CtrlK
BlogDocsLog inGet started
Tessl Logo

http-to-https

Use when checking whether a web server is configured to redirect all HTTP traffic to HTTPS.

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/http-to-https/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a tight, well-structured overview for a simple single-purpose rule: concrete check/fix guidance, an explicit verification command, and a properly signaled one-level reference. Only minor trims to already-known rationale and slightly deferred executable config keep it from the top conciseness and actionability anchors.

DimensionReasoningScore

Conciseness

The body is lean with well-scoped sections and no padding, but the intro sentence explaining attack exposure and the 'so browsers and search engines cache the redirect' rationale restate knowledge Claude already has and could be trimmed.

4 / 5

Actionability

Concrete specifics are provided — 'HTTP 301', 'https://$host$request_uri', 'curl -I http://example.com', and checking the 'redirect Location header' for path and query preservation — but no executable server configuration is inlined, leaving minor gaps covered by the reference file.

4 / 5

Workflow Clarity

This is a simple single-purpose skill with an unambiguous action, and the Check → Fix flow includes an explicit validation step ('Verify the redirect with curl -I http://example.com'), satisfying the simple-skill exception; the operation is not destructive or batch, so no validation cap applies.

5 / 5

Progressive Disclosure

The body is a concise overview and appropriately defers implementation details to a clearly signaled, one-level-deep reference ('see references/rule.md'), which exists in the bundle and matches the body's framing.

5 / 5

Total

18

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, uses third person, and has an explicit trigger clause targeting a well-defined niche. Its main weakness is that only a single action (checking) is stated and the 'what' is not separated from the 'when', leaving it slightly short of the top anchors.

Suggestions

State the what and the when separately, e.g., 'Checks that a web server redirects all HTTP traffic to HTTPS with a 301 preserving the path and query. Use when auditing a site's HTTPS configuration or when the user mentions HTTP redirects, insecure connections, or forcing HTTPS.'

Add common trigger synonyms such as 'TLS', 'SSL', 'force HTTPS', or '301 redirect' so the skill matches the natural phrasing users actually employ.

Mention the companion actions the skill body covers (fixing the server config, verifying with curl, adding HSTS) so the description's capability coverage is more comprehensive.

DimensionReasoningScore

Specificity

The description names the domain and one concrete action — 'checking whether a web server is configured to redirect all HTTP traffic to HTTPS' — but does not list several actions (e.g., fixing, verifying, adding HSTS), matching the anchor for 1-2 concrete actions that are not comprehensive.

3 / 5

Completeness

An explicit 'Use when...' clause is present, and the what (checking the redirect configuration) is stated, but it is embedded inside the when-clause rather than clearly and separately answering both what and when as the anchor-5 example does.

4 / 5

Trigger Term Quality

Terms like 'web server', 'HTTP', 'HTTPS', 'redirect', and 'traffic' are natural phrases a user would say when auditing site security, but common variations such as 'TLS', 'SSL', 'force HTTPS', or '301' are missing.

4 / 5

Distinctiveness Conflict Risk

The description targets a clear niche — auditing HTTP-to-HTTPS redirect configuration — with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.