CtrlK
BlogDocsLog inGet started
Tessl Logo

stack-trace-exposure

Use when reviewing error handling middleware, API route handlers, or server responses for security-sensitive information disclosure.

56

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/stack-trace-exposure/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-structured overview: brief motivation, actionable quick-reference rules, a clear check/fix/explain/review flow, and an exemplary handoff to a single real reference file. Minor improvements would trim the OWASP/attacker background paragraph and surface a one-line verification step in the body itself.

DimensionReasoningScore

Conciseness

The body is lean (~35 lines) with terse, directive sections ("Never return raw error objects or stack traces in API responses", "Log full error details server-side"). The only trimmable material is the opening paragraph explaining attacker CVE-lookup behavior and OWASP A09 — background Claude largely already knows — which keeps it at 'efficient; minor instances of over-explanation' rather than the fully lean anchor 5.

4 / 5

Actionability

The Quick Reference bullets and the Code Review section give concrete, executable directives, including specific patterns to search for — "Flag any location where error.stack, error.message (raw), or internal paths are serialised directly into a response body". It stops short of anchor 5 because no code or commands appear in the body itself (implementation details are deferred to the reference), leaving minor gaps if the reference were unavailable.

4 / 5

Workflow Clarity

The Check → Fix → Explain → Code Review sections give a coherent, ordered review-and-remediation flow for a single-purpose skill, and the Quick Reference anchors the key rules. It fits 'clear sequence with most checkpoints present; minor validation gaps' (4) rather than 5 because explicit verification of the fix is not stated in the body — it lives only in references/rule.md's Verification section.

4 / 5

Progressive Disclosure

The body is a concise overview and defers all implementation details, code examples, and framework-specific guidance via a clearly signaled, one-level-deep pointer: "see `references/rule.md`" — and references/rule.md exists in the bundle and delivers exactly what the pointer promises. This matches 'clear overview with well-signaled one-level-deep references; content appropriately split; easy navigation' with no nesting or buried references.

5 / 5

Total

17

/

20

Passed

Description

52%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has strong trigger phrasing and clear topical focus, but it omits any statement of what the skill does, reading as a pure 'Use when...' clause. Adding a capability statement (e.g., 'Flags and fixes stack trace and internal-detail leakage in production error responses') and the central term 'stack traces' would raise it substantially.

Suggestions

Add a 'what' statement before the trigger clause, e.g., 'Flags and helps fix stack trace and internal-detail exposure in production API error responses. Use when reviewing error handling middleware...' — this addresses the completeness gap (score 2).

Include the skill's central natural terms — 'stack traces', 'error messages', 'leaking' — in the description so users who literally say 'check for stack trace leaks' trigger this skill (trigger_term_quality).

Mention the concrete actions the skill performs (flag offending code locations, apply a central sanitized error handler, assign correlation IDs) to move specificity beyond a single 'reviewing' verb.

DimensionReasoningScore

Specificity

The description names a concrete domain and one concrete action — "reviewing error handling middleware, API route handlers, or server responses" — but offers only a single action verb rather than several specific capabilities (e.g., flag, fix, sanitize). It fits the anchor 'names domain and 1-2 concrete actions, but not comprehensive'; a 4 would require several distinct actions listed, and a 2 would require generic or minimal action language, which is not the case given the precise review targets.

3 / 5

Completeness

The description is solely a trigger clause — "Use when reviewing error handling middleware, API route handlers, or server responses for security-sensitive information disclosure" — with no statement of what the skill actually does (e.g., 'Flags and helps fix stack trace exposure'). This matches the anchor 'only "when" is present without "what"' (score 2); it cannot score 3 or 4 because those anchors require a clear 'what' component, which is entirely absent here.

2 / 5

Trigger Term Quality

Natural phrases a developer or security reviewer would say are present: "error handling middleware", "API route handlers", "server responses", "security-sensitive information disclosure". However, the most central natural terms — "stack traces", "error messages", "leaking" — are absent, so it falls just short of comprehensive synonym coverage (5) while clearly exceeding 'some relevant keywords but missing common variations' (3).

4 / 5

Distinctiveness Conflict Risk

The niche is fairly distinct — combining error-handling surfaces with security-sensitive information disclosure is specific enough that it would rarely fire for an unrelated skill. There is minor overlap risk with broader security-audit or error-handling skills, so it fits 'mostly distinct; minor overlap risk' (4) rather than 'clear niche with minimal conflict risk' (5).

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.