CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-tool-cloudbase

CloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./config/.claude/skills/auth-tool-cloudbase/SKILL.md

The canonical home for this skill is auth-tool-cloudbase in TencentCloudBase/CloudBase-AI-Toolkit

SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured routing/activation document with a clear execution order and concrete tool boundaries, backed by a solid one-level-deep extended guide. Its weaknesses are duplicated content between body and extended guide, and validation/checklist steps that reference files missing from the bundle.

Suggestions

Fix or remove the dangling "[Authentication Activation Checklist](checklist.md)" link — either ship checklist.md in the bundle or drop the bullet, and make the "Reference index" consistent with what is actually packaged.

De-duplicate the anonymous-login / 401 warning: keep a one-line pointer in the "Minimal checklist" and leave the full detail in references/extended-guide.md §2, which already covers it.

Add an explicit inline validation checkpoint for provider configuration changes (e.g. re-query via queryAppAuth(action="getLoginConfig") after patchLoginStrategy to confirm the change landed) instead of deferring verification to the absent change-safety-protocol file.

DimensionReasoningScore

Conciseness

Mostly efficient bullet-driven routing guidance, but the "Use this first when" section largely mirrors the frontmatter description, and the "Minimal checklist" anonymous-login bullet is a dense run-on paragraph duplicating nearly verbatim the warning in references/extended-guide.md §2, plus version-sensitive "@cloudbase/js-sdk 3.x" detail outside any deprecated/old-patterns section. Not 4: these are more than minor trims; not 2: there is no concept over-explanation and the structure is still tight.

3 / 5

Actionability

Concrete, executable direction: named MCP tools ("queryAppAuth / manageAppAuth"), enumerated auth-tool actions ("status, start_auth, set_env, logout, get_temp_credentials"), and a numbered preferred execution order with explicit fallback rules ("Use callCloudApi only as a fallback"). Not 5: no example request payloads inline (those live in the extended guide) and the "Minimal checklist" step points to a checklist.md that is not in the bundle.

4 / 5

Workflow Clarity

The "Preferred execution order" (1-4) and Activation Contract give a clear decision sequence, but validation checkpoints are only pointers to files absent from the bundle: "Read [Authentication Activation Checklist](checklist.md)" (missing) and the Change Safety Protocol path ("cloudbase-platform/references/protocols/change-safety-protocol.md", also not present). Enabling/disabling providers is a configuration-change workflow whose verification steps resolve to dangling references — a validation gap capping this at 3. Not 2: the sequence itself is coherent and well-defined.

3 / 5

Progressive Disclosure

The one-level-deep reference to references/extended-guide.md (which exists, is well-structured, and contains no nested references) is good, and the "Then also read" cross-skill pointers are clear. But the body links a missing in-bundle file (checklist.md) while the "Reference index" claims to list "All packaged reference files" (only extended-guide.md), and the dense anonymous-login warning is inlined in the body though it already lives in the extended guide — content that should be separate is inline. Not 4: the dangling link plus the index/body contradiction are more than minor organization gaps; not 2: structure and navigation of what does exist is good.

3 / 5

Total

13

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concise, with an explicit use-when clause and domain-specific trigger terms. Main weakness is the slightly open-ended "other provider-side readiness" tail and some overlap risk with sibling CloudBase auth-implementation skills.

DimensionReasoningScore

Specificity

Quotes concrete actions — "inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup" — giving several specific capabilities. Not 5: the trailing "or other provider-side readiness" is open-ended and generic, diluting the concrete action list; not 3: well beyond 1-2 actions.

4 / 5

Completeness

What ("CloudBase auth provider configuration and login-readiness guide") and an explicit when-clause ("This skill should be used when users need to...") with concrete trigger phrases are both present, matching the anchor-5 example pattern. Not 4: the when is fully explicit and specific, not merely adequate.

5 / 5

Trigger Term Quality

Natural trigger terms include "auth providers", "login methods", "SMS/email sender setup", "publishable-key prerequisites", "configure". Not 5: misses common user phrasings and synonyms like "third-party login", "sign-in methods", or named providers (WeChat, Google); not 3: keyword coverage is good and domain-specific.

4 / 5

Distinctiveness Conflict Risk

Scoped to provider-side readiness "before implementing a client or backend auth flow", carving a clear niche against implementation skills. Not 5: phrases like "login methods" and "SMS/email sender setup" could plausibly trigger sibling client-implementation skills (web/miniprogram/node auth) in a CloudBase skill family; not 3: the boundary language is explicit.

4 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
TencentCloudBase/CloudBase-AI-Toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.