CtrlK
BlogDocsLog inGet started
Tessl Logo

exa-security-basics

Secure Exa API keys, implement content moderation, and manage domain restrictions. Use when securing API keys, auditing Exa security configuration, or implementing content safety filtering. Trigger with phrases like "exa security", "exa secrets", "secure exa", "exa API key security", "exa content moderation".

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A thorough, actionable skill body with executable code and a clear sequenced workflow supported by a checklist. It is slightly dense with everything inlined and a few redundant comments, but navigation and structure are solid.

Suggestions

Tighten inline code comments and the Overview sentence to remove minor over-explanation (e.g. '// filter unsafe content from results') and improve conciseness.

Add an explicit validation/revert checkpoint before the destructive 'Revoke old key' step in the rotation procedure to harden the workflow.

Consider moving the Error Handling table and Examples into a separate reference file to better separate overview from detail, since no bundle files currently exist.

DimensionReasoningScore

Conciseness

Mostly efficient body of executable code with brief comments and no padding of basic concepts; a few inline comments and the overview sentence could be trimmed slightly.

4 / 5

Actionability

Provides copy-paste-ready TypeScript and bash across all common cases (key validation, moderation, domain filtering, sanitization, env isolation, git scan, rotation) with complete functions.

5 / 5

Workflow Clarity

Steps 1-5 are clearly sequenced with a closing checklist, and the rotation procedure includes a verify checkpoint (curl http_code); minor validation gaps remain for the destructive key-revocation step.

4 / 5

Progressive Disclosure

Well-organized into labeled sections with a single one-level reference to exa-prod-checklist and external docs; no bundle files exist, and some inlineable content (error table, examples) could be split out, leaving minor organization gaps.

4 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-structured description that clearly states capabilities, use conditions, and natural trigger phrases. Minor specificity gaps exist where the body covers actions not named in the description.

DimensionReasoningScore

Specificity

Names the domain and three concrete actions ('Secure Exa API keys, implement content moderation, and manage domain restrictions'), but omits other covered capabilities like query sanitization and per-environment key isolation, leaving minor gaps.

4 / 5

Completeness

Explicitly answers both what it does (three named actions) and when to use it, with concrete 'Use when...' guidance and explicit trigger phrases.

5 / 5

Trigger Term Quality

Provides good natural trigger phrases ('exa security', 'exa secrets', 'secure exa', 'exa API key security', 'exa content moderation') a user might say, though a few obvious synonyms (e.g. 'protect exa keys', 'exa api key') are missing.

4 / 5

Distinctiveness Conflict Risk

The Exa-specific niche and branded trigger phrases make it clearly distinguishable with minimal risk of triggering the wrong skill.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
jeremylongshore/claude-code-plugins-plus-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.