CtrlK
BlogDocsLog inGet started
Tessl Logo

404-frameworks-quarkus-security

Use when you need to design, review, or improve security in Quarkus applications — including Quarkus Security with JWT/OIDC, basic auth, @RolesAllowed / @Authenticated / @PermitAll, SecurityIdentity, permission checks, path-based authorization in configuration, exception mapping for auth failures, and sensitive-data-safe logging. This should trigger for requests such as Add Quarkus security support; Review Quarkus security configuration; Improve API authorization in Quarkus; Add JWT/OIDC security in Quarkus; Harden Quarkus authorization rules. Part of Plinth Toolkit

71

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, token-efficient overview body with concrete build/verify commands and an excellent one-file progressive-disclosure split. The main gaps are mild redundancy with the frontmatter trigger list, directional middle workflow steps, and a missing fix-and-retry feedback loop around verification.

Suggestions

Trim or merge the 'When to use this skill' section, which duplicates the frontmatter description's trigger list almost verbatim, to reclaim tokens.

Make Workflow steps 2-3 more concrete — e.g., name the specific files, config properties, or annotations to inspect (application.properties security settings, @RolesAllowed usage) before proposing changes.

Add a feedback loop after verification — e.g., 'If `mvn clean verify` fails, fix the failing checks and re-run before reporting' — instead of only the pre-change stop condition.

DimensionReasoningScore

Conciseness

The body is lean with no concept explanations Claude already knows, but the 'When to use this skill' section repeats the frontmatter trigger list nearly verbatim and the 'What is covered' bullets partially duplicate the Scope line, so a little could be trimmed. It sits between the lean anchor (5) and the 'minor instances of over-explanation' anchor, matching 4.

4 / 5

Actionability

Concrete executable commands are present ('Run `./mvnw compile` or `mvn compile`', 'Run `./mvnw clean verify` or `mvn clean verify`') plus an explicit reference path, but Workflow steps 2-3 ('Identify requested outcomes, constraints, and the minimum safe set of changes', 'Implement or refactor security-related configuration/code following the reference patterns') stay directional, deferring specifics to the reference file. This matches 'mostly executable guidance with minor gaps' rather than fully copy-paste-ready guidance.

4 / 5

Workflow Clarity

The 4-step workflow is clearly sequenced with an explicit pre-change checkpoint ('MANDATORY: Run compile before applying any change', 'If compilation fails, stop immediately') and a post-change verification step. It falls short of anchor 5 because there is no fix-and-retry feedback loop after verification fails — only a stop condition — leaving a minor validation gap.

4 / 5

Progressive Disclosure

The body is a concise overview and all detail lives in a single, clearly signaled, one-level-deep reference ([references/404-frameworks-quarkus-security.md](references/404-frameworks-quarkus-security.md)), which exists in the bundle and contains the detailed rules and good/bad examples. The split is appropriate and navigation is easy, matching the top anchor; no content that belongs in the reference is inlined.

5 / 5

Total

17

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly defines a specific niche and gives explicit 'Use when' trigger phrases users would naturally say. Its only deductions are the second-person phrasing ('Use when you need to...') and a trigger list that could add a few more phrasing variations; the capability enumeration is otherwise comprehensive.

DimensionReasoningScore

Specificity

The description enumerates comprehensive concrete capabilities ('Quarkus Security with JWT/OIDC, basic auth, @RolesAllowed / @Authenticated / @PermitAll, SecurityIdentity, permission checks, path-based authorization in configuration, exception mapping for auth failures, and sensitive-data-safe logging'), which would anchor at 5; however, the 'Use when you need to...' phrasing is second-person voice, which the judging guidelines penalize by reducing the specificity score by 1. It is above anchor 3 because it names the domain plus far more than 1-2 concrete actions.

4 / 5

Completeness

Both what ('design, review, or improve security in Quarkus applications — including...') and when ('This should trigger for requests such as...') are explicitly and clearly answered with concrete trigger phrases, matching the top anchor exactly. Not 4, because the 'when' clause is fully explicit rather than merely present.

5 / 5

Trigger Term Quality

It explicitly lists five natural user phrasings ('Add Quarkus security support; Review Quarkus security configuration; Improve API authorization in Quarkus; Add JWT/OIDC security in Quarkus; Harden Quarkus authorization rules') with synonym-level coverage (security support / configuration / authorization / hardening). It clearly matches the comprehensive anchor rather than the 'a few natural terms missing' anchor at 4.

5 / 5

Distinctiveness Conflict Risk

The niche is clear and specific (Quarkus application security, with Quarkus-specific terminology like SecurityIdentity, quarkus config-based path authorization), and the triggers are distinct from generic security skills or other frameworks, giving minimal conflict risk. It does not overlap broadly enough to fall to anchor 4.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
jabrena/plinth
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.