CtrlK
BlogDocsLog inGet started
Tessl Logo

password-field-security

Use when reviewing headers, forms, cookies, or third-party integrations related to Secure password input fields. Validate the effective browser and HTTP behavior in a production-like environment.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/password-field-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Content is a tidy overview that offloads detail to a real reference file and gives specific attribute-level guidance rather than vague direction. Its weakest spot is workflow clarity: the sections are modes rather than an explicitly sequenced, checkpointed review process.

Suggestions

Convert Check/Fix/Explain/Code Review into an explicitly numbered review sequence with a validation checkpoint (e.g., 'verify each finding against the live production-like response before reporting').

Add a short copy-paste HTML example showing type='password' with autocomplete='new-password' and an accessible show/hide toggle to raise actionability.

De-duplicate the Quick Reference bullets against the Check/Fix sections so each item lives in one place.

DimensionReasoningScore

Conciseness

The body is lean with no padding or elementary explanations, but the Quick Reference bullets partially overlap the Check/Fix sections (autocomplete and show/hide toggle recur), leaving minor redundancy to trim.

4 / 5

Actionability

Guidance names exact values ('autocomplete='new-password' or 'current-password'', 'type='password'', accessible toggle buttons, strength meters), which is actionable for an instruction-only skill; the gap is the absence of a copy-paste HTML snippet covering the common case.

4 / 5

Workflow Clarity

Check/Fix/Explain/Code Review read more as parallel review modes than a numbered sequence, and while the Code Review section names a verify step ('verify them against the effective production-like response'), validation checkpoints are otherwise implicit rather than explicit.

3 / 5

Progressive Disclosure

The body is a concise overview with clearly signaled one-level-deep navigation to an existing 'references/rule.md', keeping the SKILL.md itself appropriately thin.

5 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is well-formed: third-person, explicit trigger guidance, and concrete review targets tied to a clearly scoped domain. It is just shy of top marks because the stated action (validate behavior) is general and a few natural trigger synonyms are missing.

DimensionReasoningScore

Specificity

Names the domain (Secure password input fields) plus several concrete review targets ('headers, forms, cookies, or third-party integrations') and a concrete action ('Validate the effective browser and HTTP behavior'), but stops short of a comprehensive multi-action list.

4 / 5

Completeness

Explicit 'Use when reviewing...' clause supplies the trigger, and 'Validate the effective browser and HTTP behavior in a production-like environment' supplies the what; the what is somewhat general rather than sharply concrete.

4 / 5

Trigger Term Quality

Includes natural terms a user would say — 'headers, forms, cookies', 'password input fields', 'browser and HTTP behavior' — though some common variants like 'login forms', 'password fields', or 'autofill' are absent.

4 / 5

Distinctiveness Conflict Risk

Scoped tightly to Secure password input fields with specific surface-area triggers (headers, forms, cookies, integrations), giving it a clear niche with only minor overlap risk against adjacent security skills.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.