CtrlK
BlogDocsLog inGet started
Tessl Logo

form-captcha

Use when reviewing public HTML forms (no authentication required to reach them) for bot and abuse protection mechanisms.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/form-captcha/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, token-efficient overview with actionable, service-specific guidance and an exemplary progressive-disclosure split to references/rule.md. The main gaps are minor redundancy across sections, a slightly padded motivation opener, and the absence of explicit feedback loops for acting on review findings.

DimensionReasoningScore

Conciseness

The body is lean (~35 lines) with a dense Quick Reference list and short Check/Fix/Explain sections that assume Claude's competence. It falls short of 5 because the opening motivation paragraph states abuse consequences ('thousands of spam accounts per minute ... millions of username/password combinations') that Claude already knows, and rate limiting and server-side validation are each repeated across the Quick Reference, Check, and Fix sections.

4 / 5

Actionability

The guidance names concrete services (Cloudflare Turnstile, hCaptcha, Google reCAPTCHA v3), concrete checks (honeypot fields, server-side token validation), and a specific fix order, with code correctly deferred to references/rule.md — actionable for an instruction-only skill per the rubric's scoring note. It does not reach 5 because some guidance remains high-level (e.g., 'Add rate limiting as a defense-in-depth measure' gives no specifics, and no inline snippet covers the common case).

4 / 5

Workflow Clarity

The Check → Fix → Explain → Code Review sections give a clear sequence, and Check includes a verification step ('Verify any CAPTCHA tokens are validated server-side') plus 'verify them against the effective production-like response' in Code Review. It matches anchor 4 rather than 5 because there are no explicit error-recovery or feedback-loop steps (e.g., what to do when a review finding is confirmed or a token fails validation).

4 / 5

Progressive Disclosure

The body is a concise overview with a single, well-signaled, one-level-deep reference ('see references/rule.md' for implementation details, code examples, and framework-specific guidance), and the referenced file exists and delivers exactly that content. This matches the anchor for a clear overview with well-signaled one-level-deep references and easy navigation; the split between overview and detail file is appropriate.

5 / 5

Total

17

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, in third person, and clearly combines a 'what' with an explicit 'Use when' trigger, so it is functional and reasonably distinct. Its main weakness is trigger-term coverage: the most natural keywords a user would say for this skill ('CAPTCHA', 'spam') are missing, and it names only one concrete action, capping specificity.

Suggestions

Add the skill's most natural trigger words to the description, e.g. 'Use when reviewing public HTML forms (no authentication required to reach them) for CAPTCHA, honeypot, rate limiting, and other bot and abuse protection mechanisms' — 'CAPTCHA' and 'spam' are the terms users are most likely to actually say.

Name the concrete actions the skill performs rather than just 'reviewing', e.g. 'Checks forms for CAPTCHA/honeypot coverage, verifies tokens are validated server-side, and explains fixes for missing bot protection' to raise specificity.

Add trigger-phrase variations to the 'when' clause (e.g. 'or when the user mentions captcha, spam bots, credential stuffing, or form abuse') to make both completeness and trigger coverage comprehensive.

DimensionReasoningScore

Specificity

The description names the domain ('reviewing public HTML forms (no authentication required to reach them)') and one concrete action ('for bot and abuse protection mechanisms'), which matches the anchor for naming a domain with 1-2 concrete actions but not comprehensive coverage. It does not reach 4 because it lists only the single review action rather than several specific actions, and it is above 2 because the actions named are concrete, not generic.

3 / 5

Completeness

Both 'what' ('reviewing public HTML forms ... for bot and abuse protection mechanisms') and 'when' ('Use when reviewing ...') are explicitly present in a clear trigger clause. It does not reach 5 because the trigger is a single combined clause without concrete phrase variations or synonyms (e.g., 'when the user mentions CAPTCHA, spam protection, or bot mitigation'), leaving the 'when' slightly less specific than the 5 anchor.

4 / 5

Trigger Term Quality

It includes relevant keywords such as 'public HTML forms', 'bot', and 'abuse protection', but is missing the most natural synonym users would say for this skill — 'CAPTCHA' — as well as 'spam' and 'rate limiting'. This matches the anchor for some relevant keywords but missing common variations or synonyms; it is not 4 because CAPTCHA is the single most likely trigger word and it is absent, and not 2 because several genuinely natural terms are present.

3 / 5

Distinctiveness Conflict Risk

The niche — unauthenticated public HTML forms and bot/abuse protection — is clearly delineated and unlikely to trigger for unrelated skills. It matches 'mostly distinct; minor overlap risk with closely related skills' because sibling security-review rules (rate limiting, form validation, auth) could plausibly overlap; it is not 5 because the description does not fully disambiguate from those adjacent form-security skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.