CtrlK
BlogDocsLog inGet started
Tessl Logo

xai-auth

xAI Grok API authentication and setup. Use when configuring xAI API access, setting up API keys, or troubleshooting authentication issues.

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/xai-auth/SKILL.md

The canonical home for this skill is xai-auth in fernandezbaptiste/Skrillz

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, mostly actionable setup guide with a good quick-start sequence, but it underuses its own bundle (scripts/xai_client.py is orphaned) and inlines time-sensitive pricing/rate-limit data. A small executable gap (missing time import) and redundant compatibility section keep it from scoring higher.

Suggestions

Add a section pointing to scripts/xai_client.py (e.g., '## Production client: see scripts/xai_client.py for a rate-limited, error-handling wrapper') so the bundle script is discoverable from SKILL.md.

Move the pricing table, rate limits, and endpoint reference into a reference file (e.g., references/pricing.md) or date-stamp them, since these numbers change frequently.

Fix the Python error-handling example to import time, and trim the 'API Compatibility' section, which duplicates the Method 1 example almost verbatim.

DimensionReasoningScore

Conciseness

Mostly efficient with concrete examples, but the "API Compatibility" section largely repeats the Method 1 example, and time-sensitive pricing/rate-limit tables are inlined without dating, which the guidelines say should penalize conciseness. Could be tightened.

3 / 5

Actionability

Mostly executable, copy-paste-ready guidance: curl test command, three working auth code examples, env-var setup, and a concrete error-to-solution table. Minor gaps — the Python error-handling example calls time.sleep(60) without importing time, and hardcoded pricing numbers may drift.

4 / 5

Workflow Clarity

The Quick Start gives a clear get-key → set-env → test-connection sequence with the test step acting as a validation checkpoint, and the Error Handling table supports recovery. Falls short of anchor 5 because the error-recovery guidance is not integrated as an explicit feedback loop (validate → fix → retry) in the setup workflow.

4 / 5

Progressive Disclosure

The bundle contains scripts/xai_client.py (a production-ready wrapper), but SKILL.md never references or links to it, so it is undiscoverable from the body. Pricing, rate-limit, and endpoint reference tables are all inlined rather than split into reference files, though external links and related skills are clearly signaled.

3 / 5

Total

14

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description in third-person voice with an explicit 'Use when...' clause and multiple concrete triggers. Both what and when are clearly answered; only minor synonym coverage keeps trigger terms and action breadth just below perfect.

DimensionReasoningScore

Specificity

Names the domain ("xAI Grok API authentication and setup") and several concrete actions — "configuring xAI API access", "setting up API keys", "troubleshooting authentication issues" — but the actions are variants of one narrow task rather than the comprehensive multi-action coverage of the anchor-5 example.

4 / 5

Completeness

Explicitly answers both: the what ("xAI Grok API authentication and setup") and the when ("Use when configuring xAI API access, setting up API keys, or troubleshooting authentication issues") with three concrete trigger phrases, matching the anchor-5 example structure.

5 / 5

Trigger Term Quality

Good natural keyword coverage ("xAI", "Grok", "API keys", "configuring", "troubleshooting authentication") that users would plausibly say, but misses common variations and synonyms such as "Grok API", "xai key", or credential-related phrasing.

4 / 5

Distinctiveness Conflict Risk

The "xAI"/"Grok" niche is clearly distinct from other provider-setup skills and the triggers are provider-specific, so conflict risk with similar skills (even other xai-* skills like xai-models or xai-x-search) is minimal.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
fernandezbaptiste/Skrillz
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.