CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-nodejs-cloudbase

CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets. This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an existing user system into CloudBase; not when configuring providers or building client login UI.

67

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is auth-nodejs-cloudbase in TencentCloudBase/CloudBase-AI-Toolkit

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body: every scenario ships executable Node SDK code with exact method names, parameter shapes, and real-world constraints, and the routing to sibling skills is explicit and one level deep. Its main cost is redundancy — three sections restate the same use/don't-use boundary, and the summary adds a fourth pass — which inflates token spend without adding guidance value.

Suggestions

Collapse the 'Activation Contract' and 'When to use this skill' sections into one, and trim the 'Summary' to a short pointer list — the use/don't-use boundary is currently stated three to four times.

State the SDK initialization pattern once and omit the repeated tcb.init/app.auth() boilerplate from later scenarios, referencing Scenario 1 instead, to cut roughly 60 lines with no loss of actionability.

Move the 'Node Auth APIs covered by this skill' signature listing into a small reference file (or fold it into the scenario headers) so the SKILL.md body is pure scenarios and routing.

DimensionReasoningScore

Conciseness

The nine scenario code blocks are lean and copy-pasteable, but the body spends three separate sections restating the same scope guidance — "Activation Contract" ("Do NOT use for: Frontend login / sign-up UI"), "When to use this skill" ("Do NOT use this skill for: Frontend Web login / sign-up flows"), and "Summary" — plus a "Sibling skills" preamble, which is noticeable redundancy that could be collapsed. It is above anchor 2 because the padding is meta-routing text rather than explanations of concepts Claude already knows, and the API/scenario content itself is efficient.

3 / 5

Actionability

The body provides fully executable, copy-paste-ready TypeScript for every scenario (e.g. "const { openId, appId, uid, customUserId } = auth.getUserInfo();", "await auth.queryUserInfo({ platform: "PHONE", platformId: "+86 13800000000" })", "auth.createTicket(customUserId, { refresh: 3600 * 1000, expire: 24 * 3600 * 1000 })"), plus exact constraints for customUserId ("Length 4–32 characters", allowed character set). Specific examples cover the common cases and the API-signature section enumerates every supported method.

5 / 5

Workflow Clarity

"How to use this skill (for a coding agent)" gives a clear five-step sequence (clarify runtime → confirm env/SDK → pick scenario → follow API shapes → handle uncertainty), and error handling is addressed via per-scenario try/catch and a best-practices "Error handling" block. Not 5 because there are no explicit validation checkpoints in the workflow itself — verification appears as scattered advice (e.g. "treat it as suspect and avoid using it") rather than a validate-then-proceed step; the destructive/batch cap does not apply since the operations are read/issue flows.

4 / 5

Progressive Disclosure

No bundle files exist (no references/, scripts/, or assets/), so all content is inline in a single 445-line file, but it is well organized with clear headers (Activation Contract, APIs covered, Scenarios 1–9, Custom login tickets, Best practices, Summary) and clearly signaled one-level-deep sibling references ("../auth-tool-cloudbase/SKILL.md", "../auth-web-cloudbase/SKILL.md", "../http-api-cloudbase/SKILL.md"). Not 5 because some inlined bulk — the repeated tcb.init boilerplate in every scenario and the API-signature listing — is material that could live in a separate reference file, which the score-4 anchor's 'minor organization gaps' reflects.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that explicitly covers what the skill does, when to use it, and when not to, with concrete capability areas and an explicit exclusion boundary against sibling skills. The only weakness is that it stops at capability-area terms and omits a few high-value natural triggers such as the npm package name or 'cloud functions'.

DimensionReasoningScore

Specificity

The description names several concrete capability areas — "server-side identity, user lookup, and custom login tickets" and "read caller identity, inspect end users, or bridge an existing user system into CloudBase" — which matches the 'lists several specific actions; minor gaps in coverage' anchor. It falls short of 5 because the actions are stated at the capability-area level ("user lookup", "inspect end users") rather than as fully concrete operations, and the opening "auth guide" phrasing is slightly generic.

4 / 5

Completeness

It explicitly answers both questions: what it does ("CloudBase Node SDK auth guide for server-side identity, user lookup, and custom login tickets") and when to use it ("This skill should be used when Node.js code must read caller identity, inspect end users, or bridge an existing user system into CloudBase"), plus explicit negative triggers ("not when configuring providers or building client login UI"). This matches the score-5 anchor with concrete trigger phrases in both directions.

5 / 5

Trigger Term Quality

Natural trigger terms are present: "Node.js", "CloudBase", "server-side identity", "user lookup", "custom login tickets" — terms a user would plausibly say. Not 5 because common variations users would actually type are missing, e.g. the package name "@cloudbase/node-sdk", "cloud functions", or phrasing like "who is calling".

4 / 5

Distinctiveness Conflict Risk

The niche is clear (Node.js server-side auth in CloudBase) and the exclusion clause "not when configuring providers or building client login UI" explicitly steers away from the neighboring provider-setup and web-UI skills, giving a clear niche with distinct triggers and minimal conflict risk.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
TencentCloudBase/CloudBase-AI-Toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.