CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration

Build or review caddy-security Caddyfiles and select focused configuration skills. Use for security app declarations and authenticate/authorize route wiring.

64

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured router skill: complete runnable example, concrete fixture and parser pointers, explicit syntax-validation step, and exemplary use of one-level-deep reference files. The only improvements are trimming slight redundancy in Syntax Currency and making the failure path after validation explicit.

DimensionReasoningScore

Conciseness

The body is dense and almost entirely project-specific (parser file ownership, fixture paths, directive semantics) with essentially no explanation of concepts Claude already knows. Minor tightening is possible — e.g., the Syntax Currency section restates the maintenance coupling twice ('Maintain Go syntax comments, standalone Caddyfiles, fixtures, and domain skills together') — fitting 'Efficient; minor instances of over-explanation that could be trimmed' rather than the uniformly lean 5.

4 / 5

Actionability

The Common Shape section gives a complete, near copy-paste-ready Caddyfile with both the global security block and site routes, plus concrete fixture paths and a placeholder-notation legend. Minor gaps remain: parts of the Workflow and Domain Map are routing prose ('Follow only the matching Domain Map routes') rather than executable steps, so it is 'Mostly executable guidance; concrete code or commands with minor gaps' instead of fully covering the common cases at anchor 5.

4 / 5

Workflow Clarity

The 5-step Workflow is clearly sequenced and step 5 is an explicit validation checkpoint ('Check generated syntax against the local wrappers, selected upstream grammar and validators, and the fixtures under testdata/caddyfile_adapt/'), with Acceptance criteria acting as a checklist. It stops short of an explicit validate→fix→retry feedback loop (no instruction on what to do when adaptation fails), matching 'Clear sequence with most checkpoints present; minor validation gaps'. The destructive/batch cap does not apply since this is config generation.

4 / 5

Progressive Disclosure

This is a router skill done right: a terse overview with a Domain Map of one-line-per-skill links, and all three detailed topics (syntax maintenance, AuthCrunch compatibility, operator examples) split into well-signaled, one-level-deep reference files that verifiably exist in references/. Nothing that belongs in a separate file is inlined; navigation is trivial, matching 'Clear overview with well-signaled one-level-deep references; content appropriately split; easy navigation'.

5 / 5

Total

17

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description with an explicit 'Use for...' trigger clause and concrete domain terminology. Its main limitation is action coverage: it states build/review but not what kinds of configuration it produces.

Suggestions

Enumerate 2-3 more concrete actions (e.g., 'configure identity stores, authentication portals, authorization policies, and secrets') to raise specificity.

Add one or two common user phrasings such as 'Caddy' or 'auth portal' to widen natural trigger coverage.

DimensionReasoningScore

Specificity

The description names the domain ("caddy-security Caddyfiles") and only two actions ("Build or review") plus the router function ("select focused configuration skills"). It matches the anchor 'Names domain and 1-2 concrete actions, but not comprehensive' — it never says what is actually configured (identity stores, portals, policies, secrets). A 4 would require several specific actions listed.

3 / 5

Completeness

It explicitly answers both questions: what ("Build or review caddy-security Caddyfiles and select focused configuration skills") and when ("Use for security app declarations and authenticate/authorize route wiring") with concrete trigger phrases. It mirrors the anchor-5 pattern ('what' + explicit 'Use for...' clause with concrete triggers); a 4 would have a weaker or more generic 'when'.

5 / 5

Trigger Term Quality

Terms like "Caddyfiles", "security app declarations", "authenticate/authorize", and "route wiring" are natural phrases for this domain. Missing a few common variations users might say ("Caddy", "reverse proxy config", "auth portal"), matching 'Good keyword coverage; a few natural terms missing' rather than the comprehensive synonym coverage of a 5.

4 / 5

Distinctiveness Conflict Risk

"caddy-security Caddyfiles" is a clear niche with distinct directive names as triggers, so risk of firing for unrelated skills is minimal. However, as a router for a family of sibling configuration-* skills it intentionally overlaps with them, fitting 'Mostly distinct; minor overlap risk with closely related skills' rather than the fully isolated niche of a 5.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 20 suspicious

Warning

referenced_paths_exist

Referenced path issues: 1 missing, 1 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.