CtrlK
BlogDocsLog inGet started
Tessl Logo

api-security-best-practices

Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

55

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/api-security-best-practices/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a strong, expert-level security skill body: it provides concrete code sketches with explicitly justified scope limits, non-obvious operational guidance, an explicit validation-driven worked example, and honest limitations. Its main structural weakness is that everything is inlined in SKILL.md rather than split across reference files, and a few sections read as dense prose that could be tightened or externalized.

Suggestions

Move the deep-dive material (refresh-session design in section 1, distributed quota/store semantics in section 4, password migration notes in section 5) into one-level-deep reference files with clearly signaled links from SKILL.md.

Tighten section 4's prose into scannable bullet guidance to reduce token cost without losing the abuse-control distinctions.

DimensionReasoningScore

Conciseness

The body assumes Claude's competence — no explanations of what JWT, Express, or Zod are — and nearly every sentence carries non-obvious guidance (refresh-token reuse races, the INCR/EXPIRE crash gap, bcrypt byte limits). A few dense prose passages (e.g. section 4's abuse-control paragraph) could be tightened, keeping it just below the 'every token earns its place' bar.

4 / 5

Actionability

Concrete, near-executable code is provided for token verification, owner/tenant-scoped deletes, ID parsing, and Zod body validation, and the incompleteness (deliberately unnamed adapters) is explicitly justified in the Inputs section per the rubric's allowance. It falls short of 5 because no snippet is copy-paste runnable end-to-end and key operations (revocation, rate-limit store, password hashing) are described only in prose.

4 / 5

Workflow Clarity

The worked example gives a sequenced five-step checklist with explicit validation checkpoints ('expect 401 before storage access', 'expect 400 and no database mutation', 'confirm logs contain no token'), and the limitations section requires reporting untested paths. It stops short of 5 because the main body is organized by concern rather than a strict ordered workflow, and error-recovery loops beyond the worked example are implicit.

4 / 5

Progressive Disclosure

Sections are clearly headed and external references (OWASP, RFC 8725, Express, Zod) are properly listed, but the entire ~200-line guide lives inline in SKILL.md with no bundle files; deep-dive material such as the refresh-session design and distributed-quota store semantics could sit in one-level-deep reference files, matching the 'content that should be separate is inline' anchor.

3 / 5

Total

15

/

20

Passed

Description

55%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a clear capability domain with several concrete security controls, but it omits any explicit 'when to use' trigger guidance and lacks the synonym breadth (auth, JWT, OAuth, API keys) that would make it reliably surfaced by natural user phrasing. It sits comfortably above vague one-liners yet below the exemplar descriptions that pair a full action list with explicit trigger phrases.

Suggestions

Add an explicit trigger clause, e.g. 'Use when adding or reviewing API endpoints, implementing login/token checks, or hardening a service against OWASP API risks.'

Include natural synonyms users actually say — 'auth', 'JWT/tokens', 'OAuth', 'API keys', 'SSRF', 'OWASP' — alongside the current control names.

Replace the abstract tail 'protection against common API vulnerabilities' with named vulnerabilities (e.g. 'SSRF, injection, broken object-level authorization') to sharpen both specificity and trigger matching.

DimensionReasoningScore

Specificity

The description lists several concrete actions — 'authentication, authorization, input validation, rate limiting' — but 'secure API design patterns' and 'protection against common API vulnerabilities' remain abstract, leaving minor gaps in coverage rather than the comprehensive, fully concrete action list of a 5.

4 / 5

Completeness

The 'what' is clear (implement secure API design patterns with the listed controls), but there is no 'Use when...' clause or equivalent trigger guidance anywhere in the description, which per the judging guidelines caps completeness at 3.

3 / 5

Trigger Term Quality

Relevant keywords like 'authentication', 'rate limiting' and 'input validation' appear, but common variations users naturally say — 'auth', 'JWT', 'OAuth', 'API keys', 'SQL injection' — are missing, matching the 'some relevant keywords but missing common variations' anchor.

3 / 5

Distinctiveness Conflict Risk

'Secure API design patterns' carves out a recognizable niche, but the description does not distinguish itself from closely related skills like general authentication implementation or secure-coding review, so overlap risk with similar skills remains.

3 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.