CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-web-cloudbase

CloudBase Web Authentication Quick Guide for frontend integration after auth-tool has already been checked. Provides concise and practical Web authentication solutions with multiple login methods and complete user management.

58

Quality

67%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./config/.claude/skills/auth-web-cloudbase/SKILL.md

The canonical home for this skill is auth-web-cloudbase in TencentCloudBase/CloudBase-AI-Toolkit

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a strong, highly actionable guide: executable v3 API snippets, explicit pre-flight MCP validation steps, a completion checklist, and a real one-level-deep reference bundle. Its main weakness is redundancy — several critical gotchas are repeated verbatim across multiple sections, inflating token cost without adding information — plus a slightly disorganized section flow (Overview/Prerequisites appear twice, Quick Start comes after Parameter map).

Suggestions

Consolidate the repeated accessKey/getLoginState/verifyOtp/anonymous-login warnings into a single authoritative section; each is currently stated 2-4 times across Common mistakes, Parameter map, Quick Start comments, and the cookbook.

Merge the duplicated 'Prerequisites' blocks (lines 57-58 and 81-102) and move 'Quick Start' ahead of 'Parameter map' so the read order follows the actual execution order.

Move the long per-mistake explanations in 'Common mistakes' that duplicate cookbook notes into references/extended-guide.md, keeping SKILL.md to the short trigger phrases.

DimensionReasoningScore

Conciseness

The body earns most of its tokens on genuinely non-obvious v3 SDK gotchas (verifyOtp callback vs standalone, misleading getLoginState uid, gateway 401 without session) rather than explaining concepts Claude already knows — but the same 4-5 warnings are each restated 2-4 times across 'Common mistakes', the parameter map, the init snippet, and the cookbook (e.g. the accessKey/session warning appears at lines 49, 100, 116-119). This fits 'mostly efficient but could be tightened' rather than 2, since the padding is duplication of valuable content, not known-concept filler.

3 / 5

Actionability

The cookbook provides copy-paste-ready executable snippets for every common case (init with accessKey, signInWithPassword, signUp + data.verifyOtp, signInWithOtp, resetPasswordForEmail/updateUser, getSession guard, onAuthStateChange, signOut), plus exact MCP calls with parameters (queryAppAuth(action="listProviders"), manageAppAuth(action="patchLoginStrategy", patch={usernamePassword: true})). Fully executable guidance covering the common cases.

5 / 5

Workflow Clarity

A clear sequenced flow with explicit validation checkpoints: verify provider 'On: "TRUE"' via queryAppAuth before writing sign-in code, check SMTP before email signUp, resolve env aliases via queryEnv, persist the publishable key to .env.local, error-recovery fallback console links when MCP fails, and a final Completion Bar checklist gating task completion. This matches the anchor-5 pattern of sequence + validation + error feedback loops.

5 / 5

Progressive Disclosure

Good structure: the main API cookbook lives in SKILL.md while detailed per-method scenarios are delegated to references/extended-guide.md (which exists in the bundle), signaled from a dedicated 'Extended guide' section, one level deep. It stays at 4 rather than 5 because the gotchas list is long enough to be inline material that arguably belongs in the reference, and the same reference link is repeated three times (gotchas, Extended guide, Reference index).

4 / 5

Total

17

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies the right niche (CloudBase Web authentication, post auth-tool setup) but reads as marketing-adjacent summary copy rather than trigger-optimized skill metadata: it has no 'Use when...' clause and no concrete method or SDK names. Adding explicit trigger phrases and naming the actual operations would move it into the 4-5 range.

Suggestions

Add an explicit trigger clause, e.g. 'Use when building login, registration, session, or protected-route pages with @cloudbase/js-sdk on the Web after provider setup has been verified.'

Replace the vague 'multiple login methods and complete user management' with the concrete capabilities: password sign-in, OTP sign-in/sign-up, forgot-password flow, session guards, and auth-state listeners.

Include natural synonyms users would actually say ("sign in", "log in", "register", "session", "CloudBase login") to improve trigger-term coverage.

DimensionReasoningScore

Specificity

It names the domain ("CloudBase Web Authentication Quick Guide for frontend integration") and gestures at 1-2 actions ("multiple login methods", "complete user management"), but no concrete named operations (no signInWithPassword, OTP, session handling, or SDK names). This matches 'names domain and 1-2 concrete actions' rather than score 4, which requires several specific actions, and is above score 2 because the actions are not purely generic.

3 / 5

Completeness

The 'what' is present ("Provides concise and practical Web authentication solutions with multiple login methods and complete user management") but the only 'when' is an ordering precondition ("after auth-tool has already been checked"), not an explicit trigger clause. Per the guideline that a missing 'Use when...' or equivalent explicit trigger guidance caps completeness at 3, this cannot score 4.

3 / 5

Trigger Term Quality

Relevant keywords are present ("CloudBase", "Web Authentication", "login methods", "frontend integration", "user management") but common natural variations users would actually say are missing: "sign in", "sign up", "register", "session", "@cloudbase/js-sdk". This fits 'some relevant keywords but missing common variations or synonyms' — not score 4, whose bar is good coverage with only a few terms missing.

3 / 5

Distinctiveness Conflict Risk

The description carves a fairly clear niche (CloudBase Web frontend auth sequenced after auth-tool), with low overlap risk against unrelated skills. It stays at 4 rather than 5 because it does not state its own negative boundaries (mini-program/native/server auth live in the body, not the description), leaving minor overlap risk with the sibling auth-tool-cloudbase skill.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
TencentCloudBase/CloudBase-AI-Toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.