CtrlK
BlogDocsLog inGet started
Tessl Logo

hsts

Use when reviewing HTTP response headers on any site that serves content over HTTPS.

50

Quality

55%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/hsts/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, appropriately concise overview: exact header values and directive guidance inline, all implementation depth correctly delegated to a verified one-level reference. The only weaknesses are minor — a slightly redundant concept explanation up top and no inline verification command (e.g. a curl invocation) in the Fix/Check sections.

DimensionReasoningScore

Conciseness

The body is lean and well-budgeted: a one-line rationale, a five-bullet Quick Reference with exact values, and four short task sections, with all framework detail correctly pushed to the reference file. The intro sentence explaining SSL stripping and the 'Explain' section restate concepts Claude already knows, which is exactly the 'minor instances of over-explanation that could be trimmed' of the 4-anchor rather than the fully lean 5-anchor.

4 / 5

Actionability

The Quick Reference gives the exact, copy-paste-ready header value ('Strict-Transport-Security: max-age=31536000; includeSubDomains') plus concrete directive guidance (1-year minimum, preload caution, never over HTTP), and the Fix names concrete validation tools (curl, securityheaders.com). It stops short of the 5-anchor because no explicit curl command or server-config snippet appears in the body itself — those live only in references/rule.md — leaving a minor gap for the common verification case.

4 / 5

Workflow Clarity

The Check → Fix → Code Review flow forms a coherent sequence: verify header presence and directives, apply the header, then confirm against the 'effective production-like response', with validation mentioned in both Fix and Code Review. This fits the 4-anchor ('clear sequence with most checkpoints present; minor validation gaps') — an explicit verification command or ordered steps would be needed for a 5, and this is not a destructive/batch operation so no cap applies.

4 / 5

Progressive Disclosure

The ~30-line body is a genuine overview — quick-reference facts only — with a clearly signaled, one-level-deep pointer ('For full implementation details, code examples, and framework-specific guidance, see references/rule.md') to a real file that was verified to contain exactly that detail (nginx/Apache/Next.js/Express configs, preload requirements, common mistakes). This matches the 5-anchor: clear overview, well-signaled single-level reference, appropriate split.

5 / 5

Total

17

/

20

Passed

Description

32%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description functions only as a trigger clause and completely omits the 'what' — the skill's purpose (setting/verifying the HSTS Strict-Transport-Security header) must be inferred from the body. It is also scoped so broadly ('any site that serves content over HTTPS') that it would collide with every other HTTP-header review skill.

Suggestions

State the 'what' explicitly, e.g. 'Sets and verifies the Strict-Transport-Security (HSTS) response header' before the 'Use when' clause, so both halves of completeness are covered.

Add the skill's own natural trigger terms — 'HSTS', 'Strict-Transport-Security', 'security headers', 'SSL stripping' — so users who name the header directly will match this skill.

Narrow the trigger scope from 'any site that serves content over HTTPS' to HSTS-specific contexts (e.g. 'when a site serves HTTPS and you are configuring or auditing transport-security headers') to reduce conflict risk with sibling header rules.

DimensionReasoningScore

Specificity

The description names the domain ('reviewing HTTP response headers on any site that serves content over HTTPS') but offers only one generic action verb, 'reviewing', with no concrete capabilities stated. It never says what the skill actually does (set/verify the Strict-Transport-Security header), so it matches 'names the domain but actions are minimal or generic' rather than the 3-anchor's '1-2 concrete actions'.

2 / 5

Completeness

The description is a single 'Use when...' clause with no 'what' at all — the reader cannot learn that the skill sets or checks an HSTS header. This matches the 2-anchor exactly ('only when is present without what', e.g. 'Use when working with documents'), and it is not the 3-anchor because the what is not merely weakly implied, it is entirely unstated.

2 / 5

Trigger Term Quality

It includes relevant natural keywords like 'HTTP response headers' and 'HTTPS', but omits the most direct terms a user would say for this exact need — 'HSTS', 'Strict-Transport-Security', 'security headers', 'SSL/TLS stripping'. This lands between 'some relevant keywords but missing common variations' (3) and 'good keyword coverage' (4); because the skill's own name is absent from the triggers, 3 is the better fit.

3 / 5

Distinctiveness Conflict Risk

'Reviewing HTTP response headers on any site that serves content over HTTPS' is very broad: it would trigger for reviews of CSP, X-Frame-Options, CORS, cookies, or any other header rule, all of which overlap heavily with sibling header/security skills. It does not reach the 3-anchor because the scoping to HSTS specifically is absent.

2 / 5

Total

9

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.