CtrlK
BlogDocsLog inGet started
Tessl Logo

subresource-integrity

Use when reviewing templates, rendered HTML, or shared components related to Add Subresource Integrity to external scripts. Validate the final browser-facing markup, not just the source framework abstraction.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/subresource-integrity/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured overview with excellent progressive disclosure into a real, one-level reference file, and its Check/Fix guidance is concrete. The main costs are a redundant concept explanation in the intro and an unsurfaced hash-generation command and verification step.

Suggestions

Cut the intro's explanation of what SRI is and why it matters (Claude already knows this), and drop the fourth Quick Reference bullet that repeats it verbatim in substance.

Surface the one-line openssl hash command (or an explicit pointer to the Generating Hash Values section) in the Fix section so the core executable step is in the body.

Add a brief verify step after Fix (re-check the rendered markup / confirm the hash matches) or link the Verification section from the body.

DimensionReasoningScore

Conciseness

The body is mostly lean, but the 3-sentence intro paragraph explains what SRI is and why it matters — a concept Claude already knows — and the Quick Reference bullet 'SRI blocks execution if the file hash doesn't match, preventing CDN compromise attacks' repeats the intro. It fits anchor 3 ('some unnecessary explanation or could be tightened') better than anchor 4, since the concept explanation is more than a minor instance.

3 / 5

Actionability

Concrete guidance includes exact attribute syntax ('integrity="sha384-..."', 'crossorigin="anonymous"'), specific tag types ('<script> and <link rel=stylesheet> tags ... that load from CDNs'), and a precise Check instruction. Not anchor 5 because the key executable step — the hash-generation command — is only gestured at ('Generate hashes with openssl or online tools') and deferred to the reference without being surfaced.

4 / 5

Workflow Clarity

The Check → Fix sequence is clear and the Check/Fix/Explain/Code Review modes are unambiguously delineated for this single-purpose review skill. Not anchor 5 because post-fix verification (confirm the hash matches and the page still loads) is not surfaced in the body even though a Verification section exists in references/rule.md; not anchor 3 since the sequence and task boundaries are fully explicit.

4 / 5

Progressive Disclosure

The ~45-line body is a well-organized overview (Quick Reference, Check, Fix, Explain, Code Review) with a clearly signaled one-level-deep pointer — 'For full implementation details, code examples, and framework-specific guidance, see references/rule.md' — and the referenced file exists and holds those details without nested references.

5 / 5

Total

16

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit, well-targeted 'Use when' clause with concrete trigger phrases and a distinct niche. Its weaknesses are a thin capability statement ('what' side) and missing common trigger synonyms like 'SRI' and 'CDN'.

Suggestions

Add the natural synonyms users actually say — 'SRI', 'CDN', 'integrity hash' — to the trigger clause so it matches how the skill is requested.

State the capability in third-person parallel to the trigger clause, e.g. 'Adds integrity and crossorigin attributes to CDN-loaded script/link tags and generates SHA-384 hashes. Use when...'.

Broaden the 'what' beyond a single validation action so the skill's fix/generate capabilities are explicit.

DimensionReasoningScore

Specificity

Names the domain ('Add Subresource Integrity to external scripts') and 1-2 concrete actions ('reviewing templates, rendered HTML, or shared components', 'Validate the final browser-facing markup'), but does not comprehensively list capabilities such as adding integrity attributes or generating hashes. It falls below anchor 4 because the action list is minimal rather than having only minor gaps.

3 / 5

Completeness

Explicit 'Use when...' clause with concrete triggers is present, and a 'what' exists ('Validate the final browser-facing markup, not just the source framework abstraction'). Not anchor 5 because the 'what' is a single thin action entangled with the trigger phrasing rather than a clear standalone capability statement; well above anchor 3 since both what and when are explicit.

4 / 5

Trigger Term Quality

Good natural keyword coverage — 'templates', 'rendered HTML', 'shared components', 'Subresource Integrity', 'external scripts' — but common variations users would say are missing, notably the abbreviation 'SRI', 'CDN', and 'integrity hash'. Not anchor 5 because synonym coverage is incomplete; clearly above anchor 3 since multiple natural trigger phrases are present.

4 / 5

Distinctiveness Conflict Risk

Clear niche (SRI on external CDN-loaded scripts in rendered markup) with distinct, specific trigger phrases; minimal risk of firing for unrelated HTML or security skills.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.