CtrlK
BlogDocsLog inGet started
Tessl Logo

frontend-security-coder

Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns. Use PROACTIVELY for frontend security implementations or client-side security code reviews.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/frontend-security-coder/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-organized but verbose agent-definition catalogue: it lists security topics comprehensively yet provides little executable guidance and no code examples. It reads as a capabilities inventory rather than a skill that drives concrete action. Tightening redundancy and adding concrete rules/examples would raise the score.

Suggestions

Replace the descriptive Capabilities taxonomy with concrete, actionable rules (e.g., 'Use textContent for all dynamic text; if HTML is required, sanitize with DOMPurify and a strict allowlist') and at least one copy-paste-ready code example.

Collapse the redundant Purpose, Capabilities, Behavioral Traits, and Knowledge Base sections into one concise list of decision rules to remove restatement and cut tokens.

Add explicit validation/feedback checkpoints to the Response Approach (e.g., 'After applying CSP, verify with a violation-report endpoint and iterate') rather than a single abstract test step at the end.

DimensionReasoningScore

Conciseness

The body is a ~150-line taxonomy that largely enumerates concepts Claude already knows (CSP directives, SRI, Trusted Types, PKCE, WebAuthn), and the Purpose, Capabilities, Behavioral Traits, and Knowledge Base sections overlap heavily; the opening 'Instructions' bullets are generic filler. It is not patronizing, but it is padded and could be tightened.

2 / 3

Actionability

A few concrete rules exist ('Always prefers textContent over innerHTML', 'Sanitizes all dynamic content with ... DOMPurify', clickjacking only in production), but most of the document is descriptive topic listings rather than executable guidance, with no code, commands, or worked examples.

2 / 3

Workflow Clarity

The 'Response Approach' gives a 9-step sequence ending with a 'Test security controls' verification step, but the steps are abstract ('Assess', 'Implement', 'Configure') with no explicit validate-fix-retry checkpoints between them.

2 / 3

Progressive Disclosure

Sections are cleanly headed and there are no deeply nested references, but everything is inline in a single ~150-line file with no external bundle files; the large capabilities catalogue could be split into reference files for better discovery.

2 / 3

Total

8

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, well-constructed description that clearly states the skill's domain, lists concrete capabilities, and provides an explicit 'Use PROACTIVELY' trigger clause. It uses third-person voice and avoids vague fluff. No changes needed.

DimensionReasoningScore

Specificity

Lists multiple concrete actions and domains — 'XSS prevention, output sanitization, and client-side security patterns' plus 'frontend security implementations or client-side security code reviews' — matching the anchor for listing several specific concrete actions.

3 / 3

Completeness

Explicitly states both what it does ('Expert in secure frontend coding practices specializing in...') and when to use it ('Use PROACTIVELY for frontend security implementations or client-side security code reviews'), with an explicit trigger clause.

3 / 3

Trigger Term Quality

Includes natural terms a developer would say when needing this skill — 'XSS prevention', 'frontend security', 'client-side security', 'security code reviews' — giving good coverage rather than only jargon.

3 / 3

Distinctiveness Conflict Risk

The 'frontend'/'client-side' qualifiers carve a clear niche distinct from a general security-auditor skill, and the triggers are specific enough to avoid firing for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.