CtrlK
BlogDocsLog inGet started
Tessl Logo

session-cookie-flags

Use when reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response headers.

56

Quality

64%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/session-cookie-flags/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, appropriately brief overview with excellent progressive disclosure to references/rule.md and clearly actionable check/fix/review guidance. Its main weakness is redundancy: the attack-vector explanation appears both in the opening paragraph and again in the Quick Reference bullets, re-teaching cookie-flag semantics Claude already knows.

Suggestions

Drop the duplicated attack-per-flag prose — keep either the Quick Reference bullets or the intro paragraph, not both (the full explanation already lives in references/rule.md).

Add a one-line inline example of a correctly flagged Set-Cookie in the Fix section so the target state is visible without opening the reference.

Add a brief verification step after Fix (re-check Set-Cookie headers to confirm all three flags are present) to close the workflow loop.

DimensionReasoningScore

Conciseness

The body is mostly lean, but the opening paragraph ("Without Secure, session tokens are transmitted in plain text over HTTP... any XSS payload can exfiltrate the session token in one line...") re-explains standard cookie-flag semantics Claude already knows, and the same attack-per-flag mapping is then repeated almost verbatim in the Quick Reference bullets (and again in references/rule.md). Removing the duplicated prose would lift it to 4–5.

3 / 5

Actionability

The guidance is concrete and specific for an instruction-only skill: "Update the server's cookie configuration to include Secure, HttpOnly, and SameSite=Strict (or Lax) on all session and auth cookies" and "Flag any cookies missing the HttpOnly flag, absent Secure flag, or an unspecified or overly permissive SameSite setting". Per the code-vs-instruction note the absence of code is not penalized, but there is a minor gap: no inline example of a correctly flagged Set-Cookie (it is deferred to the reference).

4 / 5

Workflow Clarity

The Check / Fix / Explain / Code Review sections give a clear, unambiguous structure for a simple skill, with the Check and Code Review sections acting as verification of current state before Fix. It is not 5 because there is no explicit validation step after applying the fix (e.g. re-inspecting the Set-Cookie headers to confirm all flags are present).

4 / 5

Progressive Disclosure

The body is a concise, well-sectioned overview and the single reference is clearly signaled one level deep: "For full implementation details, code examples, and framework-specific guidance, see `references/rule.md`" — the file exists and indeed holds the code example, flag table, and framework implementations. Content is appropriately split between overview and detail file with easy navigation.

5 / 5

Total

16

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has a well-formed, specific 'Use when' trigger clause with natural keywords, but it entirely omits what the skill actually does (verify/configure Secure, HttpOnly, and SameSite cookie flags). The heavy lean on trigger context with no capability statement caps completeness and leaves it less distinctive than it could be.

Suggestions

Add a leading 'what' clause in third person, e.g. 'Verify and configure the Secure, HttpOnly, and SameSite flags on session and authentication cookies. Use when...'.

Include the natural trigger terms users most likely say for this skill: "cookie flags", "Set-Cookie", "HttpOnly", "SameSite", "session cookies".

Tighten distinctiveness by tying the triggers explicitly to cookie flags (e.g. 'auditing Set-Cookie headers or cookie configuration') rather than broad 'server-side session management'.

DimensionReasoningScore

Specificity

Names the domain and several concrete activity types — "reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response headers" — which are specific rather than generic. It falls short of 5 because the actual capability (setting/verifying Secure, HttpOnly, and SameSite flags) is never stated, leaving a notable gap in coverage.

4 / 5

Completeness

Only the 'when' is present ("Use when reviewing...") with no 'what' — the description never states what the skill does. This matches the anchor 'only when is present without what' (e.g. "Use when working with documents"); despite the 'when' clauses being specific, scoring only what is explicitly stated, the 'what' cannot be credited, keeping it below 3.

2 / 5

Trigger Term Quality

Good natural keyword coverage: "session management", "authentication middleware", "cookie configuration", "HTTP response headers" — phrases a user would plausibly say. Key natural terms users would use for this exact skill are missing: "cookie flags", "Set-Cookie", "HttpOnly", "SameSite", "Secure flag", so it is not comprehensive enough for 5.

4 / 5

Distinctiveness Conflict Risk

The trigger scope is a fairly distinct security niche (session cookies, auth middleware, cookie headers) with minor overlap risk against broader authentication or general security-audit skills. It is not a 5 because "reviewing server-side session management" could also fire broader session/auth skills that don't focus on cookie flags.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.