CtrlK
BlogDocsLog inGet started
Tessl Logo

goth-providers

This skill should be used when the user asks to "add a provider", "configure google oauth", "set up microsoft login", "azure ad authentication", "oauth provider setup", "add social login", or needs help with specific OAuth provider configuration in Goth.

52

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/goth-oauth/skills/goth-providers/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable Go examples and concrete troubleshooting, but it is inflated by wholesale duplication of the registration pattern and it cites two reference files that do not exist in the bundle. Consolidating the repeated code and actually shipping the referenced files would resolve its main weaknesses.

Suggestions

Keep a single canonical provider-registration example and have the Google Setup, Microsoft Setup, and Multiple Providers sections reference it instead of repeating near-identical goth.UseProviders blocks.

Create references/google-oauth-setup.md and references/microsoft-oauth-setup.md (currently missing) and move the detailed console/portal steps and provider-specific scope tables into them, leaving SKILL.md as the overview.

Fix the error-swallowing example ('user, _ := gothic.CompleteUserAuth(w, r)') to handle the error, and add an end-to-end verification step that confirms the callback round-trip completes after registration.

DimensionReasoningScore

Conciseness

The same goth.UseProviders registration code appears three times nearly verbatim (registration pattern, per-provider setup, and multiple-providers sections), and scope/callback guidance repeats across sections — several padded, duplicated sections beyond what a competent reader needs. Not score 3 because the duplication is wholesale section-level repetition rather than occasional over-explanation; not score 1 because the content is code-dense with no concept padding.

2 / 5

Actionability

Concrete, copy-paste-ready Go for provider registration, tenant options, provider-name override, and env vars, plus numbered console/portal steps and error-name-keyed troubleshooting ('redirect_uri_mismatch', 'invalid_client'). Not score 5 due to minor gaps: examples swallow errors ('user, _ := gothic.CompleteUserAuth(w, r)') and no complete route/handler example ties the flow together.

4 / 5

Workflow Clarity

Console and portal configuration steps are clearly numbered per provider, and the 'Common Issues' section gives error-recovery guidance for the failure modes most likely to occur. Not score 5 because there is no explicit end-to-end verification checkpoint (e.g., confirm the callback round-trip works after registration); not score 3 since the setup sequences and reactive recovery guidance are genuinely clear. Not capped at 3 since this is configuration guidance, not a destructive or batch operation.

4 / 5

Progressive Disclosure

References are clearly signaled ('For detailed Google setup steps, see references/google-oauth-setup.md') and one level deep, but the references/ directory does not exist — both cited files are dangling — and the detailed setup content that belongs in them (portal steps, scope tables) is inlined in SKILL.md. Scored against the actual bundle structure: well-organized but broken navigation and misplaced detail. Not score 4 because nonexistent referenced files are more than a minor organization gap; not score 2 because the body itself is well-sectioned and the reference intent is explicit.

3 / 5

Total

13

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has excellent, explicit trigger coverage with natural user phrasing and a clearly named niche, but it is entirely 'when'-shaped: it never states what the skill does. Leading with a concrete capability statement would make it fully complete.

Suggestions

Open with a third-person capability statement before the trigger clause, e.g., 'Configures OAuth providers (Google, Microsoft/Azure AD) with github.com/markbates/goth, covering registration, scopes, and callback setup.'

Add one or two natural trigger variations such as 'sign in with Google' or 'Goth login' to broaden keyword coverage.

Sharpen the 'what' by distinguishing this skill's scope (provider configuration) from sibling Goth skills like goth-fundamentals to reduce the residual overlap risk of the generic 'add a provider' trigger.

DimensionReasoningScore

Specificity

The description names its domain concretely ('specific OAuth provider configuration in Goth') with provider-specific triggers, but never states what actions the skill itself performs — capabilities appear only as quoted user phrases ('add a provider', 'configure google oauth'), which is implied rather than explicit capability listing.

3 / 5

Completeness

The 'when' is explicit and rich ('This skill should be used when the user asks to...'), but the 'what' is only weakly implied through the trigger clause 'needs help with specific OAuth provider configuration in Goth' — the description never states what the skill provides (e.g., setup guidance and code patterns for Goth providers).

3 / 5

Trigger Term Quality

Strong natural trigger phrases users would actually say ('add a provider', 'set up microsoft login', 'azure ad authentication', 'add social login') with good synonym coverage across providers, but a few natural variations are missing (e.g., 'sign in with Google', 'Goth login', 'Azure AD').

4 / 5

Distinctiveness Conflict Risk

Names a clear niche ('specific OAuth provider configuration in Goth') with library-specific triggers, giving minimal conflict risk with unrelated skills; minor overlap remains with sibling Goth skills (e.g., goth-fundamentals) and the fairly generic 'add a provider' trigger.

4 / 5

Total

14

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 4 missing

Warning

Total

14

/

16

Passed

Repository
freightCognition/linehaulai-claude-marketplace
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.