CtrlK
BlogDocsLog inGet started
Tessl Logo

form-https

Use when reviewing HTML forms, fetch/XHR calls, and form action attributes to ensure data is submitted exclusively over HTTPS.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/form-https/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, appropriately disclosed checklist skill whose overview body is lean and points cleanly to a real one-level-deep reference file. The main gaps are the absence of any executable command or code example in the body itself (all actionable detail is one file away) and two short sections that explain transport-security concepts Claude already knows.

Suggestions

Trim the opening paragraph and the 'Explain' section — Claude already knows why plaintext HTTP credentials are interceptable; keep only checklist-specific facts like the Chrome 86+ autofill behavior and the implicit-action rule.

Inline one or two copy-paste audit commands from references/rule.md into the 'Check' section (e.g. the grep for action="http:// and fetch('http:// endpoints) so the skill is immediately executable without loading the reference.

Tighten the vague 'Code Review' section wording ('Flag exact responses, cookies, or browser behaviors') into a concrete verification step, such as confirming the final response is served over HTTPS after the fix.

DimensionReasoningScore

Conciseness

The body is mostly efficient, but the intro paragraph ('anyone on the same Wi-Fi, the ISP, or a network proxy can read them without any special tools') and the entire 'Explain' section restate why plaintext HTTP exposes credentials — a concept Claude already knows — and 'From Chrome 86+' is a version-sensitive detail placed outside any deprecated section. Not 4: these are more than minor trims; not 2: the padding is limited to two short sections.

3 / 5

Actionability

'Scan all HTML form elements for action attributes pointing to http:// URLs' and 'Replace all http:// form action URLs with https:// equivalents' are specific prose instructions, but the body contains no executable commands or code — the grep audit commands and HTML/JS examples all live in references/rule.md. This matches 'some concrete guidance but incomplete', not 4's 'concrete code or commands with minor gaps'.

3 / 5

Workflow Clarity

Check → Fix → Explain → Code Review forms a clear, labeled sequence that ends with a verification step ('verify them against the effective production-like response'), and for this simple single-purpose skill the flow is unambiguous. Not 5: the Code Review section's guidance ('Flag exact responses, cookies, or browser behaviors that violate the rule') is vague and the checkpoints are implicit rather than explicit validate/fix/retry loops.

4 / 5

Progressive Disclosure

The SKILL.md body is a lean, well-organized overview, and implementation details are appropriately split into a clearly signaled, one-level-deep reference ('For full implementation details, code examples, and framework-specific guidance, see references/rule.md'), which is a real file containing the code examples, audit commands, and verification guidance. Navigation is easy and nothing is inlined that belongs in a separate file.

5 / 5

Total

15

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, well-targeted description with an explicit trigger clause and good natural keywords covering a distinct security niche. Its main weakness is that it describes a single action verb (reviewing), making the capability statement less comprehensive than top-scoring examples.

Suggestions

Add one or two more distinct action verbs to round out the capability statement, e.g. 'Reviews HTML forms, fetch/XHR calls, and form action attributes; flags insecure http:// endpoints and fixes them to enforce HTTPS-only submission.'

Include common user phrasings as triggers such as 'insecure forms', 'mixed content', or 'HTTP form submission' to broaden natural keyword coverage.

DimensionReasoningScore

Specificity

"Use when reviewing HTML forms, fetch/XHR calls, and form action attributes to ensure data is submitted exclusively over HTTPS" names the domain and one concrete action (reviewing) applied to specific targets, matching the anchor for 1-2 concrete actions. It is not 4 because it lists a single action verb rather than several distinct actions (no fix/flag/scan), unlike the anchor-4 example with multiple verbs.

3 / 5

Completeness

An explicit "Use when reviewing..." trigger clause is present (so it avoids the completeness cap of 3), and the what — reviewing forms and fetch/XHR calls to enforce HTTPS submission — is explicitly stated. It is not 5 because the what is merged into the when-clause rather than stated as its own concrete capability sentence, unlike the anchor-5 example.

4 / 5

Trigger Term Quality

Natural terms users would say are present: "HTML forms", "fetch/XHR calls", "form action attributes", "HTTPS". It is not 5 because common variations like "insecure forms", "mixed content", "HTTP", or "TLS" are missing.

4 / 5

Distinctiveness Conflict Risk

The form-submission transport-security niche is distinct with specific triggers (form action attributes, fetch/XHR, HTTPS), creating only minor overlap risk with closely related generic security-review or HTTPS skills. Not 5 because a broader 'HTTPS' or 'security review' skill could plausibly claim the same triggers.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.