CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-state

Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery. Use for root state blocks and process-level restart guarantees.

68

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a dense, project-specific contract with a copy-paste config example, exact JSON field paths, named code owners, and an exact test command — highly actionable with no wasted tokens. Workflow is organized topically with an explicit validation section rather than a stepwise sequence, and operator guidance is correctly externalized to a single well-signaled reference.

DimensionReasoningScore

Conciseness

Every sentence carries project-specific rules (parser ownership, exact error cases, lifecycle semantics, test contracts) with zero concept-explanation padding. Version references ("Caddy v2.11.7", "go-authcrunch v1.3.4") state the current contract with explicit recheck guidance rather than time-conditional instructions, so they earn their place.

5 / 5

Actionability

The body provides a copy-paste Caddyfile block (its fragment status explicitly justified), the exact JSON field path `apps.security.config.state` with its literal shape, named owning files and functions (`caddyfile_state.go`, `NewStateConfigFromDirectives`, `App.Start`, `App.Cleanup`), and an exact runnable test command with flags. As an instruction/config skill its guidance is fully executable.

5 / 5

Workflow Clarity

Clear topical progression (Configuration → Lifecycle and operation → Validation) with an explicit validation command and coverage-retention guidance, so the destructive-operation cap does not apply. However, the body is organized as a reference contract rather than a stepwise sequence with feedback loops; deployment/recovery sequencing is deferred to the referenced operations guide.

4 / 5

Progressive Disclosure

Good structure: operator guidance is properly split into one real, clearly signaled one-level-deep reference (`references/operations.md`) with explicit read-when conditions, and sections are well organized. It falls short of anchor 5 because the body itself is a dense full contract — e.g. the ~14-line E2E coverage enumeration and detailed lifecycle semantics could arguably live in reference files, keeping SKILL.md closer to an overview.

4 / 5

Total

18

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly states what the skill configures and includes an explicit 'Use for' clause with a distinctive, well-scoped niche. Its main weakness is trigger phrasing: terms like "root state blocks" and "process-level restart guarantees" are precise but less natural than the phrases a user would actually say when needing this skill.

Suggestions

Broaden the trigger clause with natural user phrasings, e.g. "Use when enabling state persistence, choosing a runtime state directory, or keeping sessions across Caddy restarts" — this would lift both trigger_term_quality and completeness.

Name the concrete artifacts users interact with (e.g. the `state` block, `apps.security.config.state`, the state directory) in the description to sharpen trigger terms beyond the abstract "root state blocks".

DimensionReasoningScore

Specificity

"Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery" lists five specific facets of the domain under a single verb. It goes beyond the 1-2 concrete actions of anchor 3, but the one-verb-governs-many-nouns structure leaves minor coverage gaps versus the multi-action anchor 5.

4 / 5

Completeness

Both parts are explicit: the "what" ("Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery") and the "when" ("Use for root state blocks and process-level restart guarantees"). The trigger clause is present and concrete but narrow and technical; it could be more explicit with the multiple natural trigger scenarios that anchor 5 requires.

4 / 5

Trigger Term Quality

Good keyword coverage: "stop/start persistence", "reload rejection", "state blocks", "restart", "storage ownership", "recovery". However, natural user phrasings such as "keep sessions across restarts", "persist state", or "state directory" are missing, so it falls short of the comprehensive synonym coverage of anchor 5 while clearly exceeding the sparse keyword coverage of anchor 3.

4 / 5

Distinctiveness Conflict Risk

"Durable AuthCrunch runtime state", "exclusive storage ownership", and "stop/start persistence" carve out a clear niche with distinct triggers and minimal conflict risk, cleanly separated from closely related configuration skills (authorization policies, cross-device lifecycle) that the body delegates to explicitly.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 4 suspicious

Warning

Total

15

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.