CtrlK
BlogDocsLog inGet started
Tessl Logo

netlify-access-control

Picks the right Netlify site-protection layer and disambiguates the three unrelated "auth" concepts users conflate — app-user login (Netlify Identity), site-load gating (Password Protection / project visibility), and dashboard SAML SSO. Use it when asked to password-protect a site or Deploy Preview, make a project private/public, restrict a site to your team, require SSO to view a site, set up company-wide app SSO, or invite users to a private project. Also use it for SSO-session symptoms on protected sites: "logged out mid-session", 401s after about an hour, or token expiry/refresh questions. Not for wiring auth code — route app-login setup to netlify-identity.

72

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured routing body: it disambiguates first, maps each user request to a named feature, and gives exact dashboard paths plus plan/role constraints Claude cannot know. Its main weakness is redundancy — the trailing ctx-gen 'house rules' section repeats nearly every rule already stated in the body, roughly doubling the token cost of the same guidance.

Suggestions

Deduplicate the trailing 'Netlify house rules (access-control)' section against the body: it repeats the no-API rule, the three auth layers, the double-login footgun, the Auth0 recommendation, the Reviewer remedy, and the who-can-change list that all already appear above — keep each fact in one place only.

Promote references/two-layer-pattern.md to a short dedicated section (e.g. '## Layered pattern') so the bundle's deeper content is discoverable at a glance instead of only via two inline mentions.

Add a one-line verification checkpoint to the routing workflow (e.g. 'confirm the target layer against the user's plan tier before recommending, since Password Protection scope and visibility options are plan-gated') so the disambiguation step ends in an explicit check rather than implied ones.

DimensionReasoningScore

Conciseness

The primary body is dense with facts Claude does not know (exact UI paths, plan gating, role permissions, token expiry behavior) and explains nothing Claude already knows, but the appended "Netlify house rules (access-control)" section substantially duplicates the body above it — the no-API rule, the three auth layers, the double-login footgun, the Auth0 recommendation, the Reviewer remedy, and the who-can-change list all appear twice. Mostly efficient with one large padded/duplicated section; not a 2 because the padding is duplication of genuinely useful content rather than explanation of known concepts, and not a 4 because ~40% of the file repeats earlier content that could be tightened away.

3 / 5

Actionability

Guidance is fully executable for a UI-path skill: exact dashboard URLs ("Project configuration > General > Visitor access > Project visibility" with app.netlify.com links), step-by-step menu sequences, a decision table mapping each request to a named feature, a legacy-to-credit mapping row, and a copy-paste-ready JS snippet for the 401/expiry symptom. This matches the fully-executable anchor; a 4 would require minor gaps, and none are evident.

5 / 5

Workflow Clarity

The routing workflow is clearly sequenced: "First: disambiguate 'auth' — three unrelated layers" then a decision guide, then distinctions, then UI paths, then constraints, with failure handling ("On failure, report what you tried and stop"). This fits the clear-sequence anchor with minor gaps; not a 5 because there are no explicit validation checkpoints or feedback loops beyond the failure-report instruction, and not a 3 because the sequence is coherent and the risky-path instruction (never curl the API, hand over the dashboard path) is explicit.

4 / 5

Progressive Disclosure

The single bundle file, references/two-layer-pattern.md, exists on disk, is referenced clearly and appropriately ("For the combined layered pattern and its tradeoffs, see references/two-layer-pattern.md"), and is exactly one level deep with the deeper pattern correctly offloaded. Good structure overall; not a 5 because the reference is only an inline mention with no dedicated navigation section, and the duplicated merged org-rules block inflates SKILL.md itself rather than living in a separate file.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary routing-skill description: third person, concrete actions, an explicit and comprehensive 'Use it when' clause covering both setup and symptom triggers, and an explicit negative scope routing adjacent work to netlify-identity. Every clause carries a trigger or a boundary.

DimensionReasoningScore

Specificity

"Picks the right Netlify site-protection layer and disambiguates the three unrelated 'auth' concepts" names the domain and multiple concrete actions (layer selection, three-way disambiguation, routing app-login setup elsewhere), with the three concepts individually enumerated. This matches the anchor for multiple specific concrete actions with comprehensive coverage; it is not a 4 because no meaningful action within its scope is missing.

5 / 5

Completeness

Both what ("Picks the right Netlify site-protection layer and disambiguates the three unrelated 'auth' concepts") and when ("Use it when asked to...", "Also use it for SSO-session symptoms on protected sites") are explicitly stated with concrete trigger phrases, plus an explicit negative boundary ("Not for wiring auth code — route app-login setup to netlify-identity"). This is the anchor-5 pattern; a 4 would require the 'when' to be less explicit, which it is not.

5 / 5

Trigger Term Quality

Triggers are natural user phrasing: "password-protect a site or Deploy Preview", "make a project private/public", "restrict a site to your team", "invite users to a private project", plus symptom phrasings users actually report ("logged out mid-session", "401s after about an hour", "token expiry/refresh questions"). Coverage including synonyms and symptom variants matches the comprehensive anchor; it is above the 4 anchor because it covers both setup requests and troubleshooting vocabulary.

5 / 5

Distinctiveness Conflict Risk

Clear niche (Netlify site-protection layer selection) with distinct triggers, and the adjacent-skill overlap (netlify-identity) is explicitly disambiguated in the description itself. Minimal conflict risk; not a 4 because the overlap with the closest related skill is already resolved in-scope.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
netlify/context-and-tools
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.