CtrlK
BlogDocsLog inGet started
Tessl Logo

better-auth-best-practices

Better Auth server/client setup: `auth.ts`, generated schema, DB adapters, sessions, cookies, env vars, and plugins. Use when mentioning Better Auth, betterauth, auth handlers, OAuth, email/password, or session configuration.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, well-organized quick-reference that is lean and actionable, with concrete commands, real option names, and a verification step in the setup workflow. Its main weakness is the absence of any bundle structure — reference-grade material (options, hooks, plugins, client API) is inlined in a single file, and there is no complete auth.ts example or error-recovery guidance.

Suggestions

Split the reference-grade sections (Core Config Options, Hooks, Plugins, Client, Security) into a references/ file (e.g. references/options.md) and keep SKILL.md as a concise overview that links to it one level deep.

Add a complete, copy-paste-ready auth.ts example plus a minimal framework route handler so the setup workflow is fully executable end to end.

Extend the setup workflow with a feedback loop: what to check and fix when the migrate command or the GET /api/auth/ok verification fails (e.g. re-check env vars, CLI file location, and adapter model names).

DimensionReasoningScore

Conciseness

The body is dense tables and terse bullets with no concept padding ('`session.expiresIn` (default 7 days)', 'Re-run after adding/changing plugins'), assuming Claude's competence. Minor trimmable spots remain — the 'Reference Repositories' section duplicates the Resources section, and the 'Upstream Grounding' paragraph could be tightened.

4 / 5

Actionability

Concrete executable commands ('bun add better-auth', 'bun x @better-auth/cli@latest migrate', 'openssl rand -base64 32'), real option names in the config tables, and a verification endpoint are provided. Minor gaps: no complete `auth.ts` example and hook usage is described rather than shown with code.

4 / 5

Workflow Clarity

The six-step Setup Workflow is clearly sequenced with an explicit verification checkpoint ('Verify: call `GET /api/auth/ok` — should return `{ status: "ok" }`'). It lacks an error-recovery feedback loop for when migrate or the verification call fails, keeping it below the top anchor.

4 / 5

Progressive Disclosure

No bundle files exist; all ~190 lines of reference material (options tables, hooks, plugins, client methods) are inlined in SKILL.md. Sections are well-organized and external docs are linked, but content that would naturally live in separate reference files is inline — matching the 'some structure, content that should be separate is inline' anchor rather than the well-split anchor.

3 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description in third-person voice: it states a specific scope with an enumerated artifact list and an explicit 'Use when...' clause with concrete trigger terms including a casing synonym. Minor improvements possible by phrasing capabilities as actions and adding natural user phrasings like 'sign in' or 'log in'.

DimensionReasoningScore

Specificity

Names the domain ('Better Auth server/client setup') plus a concrete inventory of artifacts — '`auth.ts`, generated schema, DB adapters, sessions, cookies, env vars, and plugins' — giving several specific items with minor coverage gaps. It enumerates topics more than actions, so it sits below the comprehensive-concrete-actions anchor at 5.

4 / 5

Completeness

It explicitly answers both 'what' (server/client setup with an enumerated scope) and 'when' ('Use when mentioning Better Auth, betterauth, auth handlers, OAuth, email/password, or session configuration') with concrete trigger phrases — matching the top anchor. The 'when' clause is explicit, so it is not the anchor below, where 'when' would be only weakly implied.

5 / 5

Trigger Term Quality

'Use when mentioning Better Auth, betterauth, auth handlers, OAuth, email/password, or session configuration' gives good natural keyword coverage including a casing synonym ('betterauth'). A few natural user phrasings are missing ('sign in', 'log in', 'authentication setup'), keeping it below the comprehensive-synonyms anchor.

4 / 5

Distinctiveness Conflict Risk

'Better Auth' carves out a clear niche, but broad trigger terms like 'OAuth', 'email/password', and 'session configuration' create minor overlap risk with other authentication-related skills. Mostly distinct with minor overlap risk matches the anchor at 4.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
EpicenterHQ/epicenter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.