CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-identity-stores

Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings. Delegates static account entries to configuration-users.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, information-dense configuration skill: complete executable examples, explicit validation guidance, and well-placed delegation to a single one-level-deep reference. The only real costs are a small amount of repeated alias/option content that could be consolidated and an inline volume that is closer to a full manual than a lean overview.

DimensionReasoningScore

Conciseness

The body is dense and assumes competence (no explanation of what LDAP or Caddy is), but the Caddyfile-to-authcrunch alias mapping is stated twice — once in the aliases bullet list and again in the 'Do not invent raw authcrunch JSON field names' paragraph of Store Options — which is trimmable redundancy. This matches anchor 4 (efficient, minor instances that could be trimmed) rather than anchor 5.

4 / 5

Actionability

Full, complete Caddyfile examples for both local and LDAP stores (including attributes, groups, and servers blocks), concrete environment variables (AUTHP_ADMIN_USER/EMAIL/SECRET), exact directive aliases, and runnable commands ('openssl s_client -showcerts', 'authdbctl', 'security local'). Copy-paste ready and covering the common cases — anchor 5.

5 / 5

Workflow Clarity

The runtime LDAP flow is a clear numbered sequence (1-4) with failure conditions at each step, followed by explicit failure-mode diagnosis ('a correct-looking Caddyfile can still fail because...'), a certificate-trust verification procedure, and a Fixtures section acting as a validation checklist ('verify exactly-one-user selection, explicit and automatic mapping, unmapped-user rejection or fallback, wrong-password rejection and trust failures ... before claiming login compatibility'). Clear sequence with explicit validation steps and error-recovery guidance matches anchor 5.

5 / 5

Progressive Disclosure

Structure is good: Caddyfile syntax lives inline while authcrunch internals and password-compatibility detail are delegated one level deep to the clearly signaled references/local-identity.md (verified present in the bundle), plus cross-skill links for user entries. It stays at anchor 4 rather than 5 because the body is a ~220-line manual — option inventories, alias tables, and default-value lists that could partly live in a reference are all inline, and navigation to the cross-skill links is not verified within this bundle.

4 / 5

Total

18

/

20

Passed

Description

71%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, third-person, capability-rich description with an explicit boundary against the sibling users skill, but it omits any 'when to use' trigger clause. Adding a 'Use when...' sentence with natural trigger phrases would raise both completeness and trigger-term quality.

Suggestions

Add an explicit trigger clause, e.g. 'Use when configuring Caddy security authentication identity stores, LDAP bind credentials, or group-to-role mappings.'

Include natural terms a user would say such as 'Caddy', 'authentication portal', and 'Caddyfile' to improve trigger-term coverage and distinctiveness.

State the outcome context briefly (e.g. 'so authentication portals can log users in against those stores') to make the 'what' answer end-to-end.

DimensionReasoningScore

Specificity

The description enumerates concrete capabilities across the whole config surface: 'local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings' — multiple specific concrete actions with comprehensive coverage, matching the anchor-5 example. It does not fall to anchor 4 because there are no minor gaps in the capability list.

5 / 5

Completeness

The 'what' is clearly stated (configure identity stores and their sub-settings), but there is no 'Use when...' clause or equivalent explicit trigger guidance; per judging guidelines a missing explicit trigger caps completeness at 3. It is above anchor 2 because the 'what' is concrete and specific, not vague.

3 / 5

Trigger Term Quality

Natural domain terms are present ('LDAP', 'identity stores', 'binds', 'TLS trust', 'group mappings') that a user configuring Caddy auth would plausibly say, but common variations like 'Caddy', 'authentication portal', 'authcrunch', or file/config extensions are missing. Good coverage with a few natural terms missing matches anchor 4, not anchor 5.

4 / 5

Distinctiveness Conflict Risk

The delegation sentence 'Delegates static account entries to configuration-users' explicitly disambiguates this skill from its closest sibling, giving it a clear niche with minor overlap risk (anchor 4). It does not reach anchor 5 because the description names no ecosystem ('Caddy', 'authcrunch') and could still overlap with generic identity/LDAP configuration skills.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 2 suspicious

Warning

referenced_paths_exist

Referenced path issues: 2 missing, 2 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.