CtrlK
BlogDocsLog inGet started
Tessl Logo

supabase-auth

Setup and manage Supabase authentication including project connection, tokens, login methods, and user management. Use when configuring Supabase access, implementing authentication, or managing users.

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, highly actionable reference: nearly all content is executable code with minimal prose, and detail is properly deferred to three real one-level-deep reference files. The main gaps are the absence of an ordered setup workflow with validation checkpoints (especially around destructive admin operations) and minor duplication between inline sections and the reference files.

Suggestions

Add an explicitly ordered setup workflow (install CLI → supabase login → supabase link → set env vars → init client) with a validation checkpoint such as confirming `supabase status` output before proceeding.

Add verification steps around destructive admin operations, e.g., confirm the target user via listUsers or getUserById before deleteUser, and check the returned error before considering the operation complete.

Trim the inline Authentication Methods and Session Management code samples to one canonical example each, deferring full coverage to references/auth-methods.md and references/session-management.md to reduce duplication.

DimensionReasoningScore

Conciseness

The body is almost entirely executable code with terse, valuable comments ("bypasses email confirmation", "NEVER expose client-side") and no concept over-explanation. Minor trimmable content remains: the Quick Reference table partially overlaps the Environment Variables section, and basic signUp/signInWithPassword samples largely restate known API usage — anchor 4 ('efficient; minor instances that could be trimmed'), not 5 ('every token earns its place').

4 / 5

Actionability

Every section provides copy-paste-ready executable code: client initialization, signUp/signInWithPassword/signInWithOtp/signInWithOAuth/signInAnonymously, session handling, resetPasswordForEmail, and admin.createUser/deleteUser/updateUserById/listUsers, covering the common cases — matches anchor 5 ('fully executable; copy-paste ready code or commands').

5 / 5

Workflow Clarity

Setup steps exist (install CLI, login, link, get keys) but only as an unordered table with no explicit sequence, and the destructive admin operation ("Delete user" via deleteUser) has no verification or feedback-loop steps — the rubric's cap on destructive operations without validation applies. Anchor 3 ('sequence present but checkpoints missing or implicit'), not 4 which requires most checkpoints present.

3 / 5

Progressive Disclosure

All three referenced files (auth-methods.md, session-management.md, mfa-setup.md) exist, are one level deep, and are clearly signaled with one-line descriptions in the References section; MFA is appropriately deferred entirely. However, the inline Authentication Methods and Session Management sections condense-duplicate their reference counterparts — anchor 4 ('most content is appropriately placed; minor organization gaps'), not 5 ('content appropriately split').

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it explicitly states what the skill does and when to use it, with platform-specific triggers and good keyword coverage. The only weakness is that capability areas are listed as noun phrases under generic verbs ('setup and manage') rather than concrete actions, and a few natural trigger variations (sign in, OAuth, MFA) are absent.

DimensionReasoningScore

Specificity

"Setup and manage Supabase authentication including project connection, tokens, login methods, and user management" names the domain plus four concrete capability areas, but they are noun phrases under generic verbs rather than concrete verb-action pairs (e.g., 'extract text from PDF files'), matching anchor 4 ('several specific actions; minor gaps') and clearly above anchor 3's 1-2 actions.

4 / 5

Completeness

Both parts are explicit: a clear what ("Setup and manage Supabase authentication including project connection, tokens, login methods, and user management") and an explicit when with three concrete trigger phrases ("Use when configuring Supabase access, implementing authentication, or managing users"), matching anchor 5 and exceeding anchor 4's weaker single 'when' example.

5 / 5

Trigger Term Quality

"Use when configuring Supabase access, implementing authentication, or managing users" plus "login methods" and "tokens" give good natural keyword coverage, but common variations users say like "sign in", "OAuth", "MFA", or "auth" are missing — anchor 4 ('good keyword coverage; a few natural terms missing'), above anchor 3's 'missing common variations'.

4 / 5

Distinctiveness Conflict Risk

"Supabase authentication" is a clear platform-specific niche with distinct triggers (Supabase access, login methods, user management), so it is unlikely to fire for unrelated skills — matches anchor 5 ('clear niche with distinct triggers; minimal conflict risk').

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
fernandezbaptiste/Skrillz
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.