CtrlK
BlogDocsLog inGet started
Tessl Logo

supabase-auth

Setup and manage Supabase authentication including project connection, tokens, login methods, and user management. Use when configuring Supabase access, implementing authentication, or managing users.

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is supabase-auth in fernandezbaptiste/Skrillz

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured reference skill with executable code for every common auth flow and clean one-level references to real bundle files. Its weaknesses are the missing validation/verification steps around destructive admin operations and some duplication between the inline method sections and the reference files.

Suggestions

Add an explicit validation/verification step before destructive admin operations, e.g. verify the user exists and confirm the target userId before calling supabaseAdmin.auth.admin.deleteUser, with an error-recovery path if the call fails.

Number the setup sequence explicitly (1. npm install supabase --save-dev, 2. supabase login, 3. supabase link --project-ref <ref>, 4. supabase status) so the connection workflow is unambiguous, and show handling of the { data, error } return in at least one example.

Trim the inline Authentication Methods and Session Management sections to the single most common example per method and defer the rest to references/auth-methods.md and references/session-management.md to reduce duplication.

DimensionReasoningScore

Conciseness

The body is dominated by lean tables and executable code with almost no concept explanation or padding, matching the 'efficient; minor instances of over-explanation' anchor. It is not 5 because the Authentication Methods section (lines 68-159) and Session Management section duplicate material that references/auth-methods.md and references/session-management.md cover in detail, so some tokens could be trimmed.

4 / 5

Actionability

Copy-paste-ready code throughout: CLI commands ("npm install supabase --save-dev", "supabase link --project-ref <ref>"), env var setup, and complete destructured calls ("supabase.auth.signUp", "supabase.auth.signInWithOAuth", "supabaseAdmin.auth.admin.createUser") covering the common cases, matching the 'fully executable' anchor. Not 4 because there are no meaningful gaps in the core flows.

5 / 5

Workflow Clarity

The Quick Reference table implies a setup sequence (install → login → link → status) and sections are logically ordered, but there is no explicit sequencing, error handling, or validation. The Admin Operations section includes destructive operations ("supabaseAdmin.auth.admin.deleteUser") with no verification or feedback-loop step, and the rubric guideline caps workflow clarity at 3 for workflows involving destructive or batch operations without validation.

3 / 5

Progressive Disclosure

All three referenced files (references/auth-methods.md, references/session-management.md, references/mfa-setup.md) exist, are one level deep, and are clearly signaled with one-line descriptions in a References section; common cases are inline with bulk detail deferred, matching the 'good structure' anchor. Not 5 because the inline Authentication Methods section substantially duplicates references/auth-methods.md, a minor organization gap.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that explicitly states what the skill does and when to use it, with concrete action areas and natural trigger phrases. The only minor gaps are missing synonyms/variations (e.g., 'auth', 'sign-in', 'SSO') and unmentioned capabilities like MFA and OAuth providers that the body actually covers.

DimensionReasoningScore

Specificity

"Setup and manage Supabase authentication including project connection, tokens, login methods, and user management" names several concrete action areas (connection, tokens, login methods, user management), matching the 'several specific actions; minor gaps' anchor. It falls short of 5 because coverage gaps exist (no hint of MFA, OAuth providers, or password recovery), and exceeds 3 because more than 1-2 concrete actions are named.

4 / 5

Completeness

Clearly answers both: what ("Setup and manage Supabase authentication including project connection, tokens, login methods, and user management") and when ("Use when configuring Supabase access, implementing authentication, or managing users") with concrete trigger phrases, matching the anchor-5 good example pattern. A 4 would require the 'when' clause to be less explicit than it is here.

5 / 5

Trigger Term Quality

"Use when configuring Supabase access, implementing authentication, or managing users" provides natural trigger phrases users would say. Not 5 because common variations like "auth", "sign-in", or "SSO" are missing; not 3 because keyword coverage is good rather than merely 'some relevant keywords'.

4 / 5

Distinctiveness Conflict Risk

"Supabase authentication" carves out a clear niche with distinct triggers; the vendor name makes conflict with generic auth skills minimal. This matches the 'clear niche with distinct triggers; minimal conflict risk' anchor.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
fernandezbaptiste/Skrillz
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.