CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-authentication-user-transforms

Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules. Use for authentication-time policy; stored account rules belong to configuration-users.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable reference: every section carries concrete syntax, exact forms, and documented failure modes with essentially no filler. Its weaknesses are organizational rather than informational — no sequenced provision-and-verify workflow, and all detail lives inline with no bundle-level reference files to offload the exhaustive test inventory and matcher grammar.

Suggestions

Add a short 'author → provision → verify' sequence with an explicit validation checkpoint (e.g., reload Caddy and confirm provisioning succeeds, with error-recovery guidance for shared-validation failures).

Move the exhaustive Validation test-suite inventory into a one-level-deep references/ file (e.g., references/validation.md), keeping a brief pointer in SKILL.md.

Consider offloading the detailed GitHub matcher grammar and lookup semantics into a reference file, keeping the four forms and a worked example inline.

DimensionReasoningScore

Conciseness

Extremely dense with no padding, no explanation of concepts Claude already knows, and no fluff ('action is optional before add, overwrite, delete and drop; it does not prefix require'). Score 4 not 5 because the Validation section's exhaustive test-suite inventory and a few over-compressed sentences ('match github retains its provider-specific spelling, including malformed statements for shared validation') could be trimmed or unpacked.

4 / 5

Actionability

Copy-paste-ready caddyfile blocks for every major case (matchers/actions, custom claims, GitHub matchers, conditional challenges), exact grammar forms ('match github id exact <id>', 'add matrix_id "@{claims.sub}:matrix.example.com" as string'), an executable inspection command (go list -m -json github.com/greenpau/go-authcrunch), and explicit parser grammar lines — fully executable and covering the common cases.

5 / 5

Workflow Clarity

This is a configuration-grammar reference rather than a multi-step process, and the single action — authoring a transform user block — is unambiguous, with failure and validation behavior documented exhaustively (what fails provisioning, what shared validation rejects, which tests verify it). Score 4 not 5 because there is no sequenced write → provision → verify workflow with explicit error-recovery checkpoints.

4 / 5

Progressive Disclosure

Well-organized sections and clearly signaled cross-references with load conditions ('Load those details only when changing the corresponding boundary'; 'See [runtime resolution](../configuration-runtime-resolution/SKILL.md)'). Score 4 not 5 because the bundle ships no references/ or scripts/ files of its own: all detail, including the long Validation test inventory and the GitHub matcher grammar, is inlined in a ~230-line SKILL.md where a one-level-deep reference file would be appropriate.

4 / 5

Total

17

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capability list, an explicit use-for clause, and deliberate boundary disambiguation against a sibling skill. Its main weakness is that the trigger phrasing ('authentication-time policy') is more abstract than the natural terms a user would actually say, and the literal block keyword 'transform user' is absent.

Suggestions

Anchor the 'when' clause in concrete trigger phrases, e.g. 'Use when configuring or debugging transform user / transform users blocks in an authentication portal'.

Add natural synonyms such as 'authentication portal', 'auth policy', or 'transform user block' to improve trigger-term recall.

Mention GitHub identity matchers and custom (typed) claims, which are major sections of the skill body, so the description's capability list is more comprehensive.

DimensionReasoningScore

Specificity

Enumerates several concrete capability areas ('matchers, typed claims, role actions, conditional challenges, MFA, and deny rules') under the verb 'Configure', matching the 'lists several specific actions; minor gaps' anchor. Not 5 because the items are domain topics rather than a fully comprehensive list of concrete actions (e.g., GitHub identity matchers and custom claims are not surfaced).

4 / 5

Completeness

Explicitly answers both 'what' ('Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules') and 'when' ('Use for authentication-time policy'). Score 4 not 5: the 'when' clause is present but abstract — 'authentication-time policy' is not a concrete trigger phrase in the style of 'when the user mentions PDFs'.

4 / 5

Trigger Term Quality

Includes natural terms users would say: 'user transforms', 'matchers', 'MFA', 'deny rules', 'authentication'. Falls at anchor 4 ('good keyword coverage; a few natural terms missing') because obvious variants like 'transform user' (the literal block keyword) and 'authentication portal' are absent.

4 / 5

Distinctiveness Conflict Risk

Clear niche ('portal user transforms') with explicit conflict avoidance ('stored account rules belong to configuration-users'), so it is highly distinguishable from sibling configuration skills with minimal wrong-trigger risk.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 6 suspicious

Warning

Total

15

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.