CtrlK
BlogDocsLog inGet started
Tessl Logo

security-baseline

Establish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP policies, doing a basic security audit, or hardening a site before launch. Triggers on security headers, HTTPS, TLS, CSP, content security policy, HSTS, secrets management, vulnerability scan, security audit, harden, OWASP, security baseline. Also triggers when a security review is required for compliance or before going live.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

73%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable security-baseline skill with a clear validated workflow and a properly signaled reference file. It could be tightened by trimming concept explanations Claude already knows and reducing duplication between the inline headers material and the reference checklist.

Suggestions

Remove or compress explanatory prose Claude already knows (e.g., 'What CSP does', per-header 'purpose' sentences, and the PCI/SOC2/GDPR definitions) to tighten conciseness.

Reduce duplication between the inline Layer 2 headers table and references/headers-checklist.md — keep a brief summary inline and defer the full table to the reference.

Add one or two concrete commands to the audit steps (e.g., a curl header-check snippet in Step 1) to lift actionability from procedural to fully executable.

DimensionReasoningScore

Conciseness

Mostly efficient and dense with actionable specifics, but several sections explain concepts Claude already knows ('CSP tells the browser which sources are allowed', per-header purpose explanations, and the compliance touchpoint definitions for PCI/SOC2/GDPR).

3 / 5

Actionability

Provides concrete header values in tables, copy-paste CSP header strings, named scanners (securityheaders.com, MDN Observatory), and a curl verification command; the audit steps themselves are procedural rather than command-driven, leaving minor gaps.

4 / 5

Workflow Clarity

An explicit 8-step sequence with validation checkpoints — Step 5 tests in non-prod, verifies with a scanner, then re-verifies in production, and the CSP rollout uses Report-Only before enforcing — plus a data-availability fallback rule.

5 / 5

Progressive Disclosure

One well-signaled, one-level-deep reference (references/headers-checklist.md, verified to exist) under a clear 'Reference files' section; however the inline headers table and CSP details overlap content in the reference file.

4 / 5

Total

16

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, comprehensive description that clearly states what the skill does and when to use it, with rich natural trigger terms. Only minor distinctiveness overlap risk with adjacent security skills.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP policies, doing a basic security audit, or hardening a site before launch' — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both 'what' ('Establish a security baseline...') and 'when' ('Use this skill when...', 'Triggers on...', 'Also triggers when...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural terms including synonyms — 'CSP, content security policy', 'security audit, vulnerability scan, harden, OWASP, HSTS' — covering the phrases users would actually say.

5 / 5

Distinctiveness Conflict Risk

Clear niche (security baseline / hardening / compliance) with specific triggers, but broad terms like 'security audit' and 'OWASP' carry minor overlap risk with closely related skills such as code-review-web.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
rampstackco/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.