CtrlK
BlogDocsLog inGet started
Tessl Logo

skill-security-framing

URL validation and content sanitization for untrusted sources — use when handling external input safely

64

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/skill-security-framing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, highly actionable instruction-only skill: every rule is concrete, the security frame template is copy-paste ready, and the workflow is sequenced with validation checkpoints and error-recovery loops. The main weaknesses are redundancy (the pipeline is restated three times) and a dangling host-adapter reference that resolves to nothing in the bundle.

DimensionReasoningScore

Conciseness

Mostly lean — rules tables, templates, and checklists with no concept tutorials — but the 26-line ASCII workflow box, 'The Bottom Line' section, and Overview all restate the same 4-step pipeline, and the RFC 1918 table explains networking facts Claude already knows.

4 / 5

Actionability

Concrete, copy-paste-ready guidance throughout: exact protocol/host/length reject lists, a strict-hostname Twitter→FxTwitter transform with input/output and attack-pattern examples, a verbatim security frame template, and fully specified error-response messages covering the common cases (article URL, tweet URL, fetch failure, rejection).

5 / 5

Workflow Clarity

The 4-step sequence is stated in the overview diagram and then detailed per step, with an explicit validation checkpoint (URL validation before fetch), feedback loops in the Error Handling section (reject/fail → user options), and an integration checklist; not a destructive/batch skill so no cap applies.

5 / 5

Progressive Disclosure

Good structure with clear section headers and appropriately placed content, but the cross-reference 'skills/blocks/codex-host-adapter.md' does not resolve to any file in this bundle (no references/ directory exists), and ~280 lines of transform rules and error templates could partially live in reference files.

4 / 5

Total

18

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A serviceable description that answers what and when in a distinct niche, but it is thin on specifics and trigger vocabulary. Adding the concrete operations (e.g., rejecting private-IP/localhost URLs, wrapping fetched content in a security frame) and natural user phrases ('fetching a link', 'analyzing a tweet') would lift it substantially.

Suggestions

Expand the 'what' with the skill's distinctive concrete actions, e.g.: 'Validates URLs (rejecting private IPs, localhost, and metadata endpoints), wraps fetched content in a security frame, and sanitizes subagent output.'

Add natural trigger phrases users would actually say: 'Use when fetching or analyzing a link, tweet, article, or other external content from untrusted sources.'

Include common synonyms of the domain — 'link', 'web page', 'prompt injection', 'external content' — so the description surfaces for the phrasings users naturally use.

DimensionReasoningScore

Specificity

It names the domain ('untrusted sources') and exactly two concrete actions ('URL validation', 'content sanitization'), matching the anchor for 1-2 concrete actions without comprehensive coverage; it does not list several specific actions, ruling out 4.

3 / 5

Completeness

Both parts are present — 'URL validation and content sanitization' answers what, 'use when handling external input safely' answers when — but the when-clause is generic and near-circular ('safely' restates the domain) rather than giving concrete trigger phrases, so it is not a 5.

4 / 5

Trigger Term Quality

'URL validation', 'external input', and 'untrusted sources' are relevant keywords, but natural user phrasings like 'check this link', 'fetch this page', or 'analyze this tweet' and synonyms such as 'link'/'web page' are missing, matching the 'missing common variations or synonyms' anchor.

3 / 5

Distinctiveness Conflict Risk

A clear security-framing niche with distinct triggers ('untrusted sources', 'external input'), with only minor overlap risk against closely related web-fetching/research skills; it is not a 5 because the trigger surface could still collide with any skill that fetches URLs.

4 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
nyldn/claude-octopus
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.