CtrlK
BlogDocsLog inGet started
Tessl Logo

configuration-sso-app

Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys. Use for sso provider blocks and their runtime limits; external SAML login providers are separate.

68

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A high-quality, deeply code-grounded configuration skill: every constraint ties to a named parser or authcrunch file, guidance is fully concrete, and a review checklist plus runtime-check expectations provide validation. Weaknesses are minor — some redundancy between sections, no explicitly sequenced workflow, and a long inline document that could shed detail to reference files.

DimensionReasoningScore

Conciseness

The body is dense and code-backed with no explanations of concepts Claude already knows, but carries minor redundancy: the Review Checklist restates the supported fields ('Include entity_id, driver aws, cert, private key, and at least one location') and the boundary statement repeats the separation point twice. Efficient with trims available, so anchor 4 rather than the lean anchor 5.

4 / 5

Actionability

Everything is concrete and executable: a complete Caddyfile example, an exact field-to-authcrunch mapping list, exact URL shapes ('/auth/apps/sso/aws/metadata.xml'), a role format with a concrete example ('aws/123456789012/Administrator'), and named fixture files. This is copy-adaptable guidance covering the common cases.

5 / 5

Workflow Clarity

The content is organized by topic with a 10-item verification checklist and a described runtime check ('verify that readable certificate/PKCS8 inputs produce the configured metadata URLs, unauthenticated requests redirect to login...'), but the edit-then-validate flow is never laid out as a sequenced process with feedback loops. Mostly clear checkpoints without an explicit step sequence, so 4 rather than 5.

4 / 5

Progressive Disclosure

A well-sectioned single document with clearly signaled one-level-deep references to authoritative source files ('caddyfile_sso_provider.go', 'go-authcrunch/pkg/sso/config.go', fixture test files) and sibling skills. No bundle files exist to split content into, but the ~165-line inline document is long enough that some detail could live in separate files, placing it at good-structure anchor 4 rather than 5.

4 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capability list in third person, an explicit trigger clause, and active disambiguation against adjacent skills. Its only weakness is limited synonym/extension coverage in the trigger terms and a single action verb.

DimensionReasoningScore

Specificity

The description lists several concrete objects ('SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys') under a single action verb, giving specific but not fully comprehensive action coverage. It is not a 3 since more than 1-2 concrete actions are named, and not a 5 because 'Configure' is the only verb and the action list is not exhaustive.

4 / 5

Completeness

The 'what' is concrete ('Configure portal-provided SAML SSO apps, AWS role names, metadata, certificates, and PKCS8 keys') and the 'when' is explicit with a concrete trigger phrase ('Use for sso provider blocks and their runtime limits'). This matches the anchor that clearly answers both what and when with concrete triggers, rather than a 4 where the 'when' is only weakly explicit.

5 / 5

Trigger Term Quality

'sso provider blocks', 'SAML SSO apps', 'AWS role names', and 'PKCS8 keys' are natural phrases a user working on this configuration would say. It falls short of 5 because natural synonyms and extensions such as 'single sign-on' spelled out or 'metadata.xml' are missing.

4 / 5

Distinctiveness Conflict Risk

'external SAML login providers are separate' plus the 'sso provider blocks' trigger carve out a clear niche explicitly disambiguated from the sibling OAuth/SAML login-provider skills. Conflict risk with other skills is minimal.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 2 suspicious

Warning

referenced_paths_exist

Referenced path issues: 3 missing, 3 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.