CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-module-architecture

处理 BK-CI Auth 模块时使用,例如 RBAC 权限校验、用户组与资源管理、IAM 集成、授权迁移和 OAuth2 认证。当用户要改权限平台实现而不是单次权限模型变更时优先使用。

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./ai/skills/auth-module-architecture/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-organized overview with clear applicable/non-applicable scoping and useful heuristics, but it offers only routing rather than executable instruction and its referenced detail files are missing from the bundle.

Suggestions

Add at least one concrete, runnable example (e.g. a permission-check call or group-membership query) so the guidance is executable rather than purely navigational.

Include a validation or verification checkpoint in 快速指导 (e.g. how to confirm a fix is an Auth-platform issue vs a business-side parameter issue) to strengthen the workflow.

Provide the referenced reference/*.md files in the bundle, or remove the broken links and inline the essential detail, so navigation resolves.

DimensionReasoningScore

Conciseness

Mostly lean and efficient with well-scoped sections that assume the reader's competence; the reference list is duplicated between 快速指导 and 延伸阅读, a minor redundancy that could be trimmed.

4 / 5

Actionability

Provides concrete decision and routing guidance (按问题类型进入对应参考文档, judgment of Auth vs business-side issues), but as an instruction-only skill it stops short of executable, copy-paste-ready commands or code patterns.

3 / 5

Workflow Clarity

A numbered 快速指导 sequence with routing logic exists, but there are no validation checkpoints or feedback loops for verifying the diagnosis; this is not a destructive/batch workflow so the hard cap does not apply.

3 / 5

Progressive Disclosure

Structure is well-organized with one-level references to reference/1-auth-foundation.md et al., but those referenced files are not present in the bundle, so the navigation points to nonexistent material.

3 / 5

Total

13

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that states concrete capabilities and an explicit use-when trigger with built-in disambiguation. It is slightly below a perfect score only on specificity, trigger synonym breadth, and residual overlap with sibling permission skills.

DimensionReasoningScore

Specificity

Names the domain and several concrete capabilities — 'RBAC 权限校验、用户组与资源管理、IAM 集成、授权迁移和 OAuth2 认证' — covering multiple distinct actions, though not exhaustively comprehensive.

4 / 5

Completeness

Clearly answers both 'what' (the enumerated Auth capabilities) and 'when' with an explicit trigger clause: '当用户要改权限平台实现而不是单次权限模型变更时优先使用'.

5 / 5

Trigger Term Quality

Includes natural terms a user would say (权限校验, 用户组, IAM, OAuth2, 权限平台) with good coverage; a few common variations like 资源授权 are present but synonym coverage is not fully comprehensive.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (Auth platform implementation) with explicit disambiguation against single permission-model changes, minimizing overlap risk; minor residual overlap with adjacent permission skills.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
TencentBlueKing/bk-ci
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.