CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-wechat-miniprogram

CloudBase WeChat Mini Program native authentication guide. This skill should be used when users need mini program identity handling, OPENID/UNIONID access, or `wx.cloud` auth behavior in projects where login is native and automatic.

52

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./config/.claude/skills/auth-wechat-miniprogram/SKILL.md

The canonical home for this skill is auth-wechat-miniprogram in TencentCloudBase/CloudBase-AI-Toolkit

SKILL.md
Quality
Evals
Security

Quality

Content

46%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is well split between a lean overview and a genuine one-level reference file, but the body itself is padded with two parallel 'when to use / do not use' sections and repeated 'native and automatic' statements, and its step-by-step instructions reference scenarios as being 'in this file' when they were moved to the extended guide. Tightening the duplication and fixing the stale pointer would raise actionability and workflow clarity.

Suggestions

Merge the 'Activation Contract' and 'When to use this skill' sections into one routing block — they currently duplicate each other's use-cases and 'Do NOT use for' lists nearly verbatim, and state 'native and automatic' auth behavior only once instead of 3-4 times.

Fix the stale pointer in 'How to use this skill' step 3: change 'Pick a scenario from this file' to point at references/extended-guide.md, where the scenarios now live after the 500-line split.

Add a validation checkpoint to the workflow (e.g. how to verify the injected identity in a cloud function call, and what to do if OPENID is absent), since the current sequence ends at 'consult the official documentation' with no feedback loop.

DimensionReasoningScore

Conciseness

The body states the same routing and concept information multiple times: "Use this first when" / "Do NOT use for" (Activation Contract) is repeated almost verbatim by "When to use this skill" / "Do NOT use for:", and "native and automatic", "no explicit login", and "identity is automatically available" each appear 3-4 times across "How to use", "Core concepts", and the activation sections. This is noticeably padded — an entire redundant section — though it is domain-specific rather than generic filler.

2 / 5

Actionability

Concrete guidance exists ("Use `wx-server-sdk` in cloud functions", "Use `wx.cloud` in Mini Program client code", "Ask the user for `env`"), but the body contains no code or API shapes — all executable examples live in references/extended-guide.md — and step 3 says "Pick a scenario from this file" when the scenarios actually live in the reference file, which is a concrete misdirection.

3 / 5

Workflow Clarity

"How to use this skill (for a coding agent)" gives a clear 5-step numbered sequence (confirm env → understand flow → pick scenario → follow API shapes → consult docs), but there are no validation checkpoints or error-recovery feedback loops, and the "Pick a scenario from this file" step points to content that is no longer in this file, leaving a gap in the sequence.

3 / 5

Progressive Disclosure

The body is an appropriately-sized overview that delegates the 415-line scenario/code detail to a real, one-level-deep reference (references/extended-guide.md, which itself contains no nested references), signaled both in "Extended guide" and the "Reference index". Minor organization gaps: the reference is listed twice, and the "Pick a scenario from this file" wording predates the split to the extended guide, slightly muddying navigation.

4 / 5

Total

12

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid description with an explicit 'use when' clause and domain-specific trigger terms (wx.cloud, OPENID/UNIONID). Its main weakness is a vague 'what' — "native authentication guide" names the domain without stating concrete actions — and no boundary against the sibling Web/Node auth skills.

DimensionReasoningScore

Specificity

Quotes: "native authentication guide", "mini program identity handling, OPENID/UNIONID access, or `wx.cloud` auth behavior". It names the domain and 2-3 concrete capability nouns, but the only action verb is "guide" — no implementation/explanation verbs like the anchor-5 examples, and coverage of what the skill actually does is not comprehensive.

3 / 5

Completeness

Both parts are present: what — "CloudBase WeChat Mini Program native authentication guide"; when — "This skill should be used when users need mini program identity handling, OPENID/UNIONID access, or `wx.cloud` auth behavior...". The 'when' clause is explicit with concrete triggers, but the 'what' is a thin noun phrase ("guide") rather than a clear statement of actions, which anchor 5 requires.

4 / 5

Trigger Term Quality

Quotes: "mini program identity handling", "OPENID/UNIONID", "wx.cloud auth behavior", "login is native and automatic". These are terms users would naturally say for this need, but a few common variations are missing (e.g. "小程序", "WeChat login", "user identity in cloud functions"), so it falls just short of anchor 5.

4 / 5

Distinctiveness Conflict Risk

Quotes: "CloudBase WeChat Mini Program", "`wx.cloud` auth behavior", "native". The niche is well-pinned to mini program native auth, but closely related sibling skills (auth-web, auth-nodejs) cover adjacent CloudBase auth territory and the description includes no explicit boundary (e.g. 'not for Web-based WeChat login'), leaving minor overlap risk — anchor 4 rather than 5.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
TencentCloudBase/CloudBase-AI-Toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.