CtrlK
BlogDocsLog inGet started
Tessl Logo

better-auth-security-best-practices

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. Use when reviewing auth security, brute-force protection, token handling, or deployment safety.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is efficient and grounded: it separates upstream defaults (delegated to a real, well-scoped reference file) from repository-made decisions, and states those decisions as explicit, executable rules. Weaknesses are modest: an undefined-helper code snippet, trimmable framing prose, and inline version-specific details that belong in the reference.

Suggestions

Define or inline the helpers used by buildTrustedOrigins (isLocalDeployment, productionOrigins, devOrigins) so the snippet is copy-paste ready, or label it explicitly as illustrative.

Move the version-specific linking-gate details (the 1.5.6 pseudo-block and the pre-requireLocalEmailVerified history) into references/configuration.md under a clearly signaled section, keeping only the durable rules in SKILL.md.

Trim the rhetorical framing sentence about 'account-takeover or open-redirect surface rather than a misconfiguration' to one clause, keeping the motivating why without the padding.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence, but the framing sentence "getting either wrong is an account-takeover or open-redirect surface rather than a misconfiguration" is trimmable rhetoric, and bare version numbers ("better-auth 1.5.6") are time-sensitive details not placed in an old-patterns section. Fits anchor 4: efficient with minor over-explanation.

4 / 5

Actionability

Concrete decision rules ("never add github to trustedProviders", "Never list email-password in trustedProviders") and real TS/code blocks are present, but buildTrustedOrigins calls undefined helpers (isLocalDeployment, productionOrigins, devOrigins) and the linking gate is a txt pseudo-block, so it is mostly rather than fully executable. Anchor 4, not 3, because the surrounding guidance is directly actionable.

4 / 5

Workflow Clarity

A clear grounding sequence is given ("ask DeepWiki a narrow question ... then verify decisive details against local installed types, source, or official docs" before "Read references/configuration.md"), but the audit workflow itself has no validation checkpoints. Anchor 4: clear sequence with most checkpoints, minor validation gaps.

4 / 5

Progressive Disclosure

"Read [references/configuration.md](references/configuration.md) when configuring or auditing an option" is a well-signaled, one-level-deep reference whose stated scope matches the actual file, but version-specific gate details (the 1.5.6 linking logic) are inlined in SKILL.md rather than delegated to the reference. Anchor 4: good structure with minor organization gaps.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names the specific framework and domain, enumerates concrete capability areas, and closes with an explicit 'Use when' clause covering natural trigger phrases. The only weakness is modest synonym coverage in its trigger terms.

DimensionReasoningScore

Specificity

"Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging" lists multiple specific capabilities with comprehensive coverage of the domain, matching the anchor-5 example's breadth.

5 / 5

Completeness

"Better Auth security hardening: rate limits, secrets, ..." explicitly states what the skill does and "Use when reviewing auth security, brute-force protection, token handling, or deployment safety" explicitly states when to use it with concrete trigger phrases, matching the anchor-5 example exactly.

5 / 5

Trigger Term Quality

"reviewing auth security, brute-force protection, token handling, or deployment safety" gives good natural keyword coverage, but common variations users would say (e.g. sign-in, login attempts, session hijacking) are missing, which fits anchor 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

The description claims a clear niche (Better Auth security hardening) with distinct triggers specific to auth review and deployment safety, so conflict with other skills is minimal.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
EpicenterHQ/epicenter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.