CtrlK
BlogDocsLog inGet started
Tessl Logo

permission-model-change-guide

修改 BK-CI IAM RBAC 权限模型时使用,例如新增资源类型、设计操作列表、配置 IAM 资源、补迁移数据和验证回调链路。当用户要变更权限模型而不是普通权限调用时优先使用。

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./ai/skills/permission-model-change-guide/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured routing overview that stays lean and points to themed reference docs, but it leans on reference files that are absent and lacks in-body executable detail and validation checkpoints for destructive model changes.

Suggestions

Add the missing reference files (reference/1-resource-action-design.md, 2-iam-config-migration.md, 3-callback-validation.md) or correct the path prefix (references/ vs reference/) so the signaled disclosures resolve.

Include an explicit validation/verification step in the workflow — e.g. a checklist confirming IAM config, migration script, and callback chain are all exercised before online rollout.

De-duplicate the reference listing (it appears in both 快速指导 and 延伸阅读) and add a few concrete in-body anchors (example IAM resource block, migration script name) to raise actionability.

DimensionReasoningScore

Conciseness

Lean overview that assumes Claude's competence and avoids explaining BK-CI/IAM basics, but the three reference files are listed twice (快速指导 step 3 and 延伸阅读) and 高信号规则/关键陷阱 overlap slightly.

4 / 5

Actionability

Gives a useful four-layer framework ('资源定义、操作定义、数据初始化、校验验证') and concrete doc routing, but lacks executable specifics (config snippets, script names, paths) and defers all detail to reference files that are not present.

3 / 5

Workflow Clarity

A rough sequence exists (identify problem type → route to doc → cover four layers → mind create action → handle i18n/migration), but there are no explicit validation checkpoints; since model changes are destructive/online ops, the missing validation caps this at 3.

3 / 5

Progressive Disclosure

Clear overview with well-signaled one-level-deep references split by theme, but the referenced files (reference/1|2|3-*.md) do not exist in the bundle and the listing is duplicated.

4 / 5

Total

14

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, and clearly distinguishes model-change work from ordinary permission calls. It concisely answers both what and when without padding.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — '新增资源类型、设计操作列表、配置 IAM 资源、补迁移数据和验证回调链路' — giving comprehensive coverage of what the skill does.

5 / 5

Completeness

Explicitly answers both what (the five enumerated model-change actions) and when ('当用户要变更权限模型而不是普通权限调用时优先使用'), with concrete trigger phrasing.

5 / 5

Trigger Term Quality

Uses natural domain terms a BK-CI IAM user would say ('权限模型', '资源类型', '操作列表', '迁移数据', '回调链路') with good coverage, though a few synonymous phrasings are absent.

4 / 5

Distinctiveness Conflict Risk

Carves a clear niche by contrasting '变更权限模型' against '普通权限调用', minimizing conflict with ordinary permission/Auth skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
TencentBlueKing/bk-ci
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.