CtrlK
BlogDocsLog inGet started
Tessl Logo

https-downgrade

Use when auditing a site's internal and external links for protocol consistency, migrating a site from HTTP to HTTPS, or reviewing hardcoded URLs in a codebase that may use `http://` instead of `https://`.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/https-downgrade/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable body with an excellent progressive-disclosure split to references/rule.md. The main cost is redundancy: the mixed-content rationale is repeated across the intro, Quick Reference, and Explain sections, and the workflow lacks an explicit verify-then-retry loop for the batch search-and-replace step.

Suggestions

Consolidate the mixed-content explanation into one place — drop the duplicated warning language from the intro and Quick Reference, and keep only the domain-specific details (referrer ranking-signal loss, redirect cost) in Explain.

Add a feedback loop after the verify step: "If the grep still returns matches, fix them and re-run; then confirm the HTTP→HTTPS server redirect responds with 301" — this would lift workflow clarity to 5.

Move or compress the Code Review section's overlap with Check (both enumerate the same attribute scanning) so each section has a single distinct job.

DimensionReasoningScore

Conciseness

The mixed-content consequence is explained three times — in the intro ("creates a mixed content situation that browsers warn users about or block entirely"), in the Quick Reference bullets, and again in the Explain section — concepts Claude already knows. The bulk (Check/Fix/Code Review) is lean, so this is removable padding rather than pervasive verbosity, matching the 3 anchor.

3 / 5

Actionability

Fully executable guidance throughout: a copy-paste grep command (`grep -r 'href="http://' ./templates/`), concrete before/after transformations (`http://yourdomain.com/path` → `/path`), specific attribute targets (`<a href>`, `<img src>`, `<script src>`, `<link href>`), and framework-specific call sites (`fetch()`, `axios`, router navigation).

5 / 5

Workflow Clarity

The Fix section is a clear 7-step sequence (audit → internal → external → resources → CMS replace → server redirect → verify) with a verification step and a mid-flow checkpoint (check the destination supports HTTPS before updating). It falls short of 5 because there is no feedback loop — nothing says what to do when the verify grep still finds matches.

4 / 5

Progressive Disclosure

A ~40-line overview with clearly signaled, one-level-deep references: "For full implementation details, code examples, and framework-specific guidance, see `references/rule.md`" — verified to be a real 109-line file with no further nested references. The split (summary in SKILL.md, details in the reference) matches the 5 anchor exactly.

5 / 5

Total

17

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, trigger-focused description with three concrete, naturally phrased use cases. Its main weakness is that the "what" (the fix/flagging outcome) is never stated independently of the "when", and the core concept "mixed content" is absent from the trigger terms.

Suggestions

State the skill's outcome explicitly before the trigger clause, e.g. "Flags and fixes insecure `http://` links that cause mixed-content warnings. Use when auditing..." — this would raise both specificity and completeness.

Add "mixed content" and "insecure links" as trigger terms, since users debugging browser security warnings naturally use those phrases.

Clarify that the audit targets both page markup and code (templates, JS fetch/router calls) to further distinguish it from generic site-migration skills.

DimensionReasoningScore

Specificity

Lists three concrete actions with specific objects ("auditing a site's internal and external links", "migrating a site from HTTP to HTTPS", "reviewing hardcoded URLs in a codebase"), but never states the fix/flag outcome the skill produces — a minor coverage gap that keeps it below the comprehensive 5 anchor.

4 / 5

Completeness

The "Use when" clause is explicit with three distinct trigger conditions, but the "what" (flag/fix HTTP links) is only implied by verbs embedded inside the trigger clause rather than stated independently as in the 5 anchor.

4 / 5

Trigger Term Quality

Good natural-term coverage: "HTTP to HTTPS", "hardcoded URLs", "internal and external links", and the `http://`/`https://` literals users would actually type. Missing a few natural synonyms like "mixed content", "insecure links", or "SSL", which the 5 anchor expects.

4 / 5

Distinctiveness Conflict Risk

The protocol-consistency niche with `http://`/`https://` triggers is mostly distinct, but "migrating a site from HTTP to HTTPS" and "auditing" could overlap with broader site-migration or general SEO-audit skills — minor overlap risk, matching the 4 anchor.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.