CtrlK
BlogDocsLog inGet started
Tessl Logo

password-field-security

Use when reviewing headers, forms, cookies, or third-party integrations related to Secure password input fields. Validate the effective browser and HTTP behavior in a production-like environment.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/password-field-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-structured body for a simple review skill: concrete attribute-level guidance up front, a clear Check/Fix/Explain flow, and an appropriately deferred one-level reference containing the code examples. The only real issues are the redundant Check vs. Code Review sections and the intro sentence duplicating the reference file's rationale.

DimensionReasoningScore

Conciseness

The ~30-line body is lean and assumes Claude's competence with no padding or explanation of known concepts. Minor redundancy keeps it below anchor 5: the 'Check' section ('Verify password fields use type='password'...') and 'Code Review' section ('Review server config, headers, forms... Flag exact responses...') repeat the same instruction, and the intro sentence duplicates the reference file's 'Why It Matters' text.

4 / 5

Actionability

The guidance names exact, executable specifics — type='password', autocomplete='new-password'/'current-password', accessible toggle buttons, strength meters with requirements, and a Quick Reference checklist — and points to references/rule.md for code. Per the instruction-skill scoring note the absence of inline code is not penalized, but a couple of checks ('support password managers with proper input names') remain high-level hints, so anchor 5's copy-paste-ready specificity is not met.

4 / 5

Workflow Clarity

For a simple single-purpose review skill, the Check → Fix → Explain sequence is unambiguous, and 'Code Review' adds a verification step ('verify them against the effective production-like response'). It sits below anchor 5 because the Check and Code Review sections overlap without a clear division of when to use which, but there is no missing-validation concern since the operation is non-destructive.

4 / 5

Progressive Disclosure

The short body is well organized into Quick Reference, Check, Fix, Explain, and Code Review sections, and the single bundle file references/rule.md is real, clearly signaled at the bottom ('For full implementation details, code examples, and framework-specific guidance, see references/rule.md'), and exactly one level deep. The split of overview-in-body versus details-and-code-in-reference matches anchor 5's structure.

5 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit 'Use when' trigger clause and a clear domain focus on secure password input fields. Its main weakness is that the 'what' is expressed as generic review/validate actions rather than the concrete capabilities (autocomplete attribute checks, show/hide toggles, strength indicators) the skill actually covers.

Suggestions

State the concrete capabilities in the 'what' clause, e.g. 'Checks password fields for correct autocomplete attributes, accessible show/hide toggles, and strength indicators. Validate the effective browser and HTTP behavior in a production-like environment.'

Add common natural trigger variations such as 'login form', 'sign-up form', or 'autocomplete' to broaden keyword coverage.

Narrow the when-clause's generic 'headers, forms, cookies' list to password-field-specific triggers to reduce overlap with sibling form/cookie security skills.

DimensionReasoningScore

Specificity

Names the domain ('Secure password input fields') with two concrete actions — 'reviewing headers, forms, cookies, or third-party integrations' and 'Validate the effective browser and HTTP behavior' — but coverage is not comprehensive (no mention of specific checks like autocomplete values, toggles, or strength meters). Fits anchor 3 ('1-2 concrete actions, but not comprehensive') better than anchor 4, whose example lists three-plus distinct actions.

3 / 5

Completeness

Both parts are present: the 'what' ('Validate the effective browser and HTTP behavior in a production-like environment') and an explicit 'when' ('Use when reviewing headers, forms, cookies, or third-party integrations related to Secure password input fields'). The 'what' is somewhat abstract about what the skill actually delivers (checks/fixes for password fields), keeping it below anchor 5's fully concrete what-and-when; the explicit 'Use when' clause keeps it above anchor 3.

4 / 5

Trigger Term Quality

Good natural keyword coverage: 'headers, forms, cookies, third-party integrations', 'password input fields', 'browser', 'HTTP', 'production-like environment' are phrases users would naturally say. A few common variations are missing ('login form', 'sign-up', 'autocomplete', 'password manager'), so it does not reach anchor 5's comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

The password-field niche is distinct, but the broad trigger terms 'headers, forms, cookies, or third-party integrations' overlap with sibling web-security review skills (e.g., other frontend checklist rules covering forms, cookies, or headers), so minor overlap risk remains rather than anchor 5's minimal-conflict niche.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.