CtrlK
BlogDocsLog inGet started
Tessl Logo

authentication

How auth works in agent-native apps. Use when wiring login/signup, configuring auth modes, setting up organizations, protecting routes, or debugging session issues.

60

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/authentication/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable reference: real code, exact env vars, endpoints, and unambiguous rules with almost no generic-filler content. Its weaknesses are verbosity in the SSO/org sections and the absence of any progressive disclosure — roughly 40+ lines of runbook detail live inline in SKILL.md that clearly belong in separate reference files.

Suggestions

Move the Cross-App SSO flow detail and the Packaged Desktop SSO subsection into a references/ file, keeping a short summary plus the existing link in SKILL.md — the body already cites a fuller doc, so the inline runbook duplicates that role.

Tighten the multi-clause run-on sentences (e.g. the Dispatch flow and federation bullets) into shorter statements or tables; several encode three or four rules per sentence.

Trim or relocate the incident narrative ("caused the 2026-04-29 credentials leak") to a brief rationale note so dated context does not sit in the main guidance path.

DimensionReasoningScore

Conciseness

Nearly all content is framework-specific knowledge Claude cannot already know (env vars, guard scripts, invariants), so there is little conceptual padding. But the prose is noticeably verbose — long run-on sentences in the Cross-App SSO bullets, repeated bolded emphasis, and a dated incident reference ("caused the 2026-04-29 credentials leak") outside any old-patterns section. Mostly efficient but could be tightened fits anchor 3, not 4 (the trimming needed exceeds "minor").

3 / 5

Actionability

Fully executable, copy-paste-ready guidance for the common cases: the defineAppRoles/authorize declaration, the getSession(event) + throw-401 custom-route handler, the /sign-in?return= redirect snippet, and AppProviders usage, plus exact env vars, endpoints, and named helpers. Matches the anchor-5 example of concrete code covering the common cases.

5 / 5

Workflow Clarity

Decision rules are unambiguous (custom route → getSession → 401; never sentinel fallback), the SSO canary rollout is an explicit ordered sequence with verification steps, and "Stop And Confirm" gives a real checkpoint with the failure symptom named. Not anchor 5: this is a multi-topic reference with no unified workflow, and several sections rely on mentioned guard scripts rather than inline validate-fix-retry loops. Clearly above anchor 3 (checkpoints are explicit, not missing or implicit).

4 / 5

Progressive Disclosure

Section structure is clear and links are well signaled one level deep ("/docs/cross-app-sso", "/docs/deployment#email-templates", Related Skills), but the bundle has no references/ or scripts/ files, and runbook-scale detail — the entire Desktop SSO subsection and the MCP OAuth spec prose — is inlined in SKILL.md even though a fuller external doc is cited at the end of the SSO section. That is the anchor-3 pattern of content that should be separate remaining inline; not 2 because structure and signaling are genuinely present.

3 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, third-person description with an explicit and concrete Use-when clause covering the core auth tasks. Its main limitation is that the "what" half is a topic statement rather than a capability list, and it omits several natural trigger terms (sign-in, SSO, OAuth) that match significant parts of the body.

Suggestions

Name the concrete capability in the what-clause (e.g. "Configures Better Auth login/signup, organizations, route protection, and session handling in agent-native apps") instead of the topic-style "How auth works in agent-native apps".

Add missing natural trigger terms such as "sign-in", "SSO", "OAuth", or "MCP auth" so users phrasing requests those ways still match the skill.

DimensionReasoningScore

Specificity

The trigger clause lists several concrete actions ("wiring login/signup, configuring auth modes, setting up organizations, protecting routes, or debugging session issues"), but the what ("How auth works in agent-native apps") is a topic statement rather than a capability list, and major body topics like MCP OAuth and SSO are uncovered. Matches anchor 4 (several specific actions, minor gaps in coverage), not 5 or 3.

4 / 5

Completeness

An explicit "Use when…" clause with concrete triggers answers "when" fully, and "How auth works in agent-native apps" answers "what", but only as a topic description rather than an explicit statement of what the skill does. Above anchor 3 (when is explicit, not weakly implied); below anchor 5 (the what is not equally concrete).

4 / 5

Trigger Term Quality

Natural developer phrases like "login/signup", "protecting routes", and "debugging session issues" are present. Missing common variations a user would say: "sign-in", "authentication", "SSO", "OAuth", "permissions". Good coverage with a few natural terms missing fits anchor 4 better than 3 (more than just "some relevant keywords").

4 / 5

Distinctiveness Conflict Risk

"agent-native apps" scopes a clear niche and the triggers are distinct, but route protection and session debugging border the sibling `security` and `actions` skills referenced in the body. Mostly distinct with minor overlap risk against closely related skills — anchor 4.

4 / 5

Total

16

/

20

Passed

Validation

68%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 11 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 2 suspicious

Warning

referenced_paths_exist

Referenced path issues: 2 missing

Warning

Total

11

/

16

Passed

Repository
BuilderIO/agent-native
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.