CtrlK
BlogDocsLog inGet started
Tessl Logo

permission-model-change-guide

修改 BK-CI IAM RBAC 权限模型时使用,例如新增资源类型、设计操作列表、配置 IAM 资源、补迁移数据和验证回调链路。当用户要变更权限模型而不是普通权限调用时优先使用。

62

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./ai/skills/permission-model-change-guide/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-organized, token-efficient routing guide with accurate scope boundaries, but it functions only as an index: all actionable detail is delegated to three reference files that are not present in the bundle, and the workflow lacks explicit validation checkpoints despite covering migration and initialization operations. Its usefulness depends entirely on shipping the referenced files.

Suggestions

Ship the three referenced files (reference/1-resource-action-design.md, reference/2-iam-config-migration.md, reference/3-callback-validation.md) or fix their paths — currently every pointer in the body is dead, making the skill unusable as a guide.

Add explicit validation checkpoints and a fix-retry loop for the migration/initialization workflow (e.g., how to verify the callback chain and confirm migration data before and after a production change), since the four-layer checklist names validation but gives no way to perform it.

Remove the duplicated reference listing (延伸阅读 repeats the 快速指导 pointers) and fold the 不适用场景 exclusions into a single boundary statement to tighten the token budget.

DimensionReasoningScore

Conciseness

The body is lean with no filler explaining concepts Claude already knows, but the three reference paths are duplicated between the 快速指导 list and the 延伸阅读 section, and the 不适用场景 overlaps the description's exclusion clause — minor trimming possible, matching the 'efficient with minor instances' anchor.

4 / 5

Actionability

Concrete domain guidance exists ("先确认关联资源是否还是父级资源", "同步考虑国际化、初始化脚本、历史数据兼容和线上落地方式"), but there are no executable steps, commands, or file paths — the actual procedure is fully delegated to the reference documents, matching the 'some concrete guidance but incomplete' anchor.

3 / 5

Workflow Clarity

A rough sequence exists (classify the change, enter the matching reference doc, check create-action parent resources, then handle i18n/migration/deployment) and the four-layer checklist names validation, but there are no explicit validation checkpoints or feedback loops — and since this skill governs migration/data-initialization batch changes, the rubric's cap of 3 applies.

3 / 5

Progressive Disclosure

The design intent is good — a concise overview pointing to three clearly signaled, one-level-deep references — but the referenced paths (`reference/1-resource-action-design.md`, `reference/2-iam-config-migration.md`, `reference/3-callback-validation.md`) resolve to nothing: no reference directory or bundle files exist, so navigation fails entirely, placing this at the broken/minimal-structure level rather than anchor 3's 'references present but not clearly signaled'.

2 / 5

Total

12

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names a specific domain, enumerates five concrete actions, and includes an explicit use-when clause that also fences off the most likely wrong trigger (ordinary permission calls). The only gap is mild — a few natural synonym/variation trigger terms are missing.

DimensionReasoningScore

Specificity

The description lists five concrete actions ("新增资源类型、设计操作列表、配置 IAM 资源、补迁移数据和验证回调链路") that comprehensively cover permission-model changes, matching the top anchor rather than the 'minor gaps' level of 4.

5 / 5

Completeness

It explicitly answers both what (the five enumerated change activities) and when ("当用户要变更权限模型而不是普通权限调用时优先使用"), with concrete trigger phrasing matching the top anchor.

5 / 5

Trigger Term Quality

Good natural domain keywords ("权限模型", "资源类型", "迁移", "回调链路", "BK-CI IAM RBAC") that users would plausibly say, but common variations and synonyms (e.g., 权限模型变更/接入, resource-type additions) are not covered, falling short of the comprehensive-synonyms anchor of 5 while clearly above anchor 3.

4 / 5

Distinctiveness Conflict Risk

A clear niche (BK-CI IAM RBAC model changes) with an explicit exclusion of the nearest competing trigger ("而不是普通权限调用"), giving minimal conflict risk with other auth/permission skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
TencentBlueKing/bk-ci
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.