CtrlK
BlogDocsLog inGet started
Tessl Logo

mixed-content

Use when reviewing an HTTPS page for resources (scripts, images, stylesheets, iframes) that are loaded over plain HTTP.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/mixed-content/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, token-efficient overview that defers implementation detail appropriately to a single verified one-level-deep reference, with concrete check/fix guidance and a coherent workflow. Its only weaknesses are minor: a duplicated CSP bullet in Quick Reference and an implicit rather than explicit verification feedback loop.

DimensionReasoningScore

Conciseness

The ~46-line body is lean and sectioned with no padding explaining concepts Claude already knows, but Quick Reference contains two bullets both stating that 'upgrade-insecure-requests' is the practical fix, and the opening line duplicates the 'Why It Matters' framing from the reference. These are minor instances of over-explanation that could be trimmed, matching anchor 4 rather than the fully lean anchor 5.

4 / 5

Actionability

The Check and Fix sections give concrete, specific instructions — exact attributes to scan ('Check <script src>, <img src>, <link href>, <iframe src>, and CSS url() values for http:// URLs') and the exact remediation ('Replace all http:// resource URLs with https:// equivalents', 'Add Content-Security-Policy: upgrade-insecure-requests'). No executable command appears inline in SKILL.md itself (the grep and config snippets live in references/rule.md), leaving minor gaps that fit anchor 4.

4 / 5

Workflow Clarity

The Check → Fix → Explain → Code Review sections form a clear, coherent sequence, and a verification checkpoint is present ('verify them against the effective production-like response'). However, verification is a single implicit step with no explicit validate→fix→retry feedback loop, matching 'clear sequence with most checkpoints present; minor validation gaps' rather than anchor 5.

4 / 5

Progressive Disclosure

The body is a concise, well-sectioned overview with one clearly signaled, one-level-deep reference — 'For full implementation details, code examples, and framework-specific guidance, see references/rule.md' — and that file exists and delivers exactly what the pointer promises (code examples, CSP configs for Nginx/Next.js, detection tooling) with no nested references. This matches 'clear overview with well-signaled one-level-deep references; easy navigation'.

5 / 5

Total

17

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A distinct, well-targeted trigger description with good natural keywords, but it is a single 'Use when' clause: it never states the skill's name or domain concept ('mixed content') and only covers detection, not the fix and CSP remediation guidance the skill contains. Adding a leading 'what' clause naming 'mixed content' would raise both completeness and trigger-term quality.

Suggestions

Add an explicit 'what' clause before the trigger, e.g. 'Detect and fix mixed content on HTTPS pages' so the skill's full capability (detection and remediation, including the upgrade-insecure-requests CSP fix) is stated, not just the review step.

Include the canonical term 'mixed content' (and a synonym like 'insecure resources') in the description so users who say the standard phrase match this skill naturally.

Consider mentioning the CSP 'upgrade-insecure-requests' fix in the description, since it is the skill's most practical remediation and a term users may ask about directly.

DimensionReasoningScore

Specificity

The description names the domain and one concrete action — 'reviewing an HTTPS page for resources (scripts, images, stylesheets, iframes) that are loaded over plain HTTP' — but covers only detection, not the fix/remediation capabilities the skill provides. It matches 'names domain and 1-2 concrete actions, but not comprehensive' rather than 'several specific actions'.

3 / 5

Completeness

An explicit 'Use when...' trigger clause is present, and the 'what' (reviewing HTTPS pages for HTTP-loaded sub-resources) is conveyed by the gerund phrase within it. Both what and when are answerable, but the 'what' is embedded rather than independently stated and omits the remediation half of the skill, matching 'both present; could be more explicit'.

4 / 5

Trigger Term Quality

Good natural keyword coverage ('HTTPS page', 'scripts, images, stylesheets, iframes', 'plain HTTP', 'reviewing'), but the canonical phrase users would say — 'mixed content' — is entirely absent. Fits 'good keyword coverage; a few natural terms missing' rather than comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

The trigger describes a narrow, well-defined scenario (HTTP sub-resources on an HTTPS page) with distinct terms that few other skills would claim, giving minimal conflict risk. Fits 'clear niche with distinct triggers; minimal conflict risk'.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.