CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-tool-cloudbase

CloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow.

62

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./config/.claude/skills/auth-tool-cloudbase/SKILL.md

The canonical home for this skill is auth-tool-cloudbase in TencentCloudBase/CloudBase-AI-Toolkit

SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured overview that points to a real extended guide and gives concrete MCP-tool guidance, but it leans on external files for validation and references a checklist.md that is not in the bundle, weakening workflow clarity and progressive disclosure.

Suggestions

Add the missing checklist.md to the bundle or remove the reference on line 52, since it is cited as a required pre-implementation read but is not packaged.

Inline a brief validation checkpoint (e.g. 'verify provider status with queryAppAuth after manageAppAuth before writing client code') instead of delegating all validation to the external change-safety-protocol.md, to satisfy the destructive-operation workflow bar.

Tighten the 'Minimal checklist' paragraph into bullets and de-duplicate the 'Do NOT use this as' and 'Common mistakes/gotchas' sections, which overlap on provider-vs-implementation concerns.

DimensionReasoningScore

Conciseness

Mostly lean bullet-structured content that assumes Claude's competence, but the dense run-on 'Minimal checklist' paragraph and overlap between 'Do NOT use this as' and 'Common mistakes/gotchas' could be tightened.

3 / 5

Actionability

Gives concrete, executable guidance — specific MCP tool names (queryAppAuth, manageAppAuth, callCloudApi), a preferred execution order, and a concrete API call (await auth.signInAnonymously()) — with only minor gaps from dangling file references.

4 / 5

Workflow Clarity

A clear numbered execution order exists, but provider enable/disable is a configuration change and validation checkpoints are delegated to an external protocol file rather than inlined, so the destructive-operation cap of 3 applies.

3 / 5

Progressive Disclosure

Good overview structure with a clearly signaled one-level-deep reference to the bundled references/extended-guide.md; the dangling checklist.md reference (listed but not present in the bundle) is a minor organization gap.

4 / 5

Total

14

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-scoped description that clearly states capability and trigger conditions in third person with concrete actions. The only gaps are a few missing natural synonyms and provider names that would push trigger coverage and distinctiveness to a perfect score.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup' — giving comprehensive coverage of the provider-side configuration domain.

5 / 5

Completeness

Explicitly answers both 'what' (CloudBase auth provider configuration and login-readiness guide) and 'when' via the explicit 'This skill should be used when users need to...' trigger clause.

5 / 5

Trigger Term Quality

Strong natural keywords ('auth providers', 'login methods', 'SMS/email sender setup', 'publishable-key') that users would say, but it omits concrete provider names (e.g. WeChat, Google) and synonyms that appear in the body.

4 / 5

Distinctiveness Conflict Risk

CloudBase-specific and scoped to provider-side readiness, giving a clear niche; minor overlap risk with sibling auth skills (web/nodejs/http) that the 'before implementing' qualifier mitigates but does not fully eliminate.

4 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
TencentCloudBase/CloudBase-AI-Toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.