CtrlK
BlogDocsLog inGet started
Tessl Logo

avoid-eval

Use when reviewing scripts, client components, bundles, or runtime behavior related to Never use eval() or unsafe dynamic code execution. Inspect both source code and the browser execution path so fixes target the real bottleneck or bug.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/avoid-eval/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, appropriately progressive skill body that correctly defers implementation detail to references/rule.md. Its weaknesses are the duplicated eval-danger explanation Claude already knows and the absence of any inline executable command or code example for the check and fix steps.

Suggestions

Add an inline, copy-paste-ready search command (e.g., a grep/ripgrep pattern for eval(, new Function(, and string-argument setTimeout/setInterval) to the Check section.

Include one short before/after code pair in the Fix section (e.g., eval(userInput) vs JSON.parse) so the most common case is executable without opening the reference.

Cut the duplicated XSS-consequences explanation from the intro or the Explain section — one mention is enough since Claude already knows why eval is dangerous.

DimensionReasoningScore

Conciseness

The body is short and sectioned, but the intro paragraph explains XSS consequences ('stealing sessions, making requests as the user, or redirecting to malicious sites') and the 'Explain' section restates the same danger — concepts Claude already knows — plus a double-negative sentence ('there is never a legitimate use case that can't be solved without it').

3 / 5

Actionability

The 'Check' step is concrete ('Search this codebase for any use of eval(), new Function(), or setTimeout/setInterval with string arguments') and 'Fix' names specific alternatives (JSON.parse, object lookups, function references), but there are no executable commands or code examples in the body — no grep/ripgrep pattern and no before/after snippets — leaving key details to the reference file.

3 / 5

Workflow Clarity

The Check → Fix → Explain → Code Review sequence is clear and matches the task, and the Code Review section requires stating 'how the change should be verified in the browser', which acts as a verification checkpoint. Minor gap: no explicit re-check loop after applying fixes, so it sits below the explicit-validation anchor.

4 / 5

Progressive Disclosure

The ~45-line body is a clean overview with well-organized sections, and the detailed material (code examples, framework guidance) is correctly split into a real, one-level-deep, clearly signaled pointer: 'For full implementation details, code examples, and framework-specific guidance, see references/rule.md' — the file exists and matches that purpose.

5 / 5

Total

15

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A functional description with an explicit trigger clause and mostly concrete language, but it is weakened by a run-on, ungrammatical clause ('related to Never use eval() or unsafe dynamic code execution') that obscures both the what and the when. Adding the skill's concrete actions and missing synonyms would lift it into the top band.

Suggestions

Rewrite the broken clause 'related to Never use eval() or unsafe dynamic code execution' into a grammatical statement of what the skill does, e.g., 'Finds and replaces eval(), new Function(), and string-argument timers with safe alternatives.'

Add missing natural trigger terms users would say, such as 'XSS', 'new Function', and 'security review'.

State the concrete capabilities (search, fix with JSON.parse/object lookups/function references) so the 'what' is explicit rather than implied by the inspection sentence.

DimensionReasoningScore

Specificity

The description names the domain ('Never use eval() or unsafe dynamic code execution') and a couple of concrete actions ('reviewing scripts, client components, bundles, or runtime behavior', 'Inspect both source code and the browser execution path'), but the run-on construction 'related to Never use eval()' muddles what the skill actually does, so coverage is not comprehensive.

3 / 5

Completeness

It has an explicit 'Use when...' clause ('Use when reviewing scripts, client components, bundles, or runtime behavior...') and a 'what' via 'Inspect both source code and the browser execution path so fixes target the real bottleneck or bug'. Not a 5 because the 'what' is buried in a grammatically broken sentence and never crisply states the skill's capabilities (e.g., find and replace eval with safe alternatives).

4 / 5

Trigger Term Quality

Good natural keywords — 'eval()', 'dynamic code execution', 'scripts', 'client components', 'browser execution path' — that a user reviewing JS code would plausibly say. A few common synonyms are missing (e.g., 'XSS', 'new Function', 'security review'), so it falls just short of the comprehensive anchor.

4 / 5

Distinctiveness Conflict Risk

The eval()/dynamic-code-execution niche is fairly distinct with concrete triggers (scripts, client components, runtime behavior). Minor overlap risk with generic JavaScript code-review or security-review skills, which keeps it below the clear-niche anchor.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.