CtrlK
BlogDocsLog inGet started
Tessl Logo

add-permission

Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard. Use when a new endpoint needs authorization. See modules/identity.md + frontend/admin.md.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An excellent, tightly written procedural skill: five concrete steps with real file paths and code, a critical failure-mode warning, an explicit build/test verification checkpoint, and a closing checklist. The only weaknesses are templated (not fully copy-paste-ready) code snippets and references to documentation files that are not present in the bundle.

Suggestions

Either add the referenced files (modules/identity.md, frontend/admin.md) to the bundle or drop the 'See ...' pointers so no references dangle.

Make the `All` collection snippet fully concrete (show the actual list construction with the new entry) so Step 1 is copy-paste ready once the {X}/{Resources} placeholders are filled.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence — no basic concepts are explained, each of the 5 steps is a path + tight snippet, and even the Dashboard divergence is covered in one dense paragraph. This matches the 'every token earns its place' anchor; the checklist is verification value, not padding, so it does not drop to 4.

5 / 5

Actionability

Concrete file paths (e.g. `Modules.{X}.Contracts/Authorization/{X}Permissions.cs`, `clients/admin/tests/helpers/shell-mocks.ts`) and real code snippets make this mostly executable, but the snippets are templated with {X}/{Resources} placeholders and elisions like `/* … include the new one … */` in the `All` collection, leaving minor gaps versus copy-paste-ready. The parameterization is justified by the argument-hint, so it sits at 4 rather than 3.

4 / 5

Workflow Clarity

A clear Step 1–5 sequence with per-step scope, a critical footgun warning ("Never let a second/duplicate of that interface exist"), and an explicit validation checkpoint in the checklist ("Build green; admin `test:e2e` green") match the top anchor. This is not a destructive or batch operation, so the cap does not apply, and the sequence is far too complete for the 4 anchor's 'minor validation gaps'.

5 / 5

Progressive Disclosure

Sections are well-organized and the content is appropriately concise for a single-file skill, but the body and description reference `modules/identity.md`, `frontend/admin.md`, and `.agents/rules/modules/identity.md`, none of which exist in the bundle — dangling references are a minor organization gap. This fits the 4 anchor; it is not the 5 anchor's clean, well-signaled one-level-deep reference structure.

4 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it explicitly states what the skill does end-to-end and when to use it, in third person, with concrete trigger phrasing. The only weakness is slightly thin trigger-term coverage — it lacks common synonyms like 'auth' or 'access control' that users might naturally say.

DimensionReasoningScore

Specificity

Quotes like "server constant + endpoint gate" and "mirror it into the permissions catalog + route guard" list multiple concrete actions covering the full server + admin scope, matching the comprehensive-coverage anchor. It does not fit the 4 anchor because no meaningful sub-task of the permission flow is left unmentioned.

5 / 5

Completeness

The what is explicit ("Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard") and the when is an explicit concrete trigger ("Use when a new endpoint needs authorization"), which matches the 5 anchor; the 4 anchor requires the 'when' to be less explicit, which it is not.

5 / 5

Trigger Term Quality

"Add a new permission" and "endpoint needs authorization" are natural phrases a user would say, but common synonyms ("auth", "access control", "role", "lock down") are absent. Good coverage with a few natural terms missing fits the 4 anchor; it is not comprehensive enough for 5.

4 / 5

Distinctiveness Conflict Risk

The description is anchored to a specific internal pipeline (permission constants, permissions catalog, route guard), giving it a clear niche with minimal overlap risk against generic coding skills. It clearly matches the 5 anchor rather than the 4 anchor's 'minor overlap risk with closely related skills'.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
fullstackhero/dotnet-starter-kit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.