CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-saml-providers

Configure external SAML login providers, ACS/IdP URLs, metadata, signing certificates, realms, and claims. Use for Azure or generic IdPs; portal SAML SSO app providers belong to configuration-sso-app.

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

High-quality skill content: every paragraph carries non-obvious, implementation-verified specifics, with executable examples, a review checklist, and an unusually thorough verification protocol. The main improvements are structural — moving version-sensitive details out of the inline flow and splitting driver-specific guidance into reference files.

DimensionReasoningScore

Conciseness

The body is dense with repo-specific facts Claude cannot infer (cookie binding behavior, exact claim-name suffixes like "identity/claims/emailaddress", per-driver required fields) and avoids teaching known concepts. Minor penalty: time-sensitive references ("In v1.3.4", "Current go-authcrunch SAML validation supports") sit inline rather than in a deprecated/old-patterns section, matching the 'efficient; minor instances that could be trimmed' anchor.

4 / 5

Actionability

Two complete, copy-paste-ready Caddyfile examples (azure and generic drivers), a concrete module-resolution command ("go list -m -json github.com/greenpau/go-authcrunch"), exact claim-attribute name suffixes, and explicit per-driver required-field lists cover the common cases. Fully executable guidance matches the 5 anchor.

5 / 5

Workflow Clarity

A Review Checklist provides checkpoints (block-name choice, driver coverage, ACS alignment, role mapping, clock sync), and the Fixtures section defines an explicit verification protocol with failure cases (wrong signature, wrong ACS, replay, foreign cookie). The configure → enable → transform → verify sequence is spread across sections rather than presented as one ordered flow with feedback loops, fitting the 4 anchor; the 5 anchor's explicit sequenced workflow with recovery steps is not fully realized.

4 / 5

Progressive Disclosure

Sections are well-organized (Purpose, Shape, Provider Notes, Review Checklist, Fixtures), and all references are one level deep and clearly signaled (source files, the go-authcrunch module path, and a cross-link to the cookies skill). Some driver-specific detail (Azure vs generic requirements) could be split into reference files, and the body exceeds overview length, matching the 'good structure; minor organization gaps' anchor rather than a fully split 5.

4 / 5

Total

17

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: specific, concrete, and explicitly disambiguated from the sibling SSO-app skill, with an explicit "Use for" trigger clause. The when-clause is driver-scoped rather than user-phrased, and a few natural synonyms (single sign-on, other IdP vendors) would round out trigger coverage.

Suggestions

Extend the 'when' clause with user-phrase variations, e.g. "Use when the user mentions SAML login, single sign-on, or configuring an external identity provider."

Include one or two common IdP vendor names (e.g., Okta, JumpCloud, OneLogin) as trigger terms alongside Azure and generic IdPs.

Optionally name the Caddyfile block ("saml identity provider") in the description so users who know the directive can match it directly.

DimensionReasoningScore

Specificity

"Configure external SAML login providers, ACS/IdP URLs, metadata, signing certificates, realms, and claims" enumerates six concrete configuration artifacts, comprehensively covering the SAML provider domain. This matches the 'multiple specific concrete actions; comprehensive coverage' anchor; the 4 anchor would require minor coverage gaps, which are absent.

5 / 5

Completeness

Both are answered: the "what" is concrete (configure SAML login providers and their URLs, metadata, certs, realms, claims) and the "when" is explicit ("Use for Azure or generic IdPs"). The when-clause names concrete drivers but offers no user-phrase variations (e.g., "when the user mentions SAML login or single sign-on"), matching the 4 anchor ('when' could be more explicit) rather than the 5 anchor's concrete trigger phrases.

4 / 5

Trigger Term Quality

Natural terms users would say are present ("SAML", "login providers", "Azure", "IdP", "SSO", "claims"), giving good keyword coverage. A few natural variations are missing (e.g., "single sign-on", common IdP vendor names like Okta or JumpCloud), which fits the 'good keyword coverage; a few natural terms missing' anchor rather than the comprehensive 5.

4 / 5

Distinctiveness Conflict Risk

"portal SAML SSO app providers belong to configuration-sso-app" explicitly carves out the closest competing skill, and the SAML-identity-provider-vs-SSO-app distinction is a clear niche with distinct triggers. Minimal conflict risk matches the 5 anchor.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 suspicious

Warning

Total

15

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.