CtrlK
BlogDocsLog inGet started
Tessl Logo

504-frameworks-micronaut-security

Use when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules, JWT/session strategies, SecurityService checks, CORS, CSRF awareness for browser apps, rejection handlers, and sensitive-data-safe logging. This should trigger for requests such as Add Micronaut security support; Review Micronaut security configuration; Improve API authorization in Micronaut; Add JWT security in Micronaut; Harden Micronaut route authorization rules. Part of Plinth Toolkit

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured overview skill with strong progressive disclosure and validation-aware workflow, but the body delegates all executable security guidance to the reference, leaving its standalone actionability moderate.

Suggestions

Include one or two short inline good/bad snippets (e.g. a minimal @Secured controller or intercept-url-map YAML) so the body is actionable without opening the reference.

Add an explicit fix-and-retry step to the Workflow (e.g. 'if compile/verify fails, fix and re-run until green') to turn the SAFETY stop into a recovery loop.

Trim the 'What is covered in this Skill?' and 'When to use this skill' sections, which largely restate the frontmatter description, to reduce token redundancy.

DimensionReasoningScore

Conciseness

The body is lean and avoids explaining concepts Claude already knows, but the 'What is covered in this Skill?' list and 'When to use this skill' section partially duplicate the frontmatter description and could be trimmed.

4 / 5

Actionability

Concrete build commands ('./mvnw compile', './mvnw clean verify') and an explicit reference path are present, but all security-specific executable code/config is deferred to the reference, leaving the core task guidance as 'follow the reference patterns' with no in-body examples.

3 / 5

Workflow Clarity

A clear four-step sequence with explicit validation checkpoints (MANDATORY compile before, SAFETY stop on failure, VERIFY after) is present, but the body lacks an explicit fix-and-retry recovery loop, capping it just below 5.

4 / 5

Progressive Disclosure

The body is a clean overview pointing to a single, verified one-level-deep reference (references/504-frameworks-micronaut-security.md), signaled in the Workflow and a dedicated Reference section, with content appropriately split between overview and detail.

5 / 5

Total

16

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with explicit what/when structure and natural trigger phrases scoped tightly to Micronaut security. The only weakness is the second-person 'you need to' voice, which costs one specificity point.

DimensionReasoningScore

Specificity

Lists multiple concrete actions and subsystems ('design, review, or improve security', '@Secured and intercept-url-map rules, JWT/session strategies, SecurityService checks, CORS, CSRF awareness, rejection handlers, sensitive-data-safe logging') for comprehensive coverage, but reduced from 5 to 4 because the second-person phrasing 'Use when you need to' triggers the voice penalty.

4 / 5

Completeness

Explicitly answers both what (the enumerated security design/review capabilities) and when ('Use when you need to... This should trigger for requests such as...') with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Provides five natural trigger phrases a user would actually say ('Add Micronaut security support', 'Review Micronaut security configuration', 'Improve API authorization in Micronaut', 'Add JWT security in Micronaut', 'Harden Micronaut route authorization rules') giving comprehensive keyword coverage.

5 / 5

Distinctiveness Conflict Risk

Targets a clear niche (Micronaut security) with framework-specific terms like 'micronaut-security', '@Secured', and 'intercept-url-map' that minimize overlap with other skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
jabrena/plinth
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.