CtrlK
BlogDocsLog inGet started
Tessl Logo

token-storage-security

Use when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based token theft.

59

Quality

69%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/token-storage-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, well-organized overview with specific, actionable review and remediation guidance, and it uses its single reference file exactly as progressive disclosure intends. Its main weakness is workflow clarity: the section sequence is implicit and validation checkpoints live only in the reference, unmentioned in the body.

Suggestions

Make the workflow explicit — order or number the Check → Fix → Explain flow and clarify that Code Review is the detection step that feeds Check, so the sequence isn't ambiguous.

Mention the verification steps in the reference pointer (e.g., 'see references/rule.md for implementation details and a 5-step verification checklist') so validation checkpoints aren't hidden one level deep.

Remove the duplicated localStorage-readability statement between the intro paragraph and Quick Reference bullet 2 to tighten conciseness.

DimensionReasoningScore

Conciseness

The ~30-line body is tight and operational (Quick Reference bullets, Check/Fix/Explain/Code Review sections), but the intro's 'localStorage is accessible to any JavaScript running on the page' is duplicated almost verbatim by Quick Reference bullet 2, and that localStorage-vs-httpOnly explanation is background Claude already knows. Not 3 because the padding is minor and localized.

4 / 5

Actionability

Concrete, specific guidance throughout: exact storage mechanisms ('localStorage/sessionStorage to httpOnly cookies set by the server'), exact flags ('Secure and SameSite'), exact APIs to flag ('localStorage.setItem, sessionStorage.setItem, document.cookie'), and exact HTTP methods ('POST, PUT, PATCH, and DELETE'). Not 5 because the actual implementation 'how' is entirely deferred to the reference — the body gives no code or commands of its own, and CSRF defense mechanics are only named, not shown.

4 / 5

Workflow Clarity

The Check → Fix → Explain → Code Review sections read as a rough review-and-remediation flow, but the sequence is never made explicit — Check and Code Review overlap without clarification of their relationship, and there are no validation checkpoints in the body (the reference's five Verification steps exist but are not surfaced or signaled). This matches anchor 3: steps present, checkpoints implicit.

3 / 5

Progressive Disclosure

The body is a clean overview (under 50 lines) that appropriately defers 'full implementation details, code examples, and framework-specific guidance' to references/rule.md, which exists as a real one-level-deep, clearly signaled reference. Content split is appropriate and navigation is easy.

5 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has strong, explicit trigger guidance and a well-defined security niche, but it is entirely 'when'-oriented — the skill's actual capability is left implicit, and common technical synonyms (JWT, localStorage, cookies) are missing. Adding a leading 'what' clause would round it out.

Suggestions

Lead with an explicit 'what' statement, e.g., 'Store session tokens and JWTs in httpOnly cookies with Secure and SameSite flags plus CSRF protection. Use when...' so completeness reaches both halves.

Add natural synonyms users would say — JWT, localStorage, sessionStorage, cookies, session tokens — to broaden trigger-term coverage.

Narrow 'reviewing authentication implementation' to token-storage-specific review to further reduce overlap with generic auth/security review skills.

DimensionReasoningScore

Specificity

Names the domain ('token storage approach', 'XSS-based token theft') and lists three specific actions — 'reviewing authentication implementation', 'setting up a new auth system', 'evaluating whether the current token storage approach exposes the application'. It falls short of 5 because the core remediation capability (e.g., moving tokens to httpOnly cookies) is never stated, leaving a gap in coverage.

4 / 5

Completeness

'When' is explicit and detailed ('Use when reviewing... setting up... evaluating...'), but the 'what' is only implied — the description never states what the skill does (secure token storage via httpOnly cookies, CSRF defenses). It is above anchor 2 because the 'when' clauses embed a specific evaluation activity, but below anchor 4, which requires an explicit 'what' statement alongside 'when'.

3 / 5

Trigger Term Quality

Natural terms like 'authentication implementation', 'new auth system', 'token storage', and 'XSS-based token theft' match what users would say. Not 5 because common synonyms users plausibly mention — JWT, localStorage, cookies, session tokens — are absent.

4 / 5

Distinctiveness Conflict Risk

The niche (token storage XSS exposure) has distinct triggers with minimal conflict risk. Not 5 because 'reviewing authentication implementation' is broad enough to overlap with generic auth-review or security-review skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.