CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-implementation-patterns

Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.

78

1.19x
Quality

68%

Does it follow best practices?

Impact

100%

1.19x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./tests/ext_conformance/artifacts/agents-wshobson/developer-essentials/skills/auth-implementation-patterns/SKILL.md

The canonical home for this skill is auth-implementation-patterns in wshobson/agents

SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers concrete, largely executable TypeScript patterns across the full auth surface area, which is its main strength. However, it inlines everything that its own Resources section says lives in separate files — and none of those files exist — while also padding token budget with a Core Concepts primer on auth basics Claude already knows and omitting any validation guidance for implementing security-critical flows.

Suggestions

Create the referenced bundle files (references/jwt-best-practices.md, references/oauth2-flows.md, references/session-security.md, assets/auth-security-checklist.md, assets/password-policy-template.md, scripts/token-validator.ts) or remove the Resources section — currently every reference is broken.

Move the full pattern implementations into the reference files and keep SKILL.md as a concise overview with one short quick-start example, applying progressive disclosure instead of inlining ~600 lines.

Delete or compress the "Core Concepts" section (AuthN vs AuthZ basics, session/token/OAuth comparisons) — this is knowledge Claude already has — and add a brief validation step per pattern (e.g., how to verify token expiry and middleware behavior before shipping).

DimensionReasoningScore

Conciseness

The "Core Concepts" section re-explains basics Claude already knows ("Authentication (AuthN): Who are you?", "Server stores session state, Session ID in cookie") and the "When to Use" bullet list duplicates the frontmatter description, so while the code sections are dense, the body includes unnecessary padding — matching anchor 3 rather than 4.

3 / 5

Actionability

Near copy-paste TypeScript implementations for JWT signing/verification, refresh token rotation, Redis sessions, Passport OAuth2, and RBAC middleware, but they depend on undefined `db`, `app`, and `hash` abstractions, leaving the minor gaps of anchor 4 rather than fully self-contained anchor-5 code.

4 / 5

Workflow Clarity

The body is a catalog of independent patterns with no sequenced implementation workflow and no validation checkpoints (e.g., nothing like "test token expiry handling after wiring the middleware"), fitting anchor 3's "sequence present but checkpoints missing" despite coherent per-pattern structure.

3 / 5

Progressive Disclosure

All five-plus full implementations (~600 lines) are inlined in SKILL.md where the rubric expects them split into referenced files, and every listed resource (references/jwt-best-practices.md, references/oauth2-flows.md, references/session-security.md, assets/auth-security-checklist.md, assets/password-policy-template.md, scripts/token-validator.ts) does not exist on disk, matching anchor 2's "content that clearly belongs in separate files is inlined" with broken rather than merely buried references.

2 / 5

Total

12

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that explicitly covers both what the skill does and when to use it, with specific named technologies (JWT, OAuth2, sessions, RBAC) and natural trigger phrasing. Minor improvements are possible: add common user synonyms like "login" or "SSO" to the trigger clause and tighten "debugging security issues" to reduce overlap with general security skills.

DimensionReasoningScore

Specificity

Names several concrete capabilities ("JWT, OAuth2, session management, and RBAC") with a clear purpose ("build secure, scalable access control systems"), though the verbs "master" and "build" are mildly generic, leaving minor gaps versus anchor 5.

4 / 5

Completeness

The first sentence explicitly states what the skill does and the "Use when implementing auth systems, securing APIs, or debugging security issues" clause gives three concrete trigger scenarios, matching the anchor-5 example pattern; the 'when' is already explicit, so anchor 4 does not fit.

5 / 5

Trigger Term Quality

"implementing auth systems, securing APIs, or debugging security issues" plus JWT/OAuth2 terms give good natural keyword coverage, but common user phrasings like "login", "sign-in", "SSO", and "permissions" are missing, so it falls short of anchor 5's synonym-level coverage.

4 / 5

Distinctiveness Conflict Risk

The auth/authz niche is distinct with clear triggers, but "debugging security issues" is broad enough to overlap with general security or web-hardening skills, keeping it below anchor 5.

4 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (648 lines); consider splitting into references/ and linking

Warning

referenced_paths_exist

Referenced path issues: 6 missing

Warning

Total

14

/

16

Passed

Repository
Dicklesworthstone/pi_agent_rust
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.