it from the portal-internal and policy-internal sibling skills.

DimensionReasoningScore

Specificity

Lists several concrete actions — "Mount authenticate and authorize handlers", "separate portal and protected routes", "align auth URLs", "preserve trusted proxy metadata" — matching the 'several specific actions; minor gaps' anchor. Not 5 because coverage omits the Caddy/Caddyfile context a user may need to recognize the skill's domain.

4 / 5

Completeness

Explicitly answers both: 'what' via four concrete actions and 'when' via "Use for path conflicts, split hosts, public JWKS, and route ordering" — concrete trigger phrases, matching the top anchor exactly.

5 / 5

Trigger Term Quality

Natural keywords users would say are present: "path conflicts", "split hosts", "public JWKS", "route ordering", "portal", "auth URLs". Not 5 because common variations like "Caddy", "Caddyfile", "login redirect", or "gatekeeper" are missing; not 3 because coverage is broad, not partial.

4 / 5

Distinctiveness Conflict Risk

The authenticate/authorize route-mounting niche is distinct with specific triggers ("public JWKS", "route ordering"). Not 5 because sibling skills (configuration-authentication/authorization) cover the same directive names, creating minor overlap risk.

4 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 8 suspicious

Warning

referenced_paths_exist

Referenced path issues: 3 missing, 3 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.