CtrlK
BlogDocsLog inGet started
Tessl Logo

moai-platform-auth

Authentication and authorization specialist covering Auth0, Clerk, and Firebase Auth. Use when implementing authentication, MFA, SSO, passkeys, WebAuthn, social login, or security features.

59

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.moai/archive/skills/v2.16/moai-platform-auth/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-organized overview with a clear platform-selection guide and good Context7 integration, but it is padded with generic security advice Claude already knows and defers all concrete implementation to reference files that are absent from the bundle, leaving the actual guidance thin and the progressive-disclosure navigation broken.

Suggestions

Ship the referenced bundle files (reference/auth0.md, reference/clerk.md, reference/firebase-auth.md, reference/comparison.md) so the signaled navigation actually resolves, or inline the key implementation steps and drop the dangling references.

Cut generic security best-practices Claude already knows (HTTPS enforcement, JWT claim validation, basic password policies) and keep only platform-specific, non-obvious guidance.

Add at least one concrete, executable snippet per platform (e.g. ClerkProvider setup, Auth0 Actions token enrichment, Firebase custom-claims Admin SDK call) so the body instructs rather than only describes.

DimensionReasoningScore

Conciseness

Mostly organized reference content (platform selection, Context7 topics) but padded with generic security advice Claude already knows — 'Always use HTTPS in production', 'Always validate token signatures', 'Verify token audience (aud claim)' — and a 'Common Rationalizations' table that could be trimmed.

2 / 3

Actionability

Some concrete guidance exists (decision criteria, Context7 tool invocations, verification checklist) but the body mostly describes platforms and patterns rather than instructing, and all concrete implementation is deferred to reference files that are not present in the bundle.

2 / 3

Workflow Clarity

A 'Navigation Guide' gives a clear 5-step sequence and a 'Verification' checklist provides endpoints, but intermediate checkpoints are implicit and the workflow breaks because the reference files it directs the reader to open do not exist.

2 / 3

Progressive Disclosure

The body is structured as an overview with well-signaled one-level-deep references ('File: reference/auth0.md', etc.), but no references/ or reference/ directory exists in the bundle, so the referenced files are missing and navigation fails; inline generic best-practices content that could live in a reference file also drags this down.

2 / 3

Total

8

/

12

Passed

Description

90%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: explicit 'Use when' trigger, natural keywords, and a clearly scoped three-platform niche. The only weakness is that the capability verbs ('covering', 'implementing') are generic rather than enumerating distinct concrete actions.

Suggestions

Replace generic verbs with concrete actions, e.g. 'Implement and configure authentication, set up MFA/SSO/passkeys, validate JWT tokens, and manage sessions across Auth0, Clerk, and Firebase Auth.'

DimensionReasoningScore

Specificity

Names the domain and three concrete platforms plus specific feature areas ("MFA, SSO, passkeys, WebAuthn, social login"), but the verbs are generic ("covering", "implementing") rather than distinct concrete actions, so it falls short of the score-3 anchor listing multiple specific actions.

2 / 3

Completeness

Explicitly answers both what ("Authentication and authorization specialist covering Auth0, Clerk, and Firebase Auth") and when ("Use when implementing authentication, MFA, SSO, passkeys, WebAuthn, social login, or security features"), with an explicit 'Use when' trigger clause.

3 / 3

Trigger Term Quality

Includes natural terms users would actually say — "authentication", "MFA", "SSO", "passkeys", "WebAuthn", "social login" — giving good coverage of common variations, matching the score-3 anchor.

3 / 3

Distinctiveness Conflict Risk

The three named platforms (Auth0, Clerk, Firebase Auth) plus specific feature triggers carve a clear niche unlikely to conflict with other skills, matching the score-3 anchor for a clear distinct niche.

3 / 3

Total

11

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
modu-ai/moai-adk
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.