CtrlK
BlogDocsLog inGet started
Tessl Logo

cross-origin-isolation

Use when reviewing security-sensitive web apps, SharedArrayBuffer usage, worker-heavy apps, editors, or measurement features that require cross-origin isolation. Check both headers and real browser behavior.

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/cross-origin-isolation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured overview with exemplary progressive disclosure to a real, single reference file. Its weaknesses are redundancy across the Check/Fix/Explain/Code Review modes, missing executable header values in the body, and no explicit recovery loop when verification fails.

Suggestions

Inline the two header values (e.g. `Cross-Origin-Opener-Policy: same-origin` + `Cross-Origin-Embedder-Policy: require-corp`) so the body's core action is executable without opening the reference.

Add an explicit ordered workflow with a feedback loop, e.g. "3. Verify `self.crossOriginIsolated === true`; if false, re-check network responses for missing CORP/CORS headers on cross-origin subresources and retry".

Consolidate the repeated audit/verify guidance spread across Quick Reference, Check, Fix, and Code Review into one sequence to cut duplicated tokens.

DimensionReasoningScore

Conciseness

The ~30-line body is short, but it repeats itself: the audit-then-verify guidance appears in Quick Reference ("Audit every cross-origin script, iframe... before enforcing COEP"), Fix ("Add COOP and COEP only after auditing dependencies"), and Code Review ("Flag exact responses or integrations that would block isolation"), and the intro paragraph explains COOP/COEP purpose Claude already knows ("Cross-origin isolation reduces opener-based attacks and XS-Leak risk"). It could be tightened into a single ordered procedure.

3 / 5

Actionability

There is one fully concrete check ("Verify `self.crossOriginIsolated === true`"), but the body gives no executable header values — "Add COOP and COEP" without specifying `Cross-Origin-Opener-Policy: same-origin` / `Cross-Origin-Embedder-Policy: require-corp` — and defers all code to the reference file, leaving key details missing from the body itself.

3 / 5

Workflow Clarity

A sensible sequence is implied across sections (audit dependencies → enforce COOP/COEP → ensure CORP/CORS on subresources → verify crossOriginIsolated), and a verification checkpoint is stated twice. But it is never laid out as an explicit ordered procedure, and there is no recovery guidance for the common failure case where verification fails because one resource blocks isolation.

3 / 5

Progressive Disclosure

The body is a clean overview with well-organized sections and a single clearly signaled, one-level-deep pointer — "For full implementation details, code examples, and framework-specific guidance, see `references/rule.md`" — and that file exists in the bundle with the expected content.

5 / 5

Total

14

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit and specific trigger clause plus distinctive technical keywords. Its main weakness is the vague "what" — "Check both headers and real browser behavior" never names COOP, COEP, or CORP, the core subject of the skill.

Suggestions

State the concrete capability in the 'what' portion, e.g. "Reviews and configures COOP, COEP, and CORP headers and verifies crossOriginIsolated in the browser".

Add the header names (COOP, COEP, CORP) and the property name crossOriginIsolated as trigger terms, since users asking about this topic often use those exact words.

Trim the broad "reviewing security-sensitive web apps" opener to a more distinctive phrase to reduce overlap with general security-review skills.

DimensionReasoningScore

Specificity

The description names its domain ("security-sensitive web apps... that require cross-origin isolation") and one concrete action ("Check both headers and real browser behavior"), but stops short of naming the COOP/COEP/CORP headers it actually works with, so coverage is not comprehensive.

3 / 5

Completeness

It explicitly answers "when" with a concrete "Use when reviewing security-sensitive web apps, SharedArrayBuffer usage..." clause, and gives a "what" ("Check both headers and real browser behavior"). The "what" is thinner than the "when" — it never states the skill configures or fixes COOP/COEP/CORP headers — so it falls just short of the top anchor.

4 / 5

Trigger Term Quality

Strong natural triggers like "SharedArrayBuffer usage", "worker-heavy apps", "editors", "measurement features", and "cross-origin isolation" cover the common ways users would raise this need. A few natural terms are missing — users would also say "COOP", "COEP", "CORP", or "crossOriginIsolated".

4 / 5

Distinctiveness Conflict Risk

The niche is clear (cross-origin isolation, SharedArrayBuffer, worker-heavy apps) with triggers unlikely to fire for unrelated skills. Minor overlap risk comes from the broad opener "reviewing security-sensitive web apps", which could collide with general security-review skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.