CtrlK
BlogDocsLog inGet started
Tessl Logo

authentication-portal-api

Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS. Use for HTTP contracts; portal Caddyfile wiring belongs to configuration-authentication.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A high-quality, information-dense API-contract skill: exact endpoints, headers, payloads, status codes, and error-recovery guidance with no padding, plus real and well-signaled one-level-deep references. The only notable weakness is that substantial contract detail lives inline in SKILL.md where the bundle's reference pattern could carry it.

Suggestions

Move fine-grained refresh-transport rules (header sets, status-code mapping, replay/capacity semantics) into references/browser-refresh.md and keep a compact contract summary plus the pointer in SKILL.md.

Similarly trim the JWKS key-format specifics (kty/crv/x encoding, kid/alg behavior) into a short reference, keeping the endpoint contract and routing boundary inline.

DimensionReasoningScore

Conciseness

The body is dense but every sentence carries project-specific contract detail — exact headers ('Accept: application/json', 'X-Authcrunch-Refresh: 1'), field names ('sandbox_id', 'sandbox_secret'), and status codes (401/403/403/503/405) that Claude cannot know. Nothing explains general concepts Claude already knows, matching the lean/every-token-earns-its-place anchor.

5 / 5

Actionability

Guidance is executable at the HTTP-contract level: numbered login steps with exact payloads and fields, exact endpoints ('POST <base>/api/refresh_token' with '{'+'{"refresh_token":"<credential>"}' body), exact query parameters, response semantics, and error codes. For an instruction-only API-contract skill this is copy-paste-ready; the few conditional points (e.g. 'portal-supported Authorization header') are configuration-dependent and are routed to the matching config skill.

5 / 5

Workflow Clarity

The login challenge sequence is a clear 5-step numbered workflow with an explicit rotation checkpoint ('the portal may rotate sandbox_secret and return another challenge') and guardrails ('do not reuse an old sandbox_secret'). The Troubleshooting section provides error-recovery feedback loops keyed to specific symptoms, and verification is anchored to named E2E tests (TestCaddyTokenRefreshE2E, TestCaddyJWKSE2E).

5 / 5

Progressive Disclosure

Structure is good: all five references/ files are real, one level deep, and clearly signaled with what each covers ('read [authentication flows](references/authentication-flows.md)'), and cross-skill pointers are explicit. Falls short of 5 because the body itself is a fairly long (213-line) carrier of fine-grained contract detail (refresh transport rules, JWKS key-format specifics) that a reference file could hold, leaving the overview less lean than the top anchor's 'content appropriately split' ideal.

4 / 5

Total

19

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, tightly-scoped description: concrete actions, an explicit use clause, and active disambiguation from sibling configuration skills. Its main weakness is trigger-term breadth — the 'when' clause is terse and misses natural synonyms users would say.

Suggestions

Expand the trigger clause with concrete user-facing phrases, e.g. 'Use for portal login sequences, token refresh, JWKS/signing-key discovery, whoami/profile, or admin API work; use configuration-authentication for Caddyfile wiring instead.'

Add natural synonyms such as 'sign-in', 'logout', 'session', or 'signing keys' so retrieval matches how users actually phrase requests.

Consider naming the JSON/HTTP contract surface once ('HTTP contracts') with its concrete instances to make the 'when' less abstract.

DimensionReasoningScore

Specificity

"Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS" names two concrete actions (build, troubleshoot) across every surface the skill covers (login clients, refresh, profile/admin APIs, JWKS), matching the comprehensive-coverage anchor. Not 4 because coverage spans the skill's full scope with no gaps.

5 / 5

Completeness

Both parts are present: a clear, specific 'what' (build/troubleshoot login clients, refresh, profile/admin APIs, JWKS) and an explicit 'Use for HTTP contracts' trigger clause plus a boundary clarification. Not 5 because the 'when' is thin and abstract — 'HTTP contracts' doesn't name concrete user-side trigger phrases (login failures, token refresh, JWKS) the way the top anchor requires.

4 / 5

Trigger Term Quality

Contains good natural terms a user in this domain would say — "login", "refresh", "admin APIs", "JWKS", "portal", "HTTP" — but misses common variations like "sign-in", "logout", "session", "whoami", or "signing keys". Fits the 'good keyword coverage; a few natural terms missing' anchor rather than the comprehensive-synonym anchor.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear niche (portal HTTP/JSON contracts) and explicitly routes the nearest overlap away — "portal Caddyfile wiring belongs to configuration-authentication" — giving minimal conflict risk, matching the clear-niche anchor. Not 4 because the explicit disambiguation against the closest sibling skill leaves only minor residual overlap.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 8 suspicious

Warning

Total

15

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.