CtrlK
BlogDocsLog inGet started
Tessl Logo

jazz-permissions-security

Use this skill when designing data schemas, implementing sharing workflows, or auditing access control in Jazz applications. It covers the hierarchy of Groups, Accounts, and CoValues, ensuring data is private by default and shared securely through cascading permissions and invitations.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is jazz-permissions-security in garden-co/classic-jazz

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable and well-structured with executable examples and a strong troubleshooting workflow. Its main weakness is mild verbosity from the redundant Quick Reference section and the lack of bundle files to offload deeper detail.

Suggestions

Remove or slim the Quick Reference section since each point is already explained in detail above it, cutting redundant tokens.

Consider moving the full roles matrix and cascading inheritance rules into a references file, keeping SKILL.md as a lean overview with well-signaled links.

DimensionReasoningScore

Conciseness

The body is mostly lean with executable code blocks and minimal concept padding, but the Quick Reference section restates points already covered above and some explanatory prose could be trimmed.

4 / 5

Actionability

Provides copy-paste-ready executable TypeScript/React/Svelte code across creating shared data, invites, public data, join requests, and cascading permissions, covering the common cases with concrete examples.

5 / 5

Workflow Clarity

The Troubleshooting section gives explicit sequenced diagnostic steps with validation checkpoints (verify ownership, verify membership, check references; check role via getRoleOf), and key heuristics and rules are clearly flagged.

5 / 5

Progressive Disclosure

Well-organized sections with a clear Quick Reference and a one-level-deep References block pointing to external docs/examples, but no bundle files exist so all detail is inlined rather than split into separate reference files.

4 / 5

Total

18

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong, specific, and clearly states both what the skill does and when to use it with a third-person voice. It could be marginally improved by adding the natural user question phrases and reducing overlap with the schema-design skill.

Suggestions

Add natural question-style triggers users actually say, e.g. 'Use when the user asks how to share data, why someone can't see data, or how to set up roles/permissions'.

Tighten the 'designing data schemas' trigger to avoid overlap with jazz-schema-design, e.g. focus on the permissions/sharing aspect of schema ownership rather than schema design itself.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'designing data schemas, implementing sharing workflows, or auditing access control' — across a clearly defined domain (Groups, Accounts, CoValues), with comprehensive coverage of the security scope.

5 / 5

Completeness

Explicitly answers both 'what' (covers the hierarchy of Groups/Accounts/CoValues, cascading permissions, invitations) and 'when' ('Use this skill when designing data schemas, implementing sharing workflows, or auditing access control') with concrete triggers.

5 / 5

Trigger Term Quality

Natural phrases like 'sharing workflows', 'access control', and 'data is private by default' align with what users say, but it lacks synonym variations and the natural short question forms ('share X with Y', 'can't see data') that appear in the body.

4 / 5

Distinctiveness Conflict Risk

The Jazz-specific niche (CoValues, cascading permissions) is distinctive, but 'designing data schemas' overlaps with the sibling jazz-schema-design skill the body itself calls out, creating minor conflict risk.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
garden-co/classic-jazz
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.