CtrlK
BlogDocsLog inGet started
Tessl Logo

slack-auth-security

OAuth flows, token management, and security best practices for Slack apps. Use when implementing app distribution, multi-workspace installations, token storage and rotation, managing scopes and permissions, or securing production Slack applications.

60

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/slack-go-sdk/skills/slack-auth-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-sectioned reference with concrete Go examples, but it under-delivers on its own promises: the OAuth flow stops after URL generation, and every detailed reference link is broken (files absent, ../../ path). Generic security boilerplate (rate limiter, secrets-manager advice) spends tokens on knowledge Claude already has.

Suggestions

Fix the reference links: create the referenced files under references/ and change paths from ../../references/*.md to references/*.md so the five 'See X for details' pointers actually resolve.

Complete the OAuth flow with the token-exchange step (handling the callback and calling oauth.v2.access) instead of showing only 'Step 1: Generate authorization URL'.

Trim generic content Claude already knows — the full RateLimiter implementation and the env-var/secrets-manager storage advice — and replace it with Slack-specific detail like signing-secret rotation and the xoxb/xoxp/xoxe token distinctions.

DimensionReasoningScore

Conciseness

Mostly efficient section style, but the 28-line RateLimiter implementation and generic advice like "Use secrets managers (AWS Secrets Manager, HashiCorp Vault)" and "Never use HTTP endpoints" restate standard security knowledge Claude already has rather than Slack-specific detail. Not a 2 because there is no padded prose and the Slack-specific content is tight.

3 / 5

Actionability

Mostly executable slack-go code (request verification, token rotation, manifest creation, workspace token handling), but there are gaps: undefined helpers (generateRandomState, storeToken, loadTokenForTeam) and the OAuth section shows only "Step 1: Generate authorization URL" with the token-exchange step deferred to a reference file that does not exist.

4 / 5

Workflow Clarity

Content is organized as a topic reference rather than sequenced workflows: no numbered multi-step procedures and no validation checkpoints — e.g., token rotation replaces the stored token without verifying the new one or handling rollback of the old. Not a 2 because sections are coherent and ordered, and not a 4 because checkpoints are entirely absent for the multi-step flows.

3 / 5

Progressive Disclosure

The overview-to-reference split is conceptually right and references are clearly signaled ("See [oauth-flow.md]... for complete OAuth implementation"), but all five links use the unusual ../../references/ path and point to files that do not exist in the bundle — navigation to the detail material is broken. Not a 4 because broken reference paths are more than a minor organization gap.

3 / 5

Total

13

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: explicit what and when with concrete Slack-specific triggers in third-person voice. The only weakness is that capabilities are phrased as noun-phrase topics rather than concrete actions, which keeps specificity at 4.

DimensionReasoningScore

Specificity

The description lists several specific capability areas ("OAuth flows, token management, and security best practices", "token storage and rotation", "managing scopes and permissions", "multi-workspace installations") covering the domain comprehensively, but they are noun-phrase topics rather than concrete action verbs like the anchor-5 example ("Extract text... fill forms").

4 / 5

Completeness

Both what ("OAuth flows, token management, and security best practices for Slack apps") and when ("Use when implementing app distribution, multi-workspace installations, token storage and rotation, managing scopes and permissions, or securing production Slack applications") are explicit, with five concrete trigger phrases — this is the anchor-5 pattern, clearly above anchor 4 where 'when' could be more specific.

5 / 5

Trigger Term Quality

Good natural keyword coverage — "Slack apps", "OAuth", "token", "scopes", "permissions", "multi-workspace", "app distribution" — but a few natural variations users would say are missing ("bot token", "xoxb", "authenticate", "sign in with Slack").

4 / 5

Distinctiveness Conflict Risk

"for Slack apps" and "production Slack applications" pin the niche clearly, and triggers like multi-workspace installation and Slack scopes are distinct from adjacent skills; minimal overlap risk.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 5 suspicious

Warning

Total

14

/

16

Passed

Repository
freightCognition/linehaulai-claude-marketplace
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.