CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-oauth-applications

Register named OAuth clients, manage private registration storage, and configure portal OIDC providers. Owns security oauth/oidc provisioning commands; external login providers and security local are separate.

56

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.codex/skills/configuration-oauth-applications/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a dense, highly project-specific reference with excellent grammar and constraint documentation and a sound reference-file split. Its weaknesses are the absence of any explicitly sequenced, checkpointed workflow, the inlining of catalogue-level detail, and prose compression that makes sections hard to scan.

Suggestions

Add an explicit ordered workflow section (declare application → stage rotation via `security oauth rotate secret` → select revision → validate via the referenced test suites) with validation checkpoints between steps.

Move the test-suite catalogue in "Examples and Validation" and the serialization-format rules to a reference file, keeping a short pointer in SKILL.md.

Break up compound sentences in "Ownership" and "Grammar" into shorter imperative bullets so the brace-handling rules are scannable instead of deduplicated across sections.

DimensionReasoningScore

Conciseness

Nearly every line carries repo-specific rules Claude could not infer (brace-handling edge cases, digest checks, byte-exact URI preservation) — no generic filler — but the prose is over-compressed into long compound sentences and repeats the quoted-brace rules in both "Ownership" and "Grammar", and the test-catalogue paragraph could be tightened. Mostly efficient with some tightening possible, matching the 3 anchor rather than 4.

3 / 5

Actionability

The complete caddyfile grammar block, byte-exact redirect_uri examples, concrete commands ("security oauth rotate secret"), and named test files/fixtures give mostly executable guidance. It falls short of 5 because much of the body is constraint description ("fails closed", "must match") with no inline worked end-to-end example — the full example lives in an external testdata fixture — leaving minor gaps.

4 / 5

Workflow Clarity

The credential-rotation flow is sequenced with failure modes ("First stage any credential change with `security oauth rotate secret`, then select that revision", digest rejection, fails-closed mismatches) and validation coverage is extensive, but the main flows are contract catalogues rather than ordered steps with explicit checkpoints. Sequence is present yet checkpoints are implicit or delegated to other skills, matching the 3 anchor rather than 4.

3 / 5

Progressive Disclosure

Well-signaled one-level-deep references to real files (references/oidc-provider.md, oidc-conformance.md, private-provisioning.md — all verified present) plus clearly labeled sections (Ownership, Grammar, Credentials, Examples). Minor gaps keep it below 5: oidc-conformance-actions.md is only reachable via a link nested inside oidc-conformance.md, and the dense serialization rules and long test catalogue inlined in SKILL.md are content that could live in a reference file.

4 / 5

Total

14

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, third-person, and exceptionally well-fenced against sibling skills, but it never states when to use it. Adding a trigger clause naming the user-facing situations and a couple of OpenID synonyms would lift it substantially.

Suggestions

Add an explicit trigger clause, e.g. "Use when configuring oauth application blocks in security, registering OAuth/OIDC clients, or rotating stored client secrets."

Include a few natural synonym triggers such as "OpenID Connect" and "identity provider" so the description fires for users who do not say "OIDC".

Make the "manage private registration storage" capability concrete by naming the action, e.g. "provision and rotate private client registrations in the oauth registration store".

DimensionReasoningScore

Specificity

"Register named OAuth clients, manage private registration storage, and configure portal OIDC providers" lists three concrete capabilities with a clear command-ownership boundary. It falls short of 5 only because "manage private registration storage" is slightly generic compared to the fully enumerated actions in the top anchor.

4 / 5

Completeness

The "what" is clearly stated (register clients, manage registration storage, configure portal OIDC providers), but there is no "Use when..." clause or equivalent explicit trigger guidance — the second sentence only draws ownership boundaries ("external login providers and security local are separate"), which is exclusion, not a when-to-use trigger. Per the judging guideline, a missing trigger clause caps completeness at 3; it is not 2 because the what is fully clear.

3 / 5

Trigger Term Quality

Solid natural keywords: "OAuth clients", "OIDC providers", "registration", "provisioning", "portal" — terms a user working on this configuration surface would plausibly say. A few common variations are missing (e.g., "OpenID Connect" spelled out, "identity provider" as an inclusive trigger rather than an exclusion), which keeps it below the comprehensive-synonym anchor at 5 and clearly above the generic keyword coverage at 3.

4 / 5

Distinctiveness Conflict Risk

"Owns security oauth/oidc provisioning commands; external login providers and security local are separate" explicitly fences this skill against its nearest sibling skills. This is a clear niche with distinct triggers and minimal conflict risk, matching the top anchor.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 7 suspicious

Warning

Total

15

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.