CtrlK
BlogDocsLog inGet started
Tessl Logo

permissions-policy

Use when reviewing HTTP response headers for defense-in-depth security hardening on any web application.

52

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/permissions-policy/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is a well-structured, appropriately split overview with excellent progressive disclosure, but the inline guidance stops just short of executable: no header-inspection command, no complete example header, and implicit verification. Trimming the duplicated XSS rationale and the 'Explain' section would tighten token efficiency.

Suggestions

Add one concrete inspection command to the Check section (e.g., 'curl -sI https://example.com | grep -i permissions-policy') so the check step is executable rather than descriptive.

Include a single complete recommended header (e.g., 'Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=(), usb=()') in the Fix section as a copy-paste starting point.

Remove the duplicated XSS/blast-radius bullet (it restates the intro) and fold the 'Explain' section into the intro to save tokens.

DimensionReasoningScore

Conciseness

The body is short and mostly efficient (Quick Reference bullets carry real information), but the XSS/blast-radius rationale is stated twice ('A site compromised by XSS... can silently record the user' in the intro and 'Restricting unused features limits the blast radius if your site is compromised by XSS' as a bullet), and the 'Explain' section mostly instructs Claude to do something it already knows how to do. This matches 'Mostly efficient but includes some unnecessary explanation or could be tightened'; not a 4 because the duplication and the filler 'Explain' section are trimmable.

3 / 5

Actionability

There is concrete syntax ('Permissions-Policy: camera=(), microphone=(), geolocation=()' and 'Start with camera=(), microphone=(), geolocation=()'), but the Check section gives no command for actually inspecting headers (e.g., curl -I), and no complete example header or framework config appears inline — details are deferred to references/rule.md. This matches 'Some concrete guidance but incomplete... missing key details'; not a 4 because a ready-to-use header line or inspection command is the obvious missing piece.

3 / 5

Workflow Clarity

The Check → Fix → Explain → Code Review sections form a coherent rough sequence, and 'Code Review' gestures at verification ('verify them against the effective production-like response'), but there is no explicit checkpoint such as how to fetch the live response or how to confirm the header is present after the fix. This matches 'Steps listed but validation gaps; sequence present but checkpoints missing or implicit'; not a 4 because the verification step is implicit rather than an actionable command.

3 / 5

Progressive Disclosure

The body is a concise overview and the 166-line detail file is split out behind a clearly signaled, one-level-deep reference ('For full implementation details, code examples, and framework-specific guidance, see references/rule.md'), and references/rule.md exists in the bundle with no further nesting. This matches the anchor 'Clear overview with well-signaled one-level-deep references; content appropriately split; easy navigation'.

5 / 5

Total

14

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, in the standard 'Use when...' trigger form, and correctly scoped, but it is generic within the security-headers domain. Naming Permissions-Policy and one concrete action (e.g., disabling unused browser features like camera and geolocation) would materially improve trigger matching and distinctiveness.

Suggestions

Name the header explicitly, e.g., 'Set and review the Permissions-Policy (formerly Feature-Policy) HTTP response header...' so users asking about that header trigger this skill rather than sibling header-hardening skills.

Add a concrete capability phrase such as 'disable unused browser features (camera, microphone, geolocation, payment)' to sharpen the 'what' portion.

Include natural trigger variants like 'security headers', 'header audit', or 'browser feature permissions' to broaden natural-language matching.

DimensionReasoningScore

Specificity

The description names the domain ("HTTP response headers") and one concrete action ("reviewing") plus a purpose ("defense-in-depth security hardening"), but never states what the skill actually does with findings (e.g., disable unused browser features). This matches the anchor 'Names domain and 1-2 concrete actions, but not comprehensive'; it is not a 4 because no several specific actions are listed, and not a 2 because the domain and action are concrete rather than generic.

3 / 5

Completeness

It has an explicit 'when' ("Use when reviewing HTTP response headers... on any web application") and a 'what' (reviewing headers for defense-in-depth hardening), satisfying the anchor 'Has both what and when; when could be more explicit or specific'. It is not a 5 because the 'what' stops at 'reviewing' without concrete outcome actions, and not a 3 because the trigger clause is explicit rather than weakly implied.

4 / 5

Trigger Term Quality

Phrases like "HTTP response headers", "security hardening", and "any web application" are relevant keywords, but the description omits the skill's own subject term "Permissions-Policy" and common user phrasings like "security headers", "header check", or "camera/microphone permissions". This matches 'Some relevant keywords but missing common variations or synonyms'; not a 4 because the single most natural trigger term (the header name itself) is absent.

3 / 5

Distinctiveness Conflict Risk

"Reviewing HTTP response headers for defense-in-depth security hardening" would equally describe sibling security-header skills (CSP, HSTS, X-Frame-Options, etc.), since the description never names Permissions-Policy. This matches 'Somewhat specific but could still overlap with similar skills'; not a 4 because the overlap with closely related header-hardening skills is real, not minor.

3 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.