CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-storage-web

Complete guide for CloudBase cloud storage using Web SDK (@cloudbase/js-sdk) - upload, download, temporary URLs, file management, and best practices.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./config/.claude/skills/cloud-storage-web/SKILL.md

The canonical home for this skill is cloud-storage-web in TencentCloudBase/CloudBase-AI-Toolkit

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers exceptional operational specificity — executable code, exact MCP commands, error-code triage, and mandatory validation loops for bucket creation, security domains, and RLS — making it highly actionable and workflow-safe. Its weaknesses are token efficiency (the same PG bucket-existence and security-domain warnings are repeated multiple times, and early sections duplicate the Overview) and structure (a long monolith with no reference bundle, where the PG-mode and RLS material would be better split out).

Suggestions

Consolidate the bucket-existence prerequisite into one section — it is currently repeated in the gotchas, the minimal checklist, the dedicated 'Bucket existence prerequisite' section, and the Upload rules, which wastes context tokens.

Move the PG/pgstore mode details (the Supabase comparison table, per-mode return-shape table, and RLS SQL) into a references/ file (e.g. references/pg-storage.md) and keep only a short routing pointer in SKILL.md, creating real progressive disclosure.

Merge the redundant 'Overview'/'Typical tasks' section with the Activation Contract, and fold the 'Security-domain reminder' section into the 'Local dev recipe' to eliminate the duplicated guidance.

DimensionReasoningScore

Conciseness

The body is mostly high-value operational detail Claude would not know (PG/pgstore bucket semantics, error codes, RLS SQL), but the bucket-existence prerequisite is stated at least four times (gotchas, minimal checklist, the dedicated 'Bucket existence prerequisite' section, and again in Upload rules), the 'Overview' section duplicates the Activation Contract, and the 'Local dev recipe' overlaps the later 'Security-domain reminder' — clearly tightenable but not dominated by padding, fitting anchor 3 rather than the 'several padded sections' of 2.

3 / 5

Actionability

Fully executable, copy-paste-ready guidance throughout: complete JavaScript for upload/progress/getTempFileURL/delete/download, exact MCP tool invocations ('queryEnv(action="domains")', 'envDomainManagement(action="create")'), exact whitelist entry formats ('127.0.0.1:4173'), a per-mode return-shape table, and runnable RLS SQL — specific examples cover the common cases, matching the top anchor.

5 / 5

Workflow Clarity

Multi-step processes are clearly sequenced with explicit validation checkpoints and feedback loops: the Local dev recipe (inspect domains → add exact host:port → poll rather than blind-sleep → only then implement), the bucket prerequisite (list buckets → create before frontend code → diagnose the failed POST response's error code), and hard failure-propagation rules ('If uploadCoverImage() rejects, the parent createArticle() MUST also reject'), matching the 'explicit validation steps; feedback loops; checklists' anchor.

5 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are all absent), and the skill is a ~330-line monolith: the PG-mode upload section (~80 lines of comparison tables and RLS SQL) and the bucket-prerequisite material are inlined where a reference file would be appropriate, and the only file pointers go to sibling skills or external doc URLs rather than a real one-level-deep bundle. Clear section headers provide some structure, so this lands on anchor 3 rather than the 'content that clearly belongs in separate files is inlined' of 2.

3 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-scoped to CloudBase browser-side storage with a clear SDK identifier and distinct niche, but it lacks any explicit 'when to use' trigger clause, which caps its completeness and overall effectiveness. Adding a 'Use when…' sentence with natural trigger phrases (e.g. 'Use when uploading or downloading files from a browser/web app via @cloudbase/js-sdk') would raise it substantially.

Suggestions

Add an explicit 'Use when…' clause with concrete trigger phrases (e.g. 'Use when a browser or web app must upload, download, or manage files in CloudBase storage, or when the request mentions uploadFile, getTempFileURL, or @cloudbase/js-sdk').

Replace the filler 'and best practices' with specific uncovered capabilities such as 'delete files' and 'generate temporary download URLs' to tighten coverage.

Include natural synonyms users would say (e.g. 'file upload', 'presigned/signed URL', 'cloud file storage') to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

The description names the domain ('CloudBase cloud storage using Web SDK (@cloudbase/js-sdk)') and lists several concrete actions ('upload, download, temporary URLs, file management'), but 'best practices' is filler and there are minor coverage gaps (no delete/preview mention beyond the generic 'file management'), matching the 'several specific actions; minor gaps' anchor rather than the comprehensive 5.

4 / 5

Completeness

It clearly answers 'what' (upload, download, temporary URLs, file management via the Web SDK) but contains no 'Use when…' clause or equivalent explicit trigger guidance — 'Complete guide for…' describes content, not activation conditions — so completeness is capped at 3 per the judging guidelines.

3 / 5

Trigger Term Quality

Good natural keyword coverage ('CloudBase cloud storage', 'Web SDK', 'upload', 'download', 'temporary URLs', plus the package name '@cloudbase/js-sdk'), but common variations a user might say are missing (e.g. 'file upload', 'presigned/signed URL', 'COS', file-type mentions), fitting the 'good coverage; a few natural terms missing' anchor.

4 / 5

Distinctiveness Conflict Risk

'CloudBase cloud storage using Web SDK (@cloudbase/js-sdk)' carves a clear niche (browser-side SDK storage vs. Mini Program, backend MCP, or static hosting) with distinct triggers, leaving only minor overlap risk with closely related CloudBase sibling skills, matching the 'mostly distinct; minor overlap' anchor rather than the fully conflict-free 5.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
TencentCloudBase/CloudBase-AI-Toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.