CtrlK
BlogDocsLog inGet started
Tessl Logo

skill-security-framing

URL validation and content sanitization for untrusted sources — use when handling external input safely

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/skill-security-framing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable security standard: an explicit four-step workflow with front-loaded URL validation, copy-paste framing and error templates, and an integration checklist. Its weaknesses are mild padding and inlining of platform-specific detail that could be split into reference files.

DimensionReasoningScore

Conciseness

The body is dense with prescriptive rules — reject lists, exact size limits, and copy-paste templates — with essentially no explanation of concepts Claude already knows. Not 5 because the ASCII workflow diagram, the repeated security-rule blocks, and the "Bottom Line" section are padding that could be trimmed.

4 / 5

Actionability

Guidance is fully concrete and copy-paste ready: exact rejected IP ranges and protocols, a complete security-frame template with delimiters, an exact Twitter→FxTwitter input/output transform, per-type size limits, and ready-to-use error-message templates. Specific examples cover the common cases with no code-vs-instruction gaps.

5 / 5

Workflow Clarity

The four-step workflow (validate URL → fetch → wrap in security frame → analyze as data) is explicitly sequenced with a front-loaded validation step, dedicated error-handling sections that offer recovery options (retry, provide a local copy, skip), and an integration checklist. The worked example walks through all five steps with checkmarks, matching the anchor for clear sequence plus explicit validation, feedback loops, and checklists.

5 / 5

Progressive Disclosure

Sections are clearly headed and well-ordered (validation rules → template → subagent integration → limits → errors → checklist → example), and there are no nested or buried references. Not 5 because the ~280-line body inlines detail that could live in separate files (e.g., the platform-specific Twitter transform rules), with no reference files provided.

4 / 5

Total

18

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description answers both what and when with concrete, natural language, but it compresses a multi-part security workflow into two action phrases. Adding one or two more concrete capabilities and sharper trigger scenarios would raise it further.

Suggestions

Add 1-2 more concrete capabilities to the description (e.g., 'wraps fetched content in a security frame before analysis, truncates oversized responses') to move specificity toward comprehensive coverage.

Make the 'use when' clause more concrete by listing trigger scenarios users would actually say, such as 'use when fetching or analyzing links, articles, tweets, or other external content'.

Include common synonyms (links, URLs, web pages, sanitize input) to broaden natural trigger-term coverage.

DimensionReasoningScore

Specificity

"URL validation and content sanitization for untrusted sources" names the domain and exactly two concrete actions. It is not 4 because coverage is limited to those two actions — fetching, truncation, and subagent framing from the body are absent — matching the anchor 'Names domain and 1-2 concrete actions, but not comprehensive'.

3 / 5

Completeness

Both parts are explicit: the what is "URL validation and content sanitization for untrusted sources" and the when is "use when handling external input safely". Not 5 because the when-clause is generic — it lacks concrete trigger scenarios like fetching URLs or processing pasted links.

4 / 5

Trigger Term Quality

Phrases like "URL validation", "content sanitization", "untrusted sources", and "external input" are terms a user would naturally say when needing this skill. Not 5 because common variations such as "links", "fetch", or "sanitize input" are missing.

4 / 5

Distinctiveness Conflict Risk

The security-focused niche (untrusted-source URL/content handling) is mostly distinct from other skills. Not 5 because "handling external input" is broad enough to overlap with general input-validation or web-fetching skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
nyldn/claude-octopus
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.