CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-authentication

Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring. Delegates cookies, UI, transforms, crypto, and OIDC provider details to focused skills.

60

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.codex/skills/configuration-authentication/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, dense reference-style skill: executable Caddyfile examples, explicit cross-skill delegation, real source/fixture pointers, and acceptance criteria that double as validation guidance. Weakest spots are the lack of an explicit stepwise workflow and some option detail inlined in SKILL.md that could be pushed to references.

DimensionReasoningScore

Conciseness

The body is dense with project-specific facts (parser semantics, defaults, validation behavior) and assumes Claude's competence without explaining generic concepts. Minor trimmable spots remain, e.g. the portal-naming style paragraph ("Avoid naming a portal `portal`: the repeated words ... are confusing") and some long chained sentences in the wiring section.

4 / 5

Actionability

Concrete, copy-paste-ready Caddyfile snippets cover the common cases (full portal + route shape, `enable` lines, crypto keys, redirect trust rules, `enable admin api`), plus precise source-file pointers and explicit negations like "Do not generate an `enable user registration <name>` portal line". It stops short of 5 because a few directives discussed only in prose (e.g. `enable source ip tracking` / `validate source address`, admin API endpoint list) lack inline syntax examples.

4 / 5

Workflow Clarity

The flow is logically ordered (shape → backend wiring → options → fixtures → acceptance criteria) with an explicit ordering constraint ("Define those stores ... with the matching domain skills before enabling them") and named validation checkpoints (fixtures, `TestParseCaddyfileRedirectTrustValues`, the E2E subtest, acceptance criteria). It is not a 5 because the sequence is section-implicit rather than an explicit stepwise procedure with validate-and-retry loops.

4 / 5

Progressive Disclosure

The body is an overview with a clearly signaled, one-level-deep reference ([token refresh](references/token-refresh.md), which exists in the bundle) and clean delegation to sibling skills for specialized sub-blocks. Minor gaps: "Common Portal Options" inlines a fair amount of directive-level detail that could live in a reference, and references/token-refresh.md itself chains onward to ../../configuration/references/operator-examples.md, adding a second hop.

4 / 5

Total

16

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description with concrete capability areas and deliberate boundary-setting via delegation. Its main weakness is the absence of any "Use when..." trigger guidance, which caps completeness and limits discoverability.

Suggestions

Add an explicit trigger clause, e.g. "Use when configuring or troubleshooting `authentication portal <name>` blocks, `authenticate with` routes, backend `enable` lines, or redirect trust rules."

Include the natural user-facing phrases for the route-level handler ("authenticate with <portal>") and the login-portal vocabulary so the skill triggers on those phrasings.

Optionally name the product/Caddyfile context once so users describing the ecosystem by product name can find this skill.

DimensionReasoningScore

Specificity

The description lists several concrete action areas — "Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring" — which are specific capabilities rather than vague filler. It falls short of the 5 anchor because coverage has minor gaps (e.g., admin API endpoints and portal role tiers covered in the body are not mentioned).

4 / 5

Completeness

The "what" is clear (configure portals, backend selection, redirect trust, refresh, wiring) and the delegation sentence clarifies scope, but there is no "Use when..." clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric guidelines.

3 / 5

Trigger Term Quality

It includes good domain keywords a user of this configuration system would naturally say: "authentication portals", "backend selection", "redirect trust", "refresh", "portal wiring". A few natural terms are missing ("login", "authenticate with", the product name), so it does not reach the comprehensive synonym coverage of the 5 anchor.

4 / 5

Distinctiveness Conflict Risk

The niche is clear (portal blocks, backend selection, redirect trust, refresh, wiring) and the explicit delegation of "cookies, UI, transforms, crypto, and OIDC provider details to focused skills" actively reduces overlap with sibling skills. It is not a 5 because the broad terms "refresh" and "crypto" still carry minor overlap risk with those delegated skills.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 11 suspicious

Warning

referenced_paths_exist

Referenced path issues: 1 missing, 1 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.