CtrlK
BlogDocsLog inGet started
Tessl Logo

xai-auth

xAI Grok API authentication and setup. Use when configuring xAI API access, setting up API keys, or troubleshooting authentication issues.

62

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/xai-auth/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, largely actionable setup guide with a clear quick-start sequence and a verification step. Its main weaknesses are redundancy (three near-identical client setup blocks), stale-prone time-sensitive tables inlined in the body, and an orphaned bundle script that is never surfaced to the reader.

Suggestions

Reference scripts/xai_client.py from the body (e.g., a "Production client" section) — it already implements the rate limiting, error handling, and streaming the skill describes, but is currently undiscoverable.

Consolidate the three near-identical OpenAI client setup code blocks (Method 1, Method 2, API Compatibility) into one example showing env-var vs direct-key options.

Move the time-sensitive pricing, rate-limit, and model tables into a separate reference file so model names and prices can be updated without touching the core workflow.

DimensionReasoningScore

Conciseness

The body is mostly efficient with scannable tables and short sections, but it includes unnecessary repetition — three near-identical OpenAI client setup code blocks (Method 1, Method 2, and the "API Compatibility" section all show the same base_url pattern) — and time-sensitive material (the "$150/Month Free Credits" pricing table, per-model rate-limit table, and model/version specifics like "grok-3-fast" vs "Grok 4.1 Fast") inlined rather than isolated. The guideline penalizing time-sensitive information outside a deprecated/old-patterns section applies here, keeping it below the 4 anchor.

3 / 5

Actionability

Guidance is mostly executable: a concrete curl test command, working Python/OpenAI SDK snippets, a .env file template, and an error-cause-solution table. Minor gaps keep it from a 5: the Python error-handling example calls time.sleep(60) without importing time, the xai-sdk method omits its install step, and the bundled production client scripts/xai_client.py is never mentioned despite being copy-paste ready.

4 / 5

Workflow Clarity

The Quick Start gives a clear three-step sequence (get key, set env var, test connection) with the curl test serving as an explicit validation checkpoint, and the error-handling section supplies error-recovery guidance. It falls short of a 5 because checkpoints are not integrated elsewhere — the free-credits opt-in flow has no verification step and the error example is illustrative rather than a feedback loop (no retry/re-validate cycle).

4 / 5

Progressive Disclosure

Sections are well organized, but scored against the actual bundle: scripts/xai_client.py (a full rate-limited, error-handling client) exists yet is never referenced from the body, making it undiscoverable, while reference-style material (rate limits, pricing, endpoint tables) is inlined in SKILL.md instead of split out. This matches anchor 3 (some structure, content that should be separate is inline, references not clearly signaled) rather than anchor 4's appropriately-placed content.

3 / 5

Total

14

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description following the good-example pattern: a concise third-person statement of what the skill does, followed by an explicit 'Use when' clause with concrete trigger phrases. The only gaps are minor missing synonyms (e.g., "Grok API key", "XAI_API_KEY") and one trigger phrase not qualified to the xAI domain.

DimensionReasoningScore

Specificity

"xAI Grok API authentication and setup" names the domain, and the trigger clause lists several concrete actions — "configuring xAI API access", "setting up API keys", "troubleshooting authentication issues" — putting it above the 1-2-action anchor. It falls short of the comprehensive 5 anchor (compare "Extract text and tables from PDF files, fill forms, merge documents, convert pages to images") because "setup" is somewhat generic and actions like key rotation or env-var configuration aren't enumerated.

4 / 5

Completeness

It explicitly answers both questions: the "what" is "xAI Grok API authentication and setup" and the "when" is a concrete 'Use when' clause with three trigger phrases, mirroring the anchor-5 example structure. It is not a 4 because the 'when' is already explicit and specific rather than merely present-but-could-be-more-specific.

5 / 5

Trigger Term Quality

Natural phrases like "setting up API keys", "troubleshooting authentication issues", and "configuring xAI API access" match what users would actually say. A few natural terms are missing ("Grok API key", "XAI_API_KEY", "console.x.ai", ".env"), so it does not reach the 5 anchor's comprehensive synonym/extension coverage.

4 / 5

Distinctiveness Conflict Risk

The xAI/Grok niche is clear and mostly distinct, but the unqualified trigger phrase "setting up API keys" could also match generic API-key or other-provider auth skills, giving minor overlap risk with closely related skills (anchor 4). It is more distinct than anchor 3's generic "works with document files" phrasing but lacks the fully provider-qualified triggers needed for a 5.

4 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
fernandezbaptiste/Skrillz
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.