CtrlK
BlogDocsLog inGet started
Tessl Logo

504-frameworks-micronaut-security

Use when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules, JWT/session strategies, SecurityService checks, CORS, CSRF awareness for browser apps, rejection handlers, and sensitive-data-safe logging. This should trigger for requests such as Add Micronaut security support; Review Micronaut security configuration; Improve API authorization in Micronaut; Add JWT security in Micronaut; Harden Micronaut route authorization rules. Part of Plinth Toolkit

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured with a clean overview-to-reference split and sensible compile/verify checkpoints, but it is held back by redundant repetition (duplicated trigger list, triple reference pointer) and vagueness in the actual change-application steps, which defer all substantive guidance to the reference. Suitable suggestions: consolidate the reference pointer to one place, drop or compress the 'When to use this skill' section, and add a compact inline example (e.g. one @Secured pattern) so the skill body is actionable on its own.

Suggestions

Consolidate the pointer to references/504-frameworks-micronaut-security.md into a single location instead of repeating it in Constraints, Workflow step 1, and the Reference section.

Remove the 'When to use this skill' section, which duplicates the frontmatter description's trigger list verbatim.

Add one compact inline example (e.g. a minimal @Secured controller or intercept-url-map rule) so the body is actionable without opening the reference, and clarify what 'apply framework-aligned changes' concretely means.

DimensionReasoningScore

Conciseness

The body is mostly efficient with no concept over-explanation, but the 'When to use this skill' section duplicates the frontmatter trigger list verbatim and the reference file is pointed to three times (Constraints, Workflow step 1, and the Reference section), which is unnecessary repetition that could be tightened.

3 / 5

Actionability

It provides some concrete guidance (e.g. 'Run ./mvnw compile or mvn compile', './mvnw clean verify', 'If compilation fails, stop immediately') but the core security guidance is entirely deferred to the reference, and workflow steps like 'Implement or refactor security-related configuration/code following the reference patterns' lack specific detail.

3 / 5

Workflow Clarity

The 4-step workflow is clearly sequenced with validation checkpoints (compile before changes, stop on failure, verify after), but there is no fix-and-retry recovery loop — 'stop immediately' ends the process rather than guiding error recovery.

4 / 5

Progressive Disclosure

The SKILL.md is a lean overview pointing to a single, well-signaled reference (references/504-frameworks-micronaut-security.md), which exists and is one level deep with no nested references — matching the ideal split and navigation structure.

5 / 5

Total

15

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with comprehensive, concrete capability coverage and explicit, natural trigger phrases. The only deduction is the second-person 'you' in the trigger clause, which the rubric penalizes on specificity.

DimensionReasoningScore

Specificity

The description lists many concrete actions ('micronaut-security authentication, @Secured and intercept-url-map rules, JWT/session strategies, SecurityService checks, CORS, CSRF awareness... rejection handlers, and sensitive-data-safe logging'), matching the comprehensive anchor 5, but the rubric's second-person penalty applies ('Use when you need to design...'), reducing the score by 1.

4 / 5

Completeness

It explicitly answers both what ('design, review, or improve security in Micronaut applications — including...') and when ('This should trigger for requests such as...') with concrete trigger phrases, matching the anchor 5 example.

5 / 5

Trigger Term Quality

It includes comprehensive natural trigger phrases users would actually say: 'Add Micronaut security support', 'Review Micronaut security configuration', 'Improve API authorization in Micronaut', 'Add JWT security in Micronaut', 'Harden Micronaut route authorization rules', matching the comprehensive anchor with domain-specific synonyms.

5 / 5

Distinctiveness Conflict Risk

It occupies a clear niche via Micronaut-specific terms (@Secured, micronaut-security, SecurityService, intercept-url-map) that would not match generic security or other framework skills; minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
jabrena/plinth
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.