CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-implementation-patterns

Implement or review authentication and authorization with explicit token, session and resource-access boundaries.

52

Quality

59%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-auth-implementation-patterns/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, well-organized overview with genuine task-specific limitations and safety notes, but it delegates all executable detail to a playbook that is absent from the bundle, leaving the skill's core guidance broken and non-actionable. Validation exists only in the worked example rather than as workflow checkpoints.

Suggestions

Include the referenced `resources/implementation-playbook.md` in the bundle (or remove the references and inline the key patterns), since the file is currently missing and both the Instructions and Resources sections point to it.

Add explicit validation checkpoints to the main workflow (e.g., a verify step after implementation such as testing failed login, logout, and session-fixation checks) rather than confining verification to the worked example.

Merge the duplicate playbook references (Instructions bullet and Resources section) into one clearly signaled reference to tighten conciseness.

DimensionReasoningScore

Conciseness

The body is lean and well-sectioned with no re-teaching of concepts Claude already knows; every section carries task-specific guidance. Not anchor 5 because of minor redundancy — the playbook is referenced in both Instructions ("If detailed examples are required, open `resources/implementation-playbook.md`") and again in a standalone Resources section, and the Limitations section could be tightened.

4 / 5

Actionability

Instructions are concrete in naming choices ("Choose auth strategy (session, JWT, OIDC) and token lifecycle") but give no executable patterns, code, or specific steps inline — all detail is deferred to `resources/implementation-playbook.md`. Not anchor 4 because the actual executable guidance is missing from the bundle entirely; not anchor 2 because the directives do specify real decisions to make.

3 / 5

Workflow Clarity

A rough sequence exists (define constraints → choose strategy → design authorization → plan secrets/audit), and the worked example does include verification steps ("verify that the old cookie cannot access `/api/profile`"). However, validation checkpoints appear only in the worked example, not as explicit steps in the main workflow. Not anchor 4 because the primary Instructions sequence lacks integrated validation checkpoints.

3 / 5

Progressive Disclosure

Structurally the split is good — a short overview body deferring detail to one one-level-deep reference — but the sole referenced file (`resources/implementation-playbook.md`) does not exist in the bundle, so the reference is broken and navigation leads nowhere. Not anchor 4 because a missing reference target undermines the disclosure structure; not anchor 2 because the body itself is well-organized and no content that belongs in a separate file is inlined.

3 / 5

Total

13

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, in third person, and names a clear niche with concrete boundary concepts, but it omits any "when to use" trigger clause, which limits discoverability and caps completeness. Keyword coverage is good but lacks common synonyms like login, OAuth, SSO, or JWT.

Suggestions

Append an explicit trigger clause, e.g., "Use when implementing login, OAuth2/SSO, session management, or RBAC, or when auditing auth code."

Broaden natural trigger terms to include synonyms users actually say: "login," "auth," "SSO," "JWT," "access control."

Name 1-2 more concrete capabilities (e.g., "design token lifecycle and refresh rotation") to lift specificity from two verbs to several specific actions.

DimensionReasoningScore

Specificity

Names the domain ("authentication and authorization") and two concrete actions ("Implement or review") with boundary types ("token, session and resource-access"), but coverage is not comprehensive — no mention of OAuth2, SSO, session management design, or RBAC. Not anchor 4 because it lists only two verbs rather than several specific actions; not anchor 2 because the actions and boundaries are concrete, not generic.

3 / 5

Completeness

It clearly answers "what" ("Implement or review authentication and authorization with explicit token, session and resource-access boundaries") but contains no "Use when..." clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. Not anchor 4 because the "when" is entirely absent rather than just under-specified.

3 / 5

Trigger Term Quality

"authentication," "authorization," "token," and "session" are natural terms users would say when needing this skill. Not anchor 5 because common synonyms and variations ("login," "auth," "OAuth," "SSO," "JWT," "RBAC") are absent; not anchor 3 because the included terms are genuinely natural rather than jargon-only.

4 / 5

Distinctiveness Conflict Risk

The specific boundary language ("explicit token, session and resource-access boundaries") carves a clear niche distinct from generic security or API skills. Not anchor 5 because "authentication and authorization" broadly could overlap with security-review or API-hardening skills; not anchor 3 because the boundary framing is specific enough to avoid most collisions.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.