CtrlK
BlogDocsLog inGet started
Tessl Logo

auth

Epicenter auth packages: `@epicenter/auth` and the Svelte adapter at `@epicenter/auth/svelte`, OAuth sessions, identity state, auth-owned fetch/WebSocket, and the reload gate that makes a page lifetime one auth generation. Use when editing Epicenter auth clients, session state, hosted sign-in, or how a route boots from auth.

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/auth/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly project-specific architecture reference with strong actionable detail (code contracts, file paths, error-handling tables, pitfalls) but weak progressive disclosure: it is a single ~615-line monolith with no references/ files, and it repeats several invariants, including one internal contradiction about the cookie client's WebSocket capability. Splitting contract/type listings into references and deduplicating repeated rules would lift both conciseness and organization.

Suggestions

Move the full type and contract listings (AuthClient, Connection, AuthState, PersistedAuth/OAuthTokenGrant, PersistedAuthStorage, the Better Auth plugin config) into references/ files (e.g. references/contracts.md), keeping one-line summaries in SKILL.md and well-signaled links.

Deduplicate repeated invariants: the connection.status liveness rule appears in 'Current Model', 'Public Surface' (twice), and 'Common Pitfalls'; state each rule once in its owning section and reference it elsewhere.

Resolve the internal contradiction about createSameOriginCookieAuth: one section says it 'has openWebSocket like every client and denies permanently' while the Server Routes section says it is 'a plain AuthClient (no openWebSocket)' — pick one description of the contract.

DimensionReasoningScore

Conciseness

The body is dense and almost entirely project-specific (ADRs, invariants, close-code contracts) so it is not padded with things Claude already knows, but key facts are repeated: the connection.status live-machine rule appears three times, the reload-gate rules twice, and the network-gate fail-closed invariant is restated across sections. This is 'mostly efficient but could be tightened' — not the anchor-2 pattern of unnecessary generic explanation, but clearly above it.

3 / 5

Actionability

Concrete, copy-shaped guidance throughout: factory signatures (createOAuthAppAuth({ baseURL, clientId, launcher, persistedAuthStorage })), real file paths (bearer-fetch.ts, require-auth.ts, reload-on-auth-change.ts), full type contracts, an explicit 401-vs-503 error-action table, and a 15-item do/don't pitfalls list. A few blocks are illustrative only (the Hono composition txt diagram), and one contradiction — the cookie client is described as having openWebSocket 'like every client and denies permanently' in one section and as 'a plain AuthClient (no openWebSocket)' in another — keeps it below fully-executable anchor 5.

4 / 5

Workflow Clarity

This is an architecture/reference skill rather than a stepwise procedure, but its state machines are laid out with explicit failure branches and checkpoints: the network-gate decision table (unverified -> /api/session -> verified/pause/fail-closed), the sign-in launcher outcomes ('launched' vs 'completed'), and the WS close-code / HTTP status classification with the client action for each. Not quite the anchor-5 pattern of validate-fix-retry feedback loops, and no destructive/batch operations requiring validation caps.

4 / 5

Progressive Disclosure

Section headers are well organized (Upstream Grounding, Current Model, Public Surface, Persisted Cell, Network Gate, Transport, Boot selection, Pitfalls), but there are no bundle files at all: everything, including full type/contract listings (AuthClient, PersistedAuth, PersistedAuthStorage) and the complete Better Auth plugin config, is inlined in a ~615-line SKILL.md. Content that clearly belongs in references/ files is inline, which is the anchor-3 pattern ('some structure but could be better organized; content that should be separate is inline').

3 / 5

Total

14

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states a concrete, package-scoped what and an explicit Use-when clause with four specific triggers, in third person and without fluff. Its only gaps are a few natural synonyms (login, token) and a capability-inventory phrasing rather than action verbs.

DimensionReasoningScore

Specificity

The description names the domain and several concrete capability areas with exact package paths ('@epicenter/auth and the Svelte adapter at @epicenter/auth/svelte, OAuth sessions, identity state, auth-owned fetch/WebSocket, and the reload gate'), listing several specific capabilities with only minor gaps. It stops short of the anchor-5 pattern of multiple concrete action verbs, reading more as a scoped capability inventory than an action list, but it is well above the anchor-3 '1-2 concrete actions' level.

4 / 5

Completeness

It clearly and explicitly answers both what ('Epicenter auth packages: @epicenter/auth and the Svelte adapter at @epicenter/auth/svelte, OAuth sessions, identity state, auth-owned fetch/WebSocket, and the reload gate...') and when ('Use when editing Epicenter auth clients, session state, hosted sign-in, or how a route boots from auth') with four concrete trigger phrases.

5 / 5

Trigger Term Quality

Good natural keyword coverage: 'auth clients', 'session state', 'hosted sign-in', 'route boots from auth', 'OAuth', 'fetch/WebSocket', 'Svelte' — terms a user would plausibly say. A few common synonyms are missing (e.g. 'login', 'log out', 'token'), which keeps it below the comprehensive anchor 5.

4 / 5

Distinctiveness Conflict Risk

A clear niche scoped to the Epicenter codebase with distinct, package-level triggers ('Epicenter auth clients', '@epicenter/auth/svelte'), making wrong-skill triggering very unlikely; only trivial adjacency to a sibling better-auth skill.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (615 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
EpicenterHQ/epicenter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.