CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-secrets

Configure security.secrets plugins and secret lookup values for users, credentials, and crypto. Use for static/AWS manager wiring and lookup failures; runtime field support belongs to runtime resolution.

64

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, information-dense configuration skill with executable Caddyfile and authdbctl examples, exact failure-mode documentation, and useful cross-skill boundary guidance. The main improvement opportunities are trimming test-archaeology detail and moving validation/fixture notes into a reference file.

DimensionReasoningScore

Conciseness

The body is dense with authcrunch-specific facts Claude would not know (exact interfaces like "GetSecretByKey(ctx, key)", exact errors like "secret value is not a string") and contains no generic concept explanations. The "Validation Notes" and "Fixtures" sections run long with test-internals detail that could be trimmed, so it does not reach 'every token earns its place'.

4 / 5

Actionability

Fully executable throughout: copy-paste Caddyfile blocks, concrete commands ("authdbctl generate password hash --cost 10 --password SomeFunkyPassword"), and the exact lookup format "secrets:<secret_id>:<key>" with rules for quoting and slash-vs-colon IDs. Common cases (static user password, API key, AWS manager) are each covered by a complete worked example.

5 / 5

Workflow Clarity

Sequences are present (generate hash → store in manager → reference via lookup; AWS region/path → JSON object → field lookup) with real validation guidance (strict three-field split, provisioning failures for missing manager/key, "check lookup spelling explicitly"). It is topic-organized rather than a single numbered workflow with an explicit validate-then-retry loop, so it does not reach a 5.

4 / 5

Progressive Disclosure

Well-organized sections and the two external references ([runtime resolution contract](../configuration-runtime-resolution/SKILL.md), authdbctl README) are one level deep and clearly signaled. No bundle files exist, but the body inlines substantial detail (validation notes, fixture test internals) that could be offloaded to a reference file, keeping it below a 5.

4 / 5

Total

17

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, third-person description that clearly states what the skill does and when to use it, with an explicit boundary against the runtime-resolution skill. Its main weakness is thin action coverage and trigger phrasing that leans on internal jargon ("static/AWS manager wiring") rather than natural user language.

Suggestions

Expand the what-clause with one or two more concrete actions, e.g. "Configure security.secrets plugin blocks (static/AWS managers) and secrets:<id>:<key> lookup values for passwords, API keys, and crypto keys, and generate bcrypt hashes with authdbctl."

Add natural trigger phrases users would actually say, such as "Use when a secret lookup fails, a password or API key needs a bcrypt hash, or a Caddyfile references secrets: values".

Keep the runtime-resolution boundary but phrase it as a trigger guard, e.g. "Use for wiring and lookup failures; {env.*} runtime field substitution is handled by runtime resolution."

DimensionReasoningScore

Specificity

"Configure security.secrets plugins and secret lookup values" names the domain plus two concrete actions (configure plugin blocks, configure lookup values), but coverage is not comprehensive — generating hashes, static/AWS block shape, and manager requirements are omitted. It stops short of the 'several specific actions with minor gaps' anchor.

3 / 5

Completeness

Both parts are explicit: what ("Configure security.secrets plugins and secret lookup values") and when ("Use for static/AWS manager wiring and lookup failures"). The when-clause is terse and jargon-heavy, so it does not reach the 'concrete trigger phrases' bar of a 5.

4 / 5

Trigger Term Quality

Terms like "secret lookup", "lookup failures", "static/AWS manager", "credentials", and "crypto" are natural phrasings for this domain, but common variations a user might say ("secrets manager", "password hash", "Caddyfile secrets") are missing.

4 / 5

Distinctiveness Conflict Risk

The "security.secrets" namespace is a clear niche, and the explicit boundary "runtime field support belongs to runtime resolution" delegates the adjacent skill's territory, minimizing wrong-skill triggering.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 suspicious

Warning

referenced_paths_exist

Referenced path issues: 3 missing, 3 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.