CtrlK
BlogDocsLog inGet started
Tessl Logo

x-frame-options

Use when reviewing HTTP response headers for clickjacking protection on any web application with authenticated user actions.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/x-frame-options/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-structured review skill: clear check/fix/explain workflow, concrete header-value guidance, and correct use of a one-level-deep reference for implementation details. The main weakness is mild redundancy — the clickjacking attack scenario is explained twice.

Suggestions

Drop one of the two clickjacking explanations — keep either the banking-login narrative in the intro or the Quick Reference bullet, not both.

Add a one-line concrete verification command to the Check section, e.g. `curl -sI https://example.com | grep -i x-frame-options`.

DimensionReasoningScore

Conciseness

The body is compact, but the opening banking-login attack narrative explains clickjacking — a concept Claude already knows — and is then restated by the Quick Reference bullet "Clickjacking attacks trick users into clicking invisible iframe buttons — DENY eliminates this entirely". One of the two passages could be cut.

3 / 5

Actionability

Concrete, executable guidance with exact header values and decision rules: "Use X-Frame-Options: DENY... or SAMEORIGIN", "ALLOWFROM is obsolete... use CSP frame-ancestors instead". Minor gap: the Check section never says how to inspect responses (e.g., curl -I or browser devtools).

4 / 5

Workflow Clarity

A simple, single-purpose skill with an unambiguous Check → Fix → Explain → Code Review sequence, and the Code Review section includes an explicit validation checkpoint ("verify them against the effective production-like response").

5 / 5

Progressive Disclosure

The body is a lean overview and the single reference (references/rule.md, which exists) is clearly signaled, one level deep, holding the implementation details — matching the simple-skill ideal structure.

5 / 5

Total

17

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has a clear, explicit trigger clause and a well-scoped niche, but it describes only one generic action and omits the concrete capabilities and natural keywords (X-Frame-Options, frame-ancestors, security headers) that would make it comprehensive and more discoverable.

Suggestions

Name the concrete capabilities, e.g. "Checks responses for X-Frame-Options or CSP frame-ancestors, recommends the correct value (DENY, SAMEORIGIN, frame-ancestors), and explains clickjacking risk".

Add natural trigger keywords users would actually say, such as "X-Frame-Options", "frame-ancestors", "security headers", or "framing protection".

DimensionReasoningScore

Specificity

"reviewing HTTP response headers for clickjacking protection" names the domain and one concrete action, but lists only a single capability without covering what the skill actually does (checking, setting, or explaining X-Frame-Options / CSP frame-ancestors).

3 / 5

Completeness

An explicit "Use when reviewing..." clause answers "when" clearly, and "reviewing HTTP response headers for clickjacking protection" answers "what" at a general level. Not a 5 because the "what" never names concrete capabilities such as checking or setting X-Frame-Options or CSP frame-ancestors.

4 / 5

Trigger Term Quality

Relevant keywords like "HTTP response headers", "clickjacking protection", and "web application" are present, but natural terms users would say — X-Frame-Options, frame-ancestors, security headers, framing — are missing.

3 / 5

Distinctiveness Conflict Risk

The clickjacking/framing-protection niche is narrow with distinct triggers, carrying only minor overlap risk with broader security-header or general web-security review skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.