CtrlK
BlogDocsLog inGet started
Tessl Logo

https

Use when auditing whether a website or web application serves content exclusively over HTTPS with a valid certificate.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/https/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, concise single-purpose audit skill with clear acceptance criteria and proper progressive disclosure to a real reference file. The main weaknesses are minor redundancy between the Quick Reference and Check sections and the absence of concrete check commands.

DimensionReasoningScore

Conciseness

The body is lean with no explanations of concepts Claude already knows, but the 'Check' section nearly duplicates the Quick Reference bullets ('Verify the TLS certificate is valid, not expired, and covers all hostnames. Confirm HTTP requests redirect to HTTPS with a 301 status code') and 'Explain' is boilerplate that could be trimmed.

4 / 5

Actionability

Concrete acceptance criteria are given (301 redirect, valid cert covering all hostnames, Let's Encrypt/Certbot, SSL Labs A/A+), and implementation commands are appropriately deferred to references/rule.md which contains executable certbot and nginx config. Minor gaps remain, e.g. no CLI check command such as curl -I or openssl s_client in either file.

4 / 5

Workflow Clarity

A clear Check -> Fix -> Explain -> Code Review sequence with verification present ('verify them against the effective production-like response'); as a read-only audit no destructive-operation cap applies. The overlapping roles of 'Check' versus 'Code Review' keep it just below the simple-skill top score.

4 / 5

Progressive Disclosure

A short overview body with a clearly signaled, one-level-deep pointer ('see references/rule.md') for full implementation details; the referenced file exists and content is appropriately split between overview and reference.

5 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit 'Use when' trigger, good natural keywords, and a clear niche, written in third person. Its main limitation is that it compresses the skill's several concrete checks into one composite auditing action rather than enumerating them.

Suggestions

Enumerate the concrete checks the skill performs, e.g. 'Audits whether a site serves all pages over HTTPS, redirects HTTP with a 301, and holds a valid certificate covering all hostnames. Use when auditing HTTPS, TLS/SSL certificate validity, or insecure transport on a website.'

Add common synonyms such as 'TLS', 'SSL', or 'mixed content' to the trigger terms so the description matches the phrasings users naturally say.

DimensionReasoningScore

Specificity

The description names the domain and a single composite action ('auditing whether a website or web application serves content exclusively over HTTPS with a valid certificate'), matching the anchor for 1-2 concrete actions but not comprehensive — it does not enumerate the distinct checks (redirect behavior, certificate expiry, hostname coverage) the body actually covers.

3 / 5

Completeness

Both what (audit HTTPS serving and certificate validity) and when ('Use when auditing...') are present, but the 'what' is embedded inside the when-clause rather than stated independently, so it does not reach level 5's fully explicit dual statement.

4 / 5

Trigger Term Quality

Good natural-term coverage ('HTTPS', 'website', 'web application', 'valid certificate') comparable to the level-4 example, though common synonyms users say such as 'TLS', 'SSL', or 'mixed content' are missing, keeping it below level 5.

4 / 5

Distinctiveness Conflict Risk

A clear niche (HTTPS/certificate auditing) with distinct triggers and only minor overlap risk against closely related sibling rules such as mixed-content or HSTS checks; not level 5 because 'valid certificate' could collide with certificate-specific skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.