CtrlK
BlogDocsLog inGet started
Tessl Logo

mcp-access

Open the GBrain owner dashboard, manage MCP clients and permissions, or connect a native OAuth harness. Distinguishes owner administration from ordinary MCP access.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./plugin-variants/gbrain-coding/skills/mcp-access/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, highly actionable operator manual with strong safety validation (dry-run previews, version guards, unknown-outcome recovery) and clearly signaled external documentation. Its main weaknesses are deferred exact commands and inlined dense policy that a skill bundle could split into reference files.

DimensionReasoningScore

Conciseness

The body contains no background explanation of concepts Claude already knows; every line is dense operational policy ("Do not print their values", "List failure is not an empty list", "Refresh cannot expand the original scope grant") and assumes the reader's competence.

5 / 5

Actionability

Concrete subcommands and flags are given throughout (login-link --oauth-request ID, mcp grant NAME --client ID --if-version N --dry-run, setup ID --harness ID, --credentials-out PRIVATE_FILE, --yes --if-version N), but exact full commands are deferred to ADMIN.md and placeholders (NAME/ID/URL) remain, leaving minor gaps versus copy-paste-ready guidance.

4 / 5

Workflow Clarity

Destructive operations (revoke, delete, invalidate-tokens) are guarded with explicit validation: --dry-run previews before/after, --if-version concurrency checks, "Inspect the existing client before retrying" on unknown outcome, and connection verification via an authenticated native-harness call. The cap for missing validation does not apply. Not 5 because the body is organized as a per-action catalog rather than a single sequenced workflow with an explicit checklist.

4 / 5

Progressive Disclosure

Three external references are clearly signaled with their purpose at the top ("for the exact commands and recovery table", "for client installation", "for the running service") plus a remote fallback URL, all one level deep. Not 5: references point outside the skill bundle (../../docs/..., not locally verifiable), and roughly 100 lines of dense operational policy are inlined that a proper bundle could partially split into its own reference files.

4 / 5

Total

17

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-scoped with concrete actions and a clear owner-vs-ordinary distinction, but it lacks an explicit "when to use" trigger clause, which caps completeness and leaves trigger guidance implicit.

Suggestions

Append a 'Use when...' clause naming explicit trigger moments, e.g. "Use when the user asks to open the MCP admin panel, register/revoke MCP clients, or connect a harness via native OAuth."

Enumerate the concrete administration operations (register, revoke, delete clients; invalidate tokens) instead of the grouped phrase "manage MCP clients and permissions".

Add natural synonyms such as "admin panel", "MCP tokens", and "client registration" to improve trigger-term coverage.

DimensionReasoningScore

Specificity

"Open the GBrain owner dashboard, manage MCP clients and permissions, or connect a native OAuth harness" lists several specific actions, but "manage MCP clients and permissions" groups operations (register, revoke, invalidate) rather than enumerating them, leaving minor coverage gaps.

4 / 5

Completeness

The "what" is clear (dashboard login, client/permission management, OAuth connection), but there is no "Use when..." clause or equivalent explicit trigger guidance; "Distinguishes owner administration from ordinary MCP access" is a scoping statement that only weakly implies when.

3 / 5

Trigger Term Quality

Natural terms like "owner dashboard", "MCP clients", "permissions", and "OAuth harness" are present, but common variations such as "admin panel", "revoke", and "tokens" are missing.

4 / 5

Distinctiveness Conflict Risk

The GBrain owner-administration niche is clear and explicitly separated from ordinary MCP access, but "connect a native OAuth harness" could overlap with generic MCP/OAuth setup skills.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 3 suspicious

Warning

Total

14

/

16

Passed

Repository
garrytan/gbrain
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.