CtrlK
BlogDocsLog inGet started
Tessl Logo

paddle-customer-portal

Mint a Paddle customer portal session URL from a Next.js Server Action — the portal-vs-custom-billing-screen trade-off, auth, ownership, URL structure (overview vs deep links), and the security model.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./providers/cursor/plugin/skills/customer-portal/SKILL.md

The canonical home for this skill is paddle-customer-portal in PaddleHQ/paddle-agent-skills

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a strong, code-first skill: a fully executable Server Action with a security model explained inline where it changes the code, plus an unusually thorough verification checklist. Weaknesses are minor — some trimmable decision-guidance prose and unlinked sibling-skill references. It compares well against the exemplar content examples.

DimensionReasoningScore

Conciseness

The code and security sections are lean and every step's comment earns its place (e.g. the no-customer 400 explanation), but the "Should you use the portal at all?" section carries essay-like prose ("The choice isn't permanent. A common evolution...") that could be trimmed — minor instances of over-explanation rather than the fully lean anchor 5.

4 / 5

Actionability

The full Server Action is copy-paste ready with real imports, exact SDK call signature ("paddle.customerPortalSessions.create(customerId, subscriptionIds)"), the returned URL structure, env vars, and a complete client component — concrete and executable throughout, covering the common cases including the no-subscription and no-customer branches.

5 / 5

Workflow Clarity

The action's steps are numbered 1–5 in code with rationale at each point, and the "Verify the integration" section provides six explicit validation checkpoints with expected results, including error paths (logged out, no customer record, URL uniqueness per click). Not a destructive or batch operation, so no cap applies.

5 / 5

Progressive Disclosure

No bundle files exist, and the single file is well-sectioned with clear headers and one-level-deep external links; minor gaps are the bare-name sibling skill references ("subscription-sync", "subscription-cancel", "subscription-update") that are not linked, and the portal-vs-custom trade-off discussion inlined where a reference file could carry it.

4 / 5

Total

18

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description states a clear, distinctive capability in a well-demarcated niche, but it reads as a topic inventory rather than a trigger-optimized description: it lacks any explicit "Use when..." guidance and omits the natural user phrases (manage subscription, invoices, payment methods) that would make it discoverable. It is clearly better than vague one-liners but well below the exemplar descriptions.

Suggestions

Add an explicit trigger clause, e.g. "Use when the user wants to let customers manage their own subscription — manage subscription button, view invoices, update payment methods, cancel — via Paddle's hosted portal rather than building a custom billing screen."

Replace topic labels ("auth, ownership, URL structure ... and the security model") with concrete actions users would recognize, such as "authenticates the user, resolves their Paddle customer ID, and returns a one-time portal URL to redirect to."

Include the natural trigger terms users would say — "manage subscription", "billing portal", "view invoices", "update payment method" — so the skill matches how the request is actually phrased.

DimensionReasoningScore

Specificity

"Mint a Paddle customer portal session URL from a Next.js Server Action" names the domain and one concrete action, but the remainder ("auth, ownership, URL structure (overview vs deep links), and the security model") are topic labels rather than specific actions, so coverage is not comprehensive as anchor 4 requires.

3 / 5

Completeness

The "what" is clear (mint a portal session URL from a Server Action), but there is no "Use when..." clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric guidelines; the portal-vs-custom mention only weakly implies the "when".

3 / 5

Trigger Term Quality

Relevant domain keywords like "Paddle customer portal", "session URL", and "Next.js Server Action" are present, but the natural phrases a user would actually say ("manage subscription", "view invoices", "update payment method", "cancel subscription") are missing — anchor 3 rather than 4's good keyword coverage.

3 / 5

Distinctiveness Conflict Risk

"Paddle customer portal", "Next.js Server Action", and the explicit "portal-vs-custom-billing-screen trade-off" framing carve a clear niche with distinct triggers and minimal conflict risk, explicitly distinguishing it from sibling custom-billing skills.

5 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
PaddleHQ/paddle-agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.