CtrlK
BlogDocsLog inGet started
Tessl Logo

best-practices

Apply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities". Do NOT use for accessibility (use web-accessibility), SEO (use seo), performance (use core-web-vitals), or comprehensive multi-area audits (use web-quality-audit).

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./packages/skills-catalog/skills/(quality)/web-best-practices/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable and well-sectioned, with concrete copy-paste code for every topic, but it functions as a 600-line inlined reference rather than an overview with one-level-deep reference files, and a fair share of the material (doctype, semantic HTML, basic validity) restates knowledge Claude already has. The audit process itself is never sequenced — the checklist at the end is the only procedural artifact.

Suggestions

Split the topic blocks (security headers/CSP, browser compatibility, deprecated APIs, code quality) into separate reference files under references/ and keep SKILL.md as a concise overview with one-level-deep pointers, per the progressive-disclosure model.

Add a short ordered audit workflow at the top (e.g., 1. run npm audit and Lighthouse best-practices audit, 2. check headers via SecurityHeaders.com, 3. review code against the per-area checklists) with an explicit verify-and-reiterate step, instead of leaving the checklist as the only procedural guidance.

Trim sections that restate well-known defaults (doctype, charset placement, semantic HTML, duplicate-ID validity) down to single checklist lines, keeping the space for the genuinely non-obvious content like the full CSP header block and polyfill strategies.

DimensionReasoningScore

Conciseness

The ~600-line body spends large stretches on patterns Claude already knows as a default — "<!DOCTYPE html>", charset-first-in-head, "<ul><li>" over divs, semantic <header>/<nav>/<main> vs. div soup, duplicate IDs being invalid. The ❌/✅ code format is efficient (no prose padding), but per the guideline to penalize explanations of concepts Claude already knows, well-known basics like the doctype and semantic-HTML sections could be cut to a checklist line each. Mostly efficient with some unnecessary content — anchor 3; not 4 because the amount of already-known material is more than minor.

3 / 5

Actionability

Nearly every section is copy-paste-ready: "npm audit", "npm audit fix", the full "Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-abc123'..." header block, "Set-Cookie: session=abc123; Secure; HttpOnly; SameSite=Strict", executable DOMPurify/AbortController/event-delegation snippets, and a tools table with concrete targets (SecurityHeaders.com, W3C Validator). Fully executable and covers the common cases — matches the top anchor.

5 / 5

Workflow Clarity

The body is organized by topic, not as a sequenced audit procedure; the "Audit checklist" section does supply checkpoints (and marks "Security (critical)"), but there is no explicit order of operations for conducting an audit (e.g., run Lighthouse/npm audit first, then headers, then code review) and no verify-fix-retry loop. Anchor 3 ('sequence present but checkpoints missing or implicit') is the best fit; not 4 because the sequence of an actual audit workflow is missing rather than having only minor gaps.

3 / 5

Progressive Disclosure

No bundle files exist (no references/, scripts/, or assets/), so everything is inlined in one ~600-line SKILL.md. Section headers are plentiful and the References section lists external links plus one sibling-skill pointer (../web-quality-audit/SKILL.md), but substantial topic blocks (security headers, compatibility, deprecated APIs) would sit more appropriately in separate reference files. Anchor 3 ('some structure... content that should be separate is inline') fits; not 2 because the inline content is clearly sectioned and navigable, not a wall of text.

3 / 5

Total

14

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: correct third-person voice, explicit what/when with quoted natural trigger phrases, and unusually good negative-scope guidance that routes to sibling skills. The only real weakness is that the capability statement itself is generic — it names domains rather than concrete actions.

DimensionReasoningScore

Specificity

Quotes: "Apply modern web development best practices for security, compatibility, and code quality" — it names three domains (security, compatibility, code quality) but the action itself is a single generic verb ("apply best practices"), with no enumeration of concrete actions like "audit headers", "fix mixed content", or "flag deprecated APIs". This matches the anchor 'Names domain and 1-2 concrete actions, but not comprehensive'; a 4 would require several distinct specific actions, and a 2 would name the domain with no actionable content at all.

3 / 5

Completeness

Quotes: "Apply modern web development best practices for security, compatibility, and code quality. Use when asked to 'apply best practices', 'security audit', ..." plus an explicit exclusion clause "Do NOT use for accessibility (use web-accessibility), SEO (use seo), performance (use core-web-vitals)...". Both what and when are explicitly and concretely answered with trigger phrases, matching the top anchor exactly.

5 / 5

Trigger Term Quality

Quotes: "'apply best practices', 'security audit', 'modernize code', 'code quality review', or 'check for vulnerabilities'" — five natural quoted phrases users would plausibly say. Not a 5 because a few natural synonyms are absent (e.g., "security review", "vulnerability scan", "hardening") and there is no equivalent of file-extension-style unambiguous signals; not a 3 because the coverage that exists is genuinely user-voiced, not jargon.

4 / 5

Distinctiveness Conflict Risk

Quotes: "Do NOT use for accessibility (use web-accessibility), SEO (use seo), performance (use core-web-vitals), or comprehensive multi-area audits (use web-quality-audit)" — explicit routing away from every adjacent skill gives it a clear niche with minimal conflict risk, matching the top anchor.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (617 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 1 suspicious

Warning

Total

14

/

16

Passed

Repository
tech-leads-club/agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.