CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/session-management-test-author

Build-an-X for session management tests per OWASP ASVS V3 - cookie attribute coverage (Secure / HttpOnly / SameSite=Strict|Lax), session-fixation defense (regenerate session ID on login), absolute + idle timeout, concurrent-session limits, logout invalidation across devices, CSRF token handling, session-binding to TLS / IP / device fingerprint. Use when authoring tests for any web app's session layer, regardless of framework (Express session, Django sessions, Spring Security, ASP.NET, Rails, etc.).

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured build-an-X skill: sequenced steps with executable test patterns, explicit failure-severity feedback, an end-to-end checklist, and clean one-level-deep offloading of extended patterns to a verified reference file. Weakest points are minor: dependency on undefined test helpers and brief re-explanations of timeout/session-fixation basics.

Suggestions

Define or show the assumed test helpers once (parse_cookie, client.login, the freezer fixture and timedelta/requests imports) so the code patterns are copy-paste runnable rather than requiring the reader to reconstruct the harness.

Trim the Step 2 session-fixation primer and the absolute/idle timeout definitions to one line each — Claude already knows these concepts; keep only the app-specific policy values.

Complete the truncated "limited_concurrent" branch in references/session-test-patterns.md (currently ends in "...") or state explicitly that the assertion depends on the documented app policy.

DimensionReasoningScore

Conciseness

Mostly lean — attribute tables, code-first steps, terse rationale — with minor over-explanation of concepts Claude already knows ("Absolute timeout: maximum session lifetime regardless of activity (e.g., 8 hours)" / "Idle timeout: session expires after N minutes of inactivity", and the 3-line session-fixation primer in Step 2). Not 5: those definitions and the repeated Step 8 checklist mapping could be trimmed slightly; not 3: padding is incidental, not a pattern.

4 / 5

Actionability

Mostly executable pytest-style code with concrete assertions (e.g., "assert sid_after != sid_before", the Set-Cookie attribute checks, freezer-based timeout ticks), plus verified code in references/session-test-patterns.md. Not 5: patterns depend on undefined helpers ("parse_cookie", "client.login", "freezer" fixtures) without showing their setup, imports of "timedelta"/"requests" are omitted, and the reference file's concurrent-session pattern ends in "...".

4 / 5

Workflow Clarity

Eight clearly numbered, sequenced steps with an end-to-end checklist (Step 8) mapping each requirement to its step, and explicit failure-interpretation feedback ("If the test fails (session ID unchanged), mark critical: session-fixation vulnerability"; the logout-replay critical marker in Step 5). Matches the 5 anchor's sequence + checkpoints + checklist; no destructive/batch operation applies to cap it.

5 / 5

Progressive Disclosure

SKILL.md is a well-signaled overview holding core patterns, with extended patterns (concurrent sessions, logout-all-devices, session binding, anti-patterns) split one level deep into references/session-test-patterns.md, which exists and delivers the promised content. Navigation is easy and consistent; no nested or buried references.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: comprehensive, mechanism-level capability list paired with an explicit framework-agnostic "Use when" trigger clause. The only weaknesses are a jargon-forward opening ("Build-an-X ... per OWASP ASVS V3") and a few missing natural synonyms such as "session hijacking" or "session expiry".

DimensionReasoningScore

Specificity

The description enumerates multiple concrete capabilities with their mechanisms — "cookie attribute coverage (Secure / HttpOnly / SameSite=Strict|Lax)", "session-fixation defense (regenerate session ID on login)", "absolute + idle timeout", "concurrent-session limits", "logout invalidation across devices", "CSRF token handling", "session-binding to TLS / IP / device fingerprint" — matching the comprehensive-coverage anchor. Not 4: there are no minor gaps; every action names a specific test target.

5 / 5

Completeness

Explicitly answers both: "what" is the enumerated list of session-management test capabilities, and "when" via "Use when authoring tests for any web app's session layer, regardless of framework (...)" with concrete trigger phrasing. Matches the 5 anchor exactly.

5 / 5

Trigger Term Quality

Good natural-term coverage: "session", "cookie", "login", "logout", "CSRF", "timeout", plus framework names users actually mention ("Express session, Django sessions, Spring Security, ASP.NET, Rails"). Not 5: it opens with meta-jargon ("Build-an-X for session management tests per OWASP ASVS V3") and misses natural synonyms such as "session hijacking", "session expiry", or "auth"; not 3: coverage goes well beyond "some relevant keywords".

4 / 5

Distinctiveness Conflict Risk

Clear niche — session-layer test authoring only — with distinct triggers (framework names, session/cookie/CSRF terms) and minimal overlap with adjacent authn skills, which the skill itself separates out (JWT/IdP scopes are explicitly excluded in the body). Not 4: no meaningful overlap with closely related skills is evident from the description.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents