CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-module-architecture

处理 BK-CI Auth 模块时使用,例如 RBAC 权限校验、用户组与资源管理、IAM 集成、授权迁移和 OAuth2 认证。当用户要改权限平台实现而不是单次权限模型变更时优先使用。

64

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./ai/skills/auth-module-architecture/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-organized, concise router skill with sensible in/out-of-scope sections, a clear decision sequence, and genuinely useful high-signal rules and pitfalls. Its main weaknesses are executable-guidance gaps — a diagnostic step with no criteria and reference paths that do not resolve in the provided bundle — plus a small duplication of the reference list.

Suggestions

Add concrete criteria or a quick check for the instruction "先判断是 Auth 平台问题还是业务侧传参问题" (e.g., what evidence in logs/responses indicates each case), so the routing decision is executable rather than judgment-only.

Ship the referenced files (`reference/1-auth-foundation.md`, `reference/2-rbac-group-authorization.md`, `reference/3-iam-oauth-debug.md`) in the bundle or fix the paths so the skill's routing targets actually resolve; currently no reference files are present.

Remove the duplicated reference listing in "延伸阅读" (it repeats the three paths already given in "快速指导") or make it add new information, tightening token usage.

DimensionReasoningScore

Conciseness

The ~50-line body is lean and assumes Claude's competence — e.g., "IAM 集成和本地 RBAC 数据是一条完整权限链,不应分开孤立看" adds non-obvious guidance without padding. The one trimmable redundancy is that the three reference paths are listed verbatim twice ("快速指导" item 3 and again in "延伸阅读"), matching anchor 4 ('efficient; minor instances that could be trimmed') rather than the every-token-earns-its-place anchor 5.

4 / 5

Actionability

The problem-type-to-document routing map ("模块结构与核心对象:`reference/1-auth-foundation.md`" etc.) is concrete, but the key diagnostic instruction "先判断是 Auth 平台问题还是业务侧传参问题" gives no criteria for making that judgment, and the routing targets (`reference/*.md`) do not exist in the provided bundle — no `reference/` or `references/` directory is present — so the primary action cannot actually be executed here. This matches anchor 3 ('some concrete guidance but incomplete; missing key details') rather than anchor 4.

3 / 5

Workflow Clarity

"快速指导" lays out a clear numbered decision sequence — classify the problem type, route to the matching reference, switch to `permission-model-change-guide` when designing new resource types, then classify platform-vs-caller failures — which is coherent for a routing skill with no destructive operations. It stops short of anchor 5 because the classification steps lack explicit checkpoints/criteria (e.g., how to tell an Auth platform issue from a business-side parameter issue).

4 / 5

Progressive Disclosure

The written structure is good — a concise overview with clearly labeled, one-level-deep references ("RBAC、用户组与授权链路:`reference/2-rbac-group-authorization.md`") — but those referenced files are not present in the bundle being evaluated (no `reference/`, `references/`, `scripts/`, or `assets/` directories exist), so the navigation the skill depends on cannot be verified to resolve. Per the guideline to score against the actual bundle structure, this drops it to anchor 3; with the referenced files present it would merit 5.

3 / 5

Total

14

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it names a clear niche (BK-CI Auth module), lists concrete capability areas, provides an explicit use-when clause with trigger terms, and even disambiguates against a neighboring permission-model skill. Minor room to improve lies in adding a few more natural synonym/variation trigger terms.

DimensionReasoningScore

Specificity

The description enumerates five concrete capability areas — "RBAC 权限校验、用户组与资源管理、IAM 集成、授权迁移和 OAuth2 认证" — under the umbrella verb "处理" (handle), which is specific but more a list of domains than distinct executable actions, matching anchor 4 ('lists several specific actions; minor gaps') rather than the fully action-verb-driven anchor 5.

4 / 5

Completeness

It explicitly answers both questions: what it covers ("RBAC 权限校验、用户组与资源管理、IAM 集成、授权迁移和 OAuth2 认证") and when to use it ("处理 BK-CI Auth 模块时使用" plus "当用户要改权限平台实现而不是单次权限模型变更时优先使用" — a concrete, discriminating trigger phrase), matching anchor 5. It is not anchor 4 because the 'when' is not merely present but explicitly disambiguated against a sibling skill.

5 / 5

Trigger Term Quality

Strong natural keywords a BK-CI contributor would actually say — "RBAC 权限校验", "用户组", "IAM 集成", "OAuth2", "授权迁移", "权限平台" — giving good coverage; a few common variations (e.g., 权限排查/debugging phrases, login/authentication wording, English equivalents) are missing, so it fits anchor 4 rather than the comprehensive synonym coverage of anchor 5.

4 / 5

Distinctiveness Conflict Risk

It is tightly scoped to the "BK-CI Auth 模块" niche and actively reduces conflict risk by stating "当用户要改权限平台实现而不是单次权限模型变更时优先使用" — explicitly separating itself from a single permission-model change — matching anchor 5 (clear niche with distinct triggers, minimal conflict risk).

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
TencentBlueKing/bk-ci
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.