CtrlK
BlogDocsLog inGet started
Tessl Logo

minimal-web-baas-demo

Fast path for a minimal CloudBase Web + database demo (最小前后端 / 最小可用 fullstack / Lovable-like BaaS). Defaults to @cloudbase/js-sdk client CRUD (NoSQL app.database / PG app.rdb), MCP-only schema, preview-first, and forbids cloud functions unless secrets, cron/background jobs, or logic that security rules/RLS cannot express. Use for 搭一套 demo、留言板、Todo、Notes、Kanban, or when users say 带云函数+云数据库 but only need CRUD. NOT for production multi-service backends, CloudRun, WeChat Mini Programs, or tasks that truly need server secrets.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strongly actionable, well-sectioned fast-path brief that never wastes tokens teaching known concepts, but it is undermined by redundancy — the same ordering and the zero-cloud-function rule restated three to four times — and by missing explicit validation checkpoints for its database CRUD workflow. The partner-packaging section is inline content that would serve better as a one-level-deep reference.

Suggestions

Deduplicate the pipeline: keep the 'Capability sniff order' as the single canonical ordering and reduce the 'Standard playbook' and 'One-screen partner paste' to cross-references to it; state the zero-cloud-function rule once (Hard rule 2) instead of four times.

Add an explicit validation checkpoint and error-recovery loop to the playbook, e.g. after wiring list + create, verify the newly added record round-trips in the list before reporting the preview URL, and give the fix→retry step for the gateway 401 case (call auth.signInAnonymously() then retry the operation).

Move the 'WorkBuddy / partner packaging notes' section (~30 lines including the host-capability table and paste block) into a separate reference file (e.g. references/partner-packaging.md) and keep a one-line pointer in SKILL.md.

DimensionReasoningScore

Conciseness

There is no concept-explanation padding (it never explains what CloudBase or BaaS is), but the same pipeline is stated three times — the "Capability sniff order" block, the "Standard playbook", and the "One-screen partner paste" — and the rule "cloud function count for this path = 0" appears four times (Hard rule 2, sniff order step 7, playbook step 6, partner paste). The ~30-line WorkBuddy/partner packaging section is host-integration detail most sessions don't need. This fits "mostly efficient but includes some unnecessary explanation or could be tightened"; it is below anchor 4 because the repetition is more than minor trimmable instances.

3 / 5

Actionability

Concrete, executable guidance dominates: named MCP tools ("writeNoSqlDatabaseStructure", "queryPgDatabase / managePgDatabase"), SDK calls ("app.database() → db.collection(...).get()/add()/update()/watch(...)", "app.rdb().from(...)"), CLI parity ("tcb db pg …"), and a runnable anonymous-sign-in snippet with error handling. It falls short of anchor 5's copy-paste-ready coverage of common cases because the actual list/create wiring (step 4 of the playbook) is only named, not shown, and some steps like "downloadTemplate" are host-tool references without invocation detail.

4 / 5

Workflow Clarity

The sequence is clear and ordered (numbered playbook 1-6, an explicit "Do not reorder" sniff order, gates like "ask before deploy"), but validation is implicit rather than explicit: there is no "verify the created record appears in the list" checkpoint before reporting the preview URL, and no fix→retry loop for database failures — the "Skipping this yields gateway 401" note is prevention, not recovery. Because the workflow centers on database CRUD operations and the rubric caps workflow clarity at 3 without explicit validation/feedback loops for database operations, this stays at anchor 3 despite the clear sequencing.

3 / 5

Progressive Disclosure

No bundle files exist, so this scores the body's own structure: sections are well organized (Activation Contract, Hard rules, sniff order, playbook, an "On-demand skills" table with clearly signaled one-level-deep sibling references). The gap keeping it below anchor 5 is that the "WorkBuddy / partner packaging notes" section (~30 lines of host-packaging tables and a paste block) is niche operational detail inlined in SKILL.md that belongs in a separate reference file, which is a minor organization gap consistent with anchor 4.

4 / 5

Total

14

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An excellent description: third-person voice, dense with concrete capability statements (specific SDK, NoSQL/PG APIs, MCP schema management), bilingual natural trigger phrases, and an explicit NOT-for boundary. The only minor cost is that it packs a lot into ~90 words, but every clause is informational rather than fluff.

DimensionReasoningScore

Specificity

The description names multiple concrete capabilities with the exact APIs involved: "@cloudbase/js-sdk client CRUD (NoSQL app.database / PG app.rdb), MCP-only schema, preview-first, and forbids cloud functions unless secrets, cron/background jobs, or logic that security rules/RLS cannot express". Coverage of the niche is comprehensive with named tools, data planes, and explicit exclusions, matching the anchor for multiple specific concrete actions with comprehensive coverage; it exceeds anchor 4, which requires minor gaps.

5 / 5

Completeness

What is answered explicitly ("Fast path for a minimal CloudBase Web + database demo. Defaults to @cloudbase/js-sdk client CRUD... MCP-only schema, preview-first") and when is answered with concrete trigger phrases ("Use for 搭一套 demo、留言板、Todo、Notes、Kanban, or when users say 带云函数+云数据库 but only need CRUD"), plus a NOT-for clause. This matches the anchor requiring both what AND when with concrete trigger phrases; a 4 would have a weaker or less explicit 'when', which does not apply.

5 / 5

Trigger Term Quality

Natural phrases a user would actually say appear in both languages: "最小前后端 / 最小可用 fullstack / Lovable-like BaaS", "搭一套 demo、留言板、Todo、Notes、Kanban", and the reinterpreted request "带云函数+云数据库 but only need CRUD". This is comprehensive natural-term coverage including synonyms (message board/留言板, Todo/Notes/Kanban, Lovable-like), matching the anchor-5 example's breadth; anchor 4 would leave common variations missing, which is not the case here.

5 / 5

Distinctiveness Conflict Risk

The niche is tightly scoped to CloudBase minimal Web BaaS demos, and the explicit negative triggers ("NOT for production multi-service backends, CloudRun, WeChat Mini Programs, or tasks that truly need server secrets") sharply separate it from adjacent cloud-function, CloudRun, and Mini Program skills. Distinct triggers plus a clear niche with minimal conflict risk matches anchor 5; anchor 4's "minor overlap risk" is not present given the exclusion list.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
TencentCloudBase/CloudBase-AI-Toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.