CtrlK
BlogDocsLog inGet started
Tessl Logo

renew-test-certs

Renews expiring TLS test certificates used by MockServer integration tests. Use when TLS tests fail with "Channel handler removed before valid response has been received", "Broken pipe", certificate expired errors, when the ":lock: certificate expiry guard" CI step fails or warns, or when a user says "renew certs", "certificates expired", "TLS tests failing".

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An excellent, fully executable runbook: exact commands, paths, and per-directory variations, with a clearly sequenced workflow and strong validation checkpoints (expiry guard run before and after, explicit verify step). The two weaker spots are minor: some dated incident narrative that could be trimmed, and lookup-style reference material (test-class lists, cert-location table) inlined in SKILL.md rather than split into a references file.

Suggestions

Trim the dated incident narratives (e.g. the 2021-06/2022-01/2023-02/2026-05 expiry history and the May 2026 PKCS#1 destruction story) to one-line justifications, moving any needed historical detail to a compact 'history / old patterns' note.

Move the 'Affected Test Classes' listing and the certificate-locations table into a references/ file (e.g. references/cert-locations.md) and link to it, keeping SKILL.md a lean overview plus the executable steps.

The Step 2 extension configs are static content written at runtime every renewal; ship them as committed template files under references/ or scripts/ and copy them in Step 2 instead of the inline heredocs.

DimensionReasoningScore

Conciseness

The body is dense with project-specific, non-obvious knowledge (PKCS#1 vs PKCS#8 trap, SKI/AKI invariant, AKI requirement for shared subject DNs) and avoids generic explanations Claude already knows, so it is well above anchor 3. It falls short of anchor 5 because of narrative padding around dated incidents ("2021-06, 2022-01, 2023-02, 2026-05", "already destroyed this way in May 2026") that could be trimmed to bare rules.

4 / 5

Actionability

Every step is copy-paste-ready bash: exact `openssl req/x509` commands with flags, absolute extension-config paths, per-directory `-subj` values, chain rebuilds, cleanup, and exact Maven test invocations. This matches the fully-executable anchor with specific examples covering the common cases.

5 / 5

Workflow Clarity

Steps 0-7 are clearly sequenced (set repo root, check expiry, write configs, re-sign CA, re-sign leaf, protect negative fixture, verify, clean up) with explicit validation: the guard is run first and again after renewal, Step 6 requires the whole-tree guard to PASS plus openssl checks and affected test runs, and remediation guidance ("run it locally any time", self-test with CERT_EXPIRY_HARD_FAIL_DAYS) is provided. This matches the anchor with explicit validation steps and feedback loops, so the destructive/batch cap does not apply.

5 / 5

Progressive Disclosure

No bundle files exist, and the single SKILL.md is well-sectioned (guard first, longevity model, trap, locations table, numbered steps, affected test classes) making navigation easy — above anchor 3. It is below anchor 5 because ~250 lines are all inline: the affected-test-class listings and certificate-location reference material are lookup-style content that could live in a references/ file to keep SKILL.md an overview.

4 / 5

Total

18

/

20

Passed

Description

90%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete, and highly specific, with an explicit 'Use when...' clause covering error strings, CI signals, and natural user phrasings. The only limitation is that it names a single action (renew) rather than enumerating several specific operations, keeping specificity at the 1-2 concrete-actions anchor.

DimensionReasoningScore

Specificity

"Renews expiring TLS test certificates used by MockServer integration tests" names the domain and one concrete action (renewing certs), but does not list several distinct actions. It sits at anchor 3 rather than 4 because no additional specific capabilities (re-issuing, re-signing, verifying) are enumerated, and not 2 because the action and scope are concrete and precise.

3 / 5

Completeness

The first sentence explicitly states what the skill does and the "Use when..." clause gives multiple concrete trigger conditions (specific TLS test failures, error strings, CI guard failure/warning, and direct user phrasings). Both what and when are clearly and explicitly answered with concrete trigger phrases, matching anchor 5.

5 / 5

Trigger Term Quality

It covers natural user phrases ("renew certs", "certificates expired", "TLS tests failing"), exact CI step name (":lock: certificate expiry guard"), and specific failure strings ("Broken pipe", "Channel handler removed before valid response has been received"). Coverage includes synonyms and error-level variations, matching the comprehensive anchor.

5 / 5

Distinctiveness Conflict Risk

The niche is narrow (renewing MockServer TLS test certificates) and triggers are anchored to project-specific signals like the exact CI step name and MockServer TLS test errors, so risk of firing for an unrelated skill is minimal. It clearly matches anchor 5 rather than 4, which would imply overlap with closely related skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
mock-server/mockserver-monorepo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.