CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-users

Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules. Use for Caddyfile-owned users; online administration belongs to scripts-and-automation.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

93%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a lean, code-backed reference: exact grammar, executable Caddyfile examples, precise limits, and an explicit review checklist, with detail correctly offloaded to a one-level-deep reference file. The one gap is workflow sequencing — validation exists as a checklist but without feedback-loop guidance for failing entries.

Suggestions

Add a short error-recovery note after the Review Checklist (e.g. which subdirective or field to fix for each failing check, and when to re-check) to close the feedback-loop gap.

Consider a brief 2-3 step 'when adding or editing a user' sequence at the top to make the implied workflow (write entry → resolve secrets → validate against checklist) explicit.

DimensionReasoningScore

Conciseness

The body is dense with non-inferable domain facts (24-character key ids, bcrypt:<cost>:<hash> import formats, 3-50/8-128/72-byte policy limits, sync-vs-create semantics) and never explains concepts Claude already knows; every sentence carries a code-backed constraint, matching the lean/efficient anchor.

5 / 5

Actionability

The Shape and Secrets blocks are copy-paste-ready Caddyfile, the Fields section gives exact subdirective grammar, and the challenge-rule examples with the "kid123456789012345678901" key id cover the common cases concretely, matching the fully-executable anchor.

5 / 5

Workflow Clarity

The Review Checklist provides explicit post-generation validation points, but the workflow is topical rather than sequenced and there is no error-recovery guidance (what to do when a checklist item fails), so it fits clear-sequence/most-checkpoints (anchor 4) rather than the feedback-loops-plus-checklist anchor 5.

4 / 5

Progressive Disclosure

The body is an overview that moves the Argon2/generation detail to the real, one-level-deep references/password-hashing.md with a clear description of what it contains, and defers sibling-skill depth (identity stores, transforms, secrets, portal flows) to well-signaled external links; nothing that belongs in a reference file is inlined.

5 / 5

Total

19

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it enumerates concrete capabilities, gives an explicit use-for trigger with a negative boundary for routing, and occupies a distinct niche. Its only weakness is slight trigger-term breadth — a few natural synonyms users might say (identity store, user entries, static users) are absent.

DimensionReasoningScore

Specificity

"Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules" enumerates six concrete, distinct capabilities that comprehensively cover the skill's scope, matching the multiple-specific-actions/comprehensive-coverage anchor rather than the anchor 4 example that leaves minor gaps.

5 / 5

Completeness

The 'what' is explicit and enumerated ("Configure static local accounts, required identity fields, ...") and the 'when' is explicit with a concrete trigger phrase ("Use for Caddyfile-owned users"), plus a routing boundary ("online administration belongs to scripts-and-automation"), matching the anchor that clearly answers both what and when.

5 / 5

Trigger Term Quality

Natural terms a user would say are present ("local accounts", "password", "roles", "API keys", "Caddyfile-owned users"), giving good coverage; a few natural variations are missing (e.g. "identity store", "user entries", "static users"), so it sits at the good-coverage anchor rather than the comprehensive-synonyms anchor.

4 / 5

Distinctiveness Conflict Risk

"Caddyfile-owned users" carves out a clear niche, and the explicit delegation of "online administration" to scripts-and-automation actively routes away the nearest overlapping skill, so conflict risk is minimal.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 7 suspicious

Warning

referenced_paths_exist

Referenced path issues: 1 missing, 1 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.