CtrlK
BlogDocsLog inGet started
Tessl Logo

netlify-identity

Add user authentication to a Netlify site with @netlify/identity — signup/login/logout, Google/GitHub/GitLab/Bitbucket OAuth, server-side getUser() checks, role-based access control, and Identity event functions. Use it when a task involves adding a login or signup form, gating content to members or roles, "auth middleware" or verifying users in Netlify Functions or Edge Functions, handling OAuth or email-confirmation callbacks, assigning roles at signup, or customizing Identity emails. For locking a whole site to your company or employees-only access, use netlify-access-control instead.

69

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, highly actionable reference with executable code throughout, explicit failure handling, and genuine one-level-deep bundle references. The main costs are the duplicated house-rules section that re-states earlier callouts and an undocumented getSettings() that the body nonetheless instructs the agent to call.

Suggestions

Delete or deduplicate the trailing "Netlify house rules (identity)" section — rules 2–8 restate the netlify dev, dashboard-only, raw-OAuth, v2-function, getSettings, and site-gating callouts already present earlier in the body; keep each rule in exactly one place.

Document getSettings() (signature and return shape) next to the instruction to call it at startup, or point to where it is documented — the body's own gap comment flags this as missing, and an agent following the instruction cannot render provider buttons without knowing what it returns.

Move dashboard-only configuration detail — email template variables/constraints, audit-log search terms, and external JWT provider requirements — into a reference file (e.g., references/configuration.md) and link to it, shortening the main body to the auth patterns an agent needs at a glance.

DimensionReasoningScore

Conciseness

The body is dense and mostly high-value with no padding of concepts Claude already knows, but the trailing "Netlify house rules (identity)" section (rules 2–8) restates the `netlify dev`, dashboard-only, raw-OAuth, v2-functions, getSettings, and site-gating warnings already given as callouts earlier in the file — roughly 35 lines of duplication. That is more than the "minor instances" of the score-4 anchor, fitting the score-3 anchor ("mostly efficient but includes some unnecessary explanation or could be tightened").

3 / 5

Actionability

Guidance is overwhelmingly executable: install command, copy-paste-ready client auth calls, a `handleAuthCallback()` landing-page snippet, complete v2 Function examples with imports, role checks, `verifyRequestOrigin(req)` CSRF usage, typed event handlers, and concrete `_redirects`/`netlify.toml` RBAC configs. It falls short of the score-5 anchor because `getSettings()` is mandated ("Call getSettings() at startup and render the signup form and OAuth buttons from what it returns") without its signature or return shape being documented — a gap the file itself flags — and framework examples are deferred entirely to an external README.

4 / 5

Workflow Clarity

Sequences are clear with most checkpoints present: the mandatory `handleAuthCallback()` on the landing page, the oauthLogin → callback flow, signup → confirmation → login, and an explicit "On failure — stop, don't guess" error-recovery section that names the error, dashboard URL, and setting to check before stopping. Not 5 because guidance is organized topically rather than as a sequenced onboarding path, and a few checkpoints (e.g., verifying Identity is enabled before coding, testing on a deploy) are implicit rather than explicit steps; not 3 because the failure-recovery loop and per-runtime constraints are explicit.

4 / 5

Progressive Disclosure

The two deep guides (SSR/session hydration, authorization-and-sessions) are correctly split into real, one-level-deep reference files clearly signaled from the body ("Deep guides ... live in references/advanced-patterns.md and references/authorization-and-sessions.md"), and the full API reference is delegated to the package README — matching the score-4 anchor ("Good structure; most content is appropriately placed; references mostly clear"). It is not 5 because the references are signaled in only one sentence near the end of the Roles section, and dashboard configuration minutiae (email template variables, audit-log search terms, external JWT provider rules) plus the duplicated house-rules section are inlined in an already-long body where a reference file would keep the overview leaner.

4 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: concrete capability list, explicit and natural trigger phrases, third-person voice, and explicit boundary guidance against a neighboring skill. It aligns closely with the rubric's good-overall examples.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions with comprehensive coverage of the domain: "signup/login/logout, Google/GitHub/GitLab/Bitbucket OAuth, server-side getUser() checks, role-based access control, and Identity event functions". It matches the score-5 anchor ("Lists multiple specific concrete actions; comprehensive coverage") rather than 4, since there are no meaningful capability gaps for Netlify Identity work.

5 / 5

Completeness

It explicitly answers both questions: the "what" ("Add user authentication to a Netlify site with @netlify/identity — signup/login/logout, ... role-based access control, and Identity event functions") and an explicit "Use it when a task involves..." trigger clause with concrete phrases. It exceeds the score-5 anchor example by also adding boundary routing ("For locking a whole site to your company or employees-only access, use netlify-access-control instead").

5 / 5

Trigger Term Quality

Natural user phrasings are comprehensively covered: "adding a login or signup form", "gating content to members or roles", "auth middleware", "verifying users", "handling OAuth or email-confirmation callbacks", "assigning roles at signup", "customizing Identity emails" — including synonyms (login/signup, OAuth/external providers) and the exact technical terms a user would say. Not 4 because no common variation for this domain is missing.

5 / 5

Distinctiveness Conflict Risk

It occupies a clear niche (Netlify + @netlify/identity) with distinct triggers (Netlify Functions, Edge Functions, Identity emails, OAuth callbacks) and explicitly resolves the one real adjacent-skill conflict by routing site-gating requests to netlify-access-control. This is the score-5 anchor ("Clear niche with distinct triggers; minimal conflict risk"), not 4, because it actively disambiguates rather than merely being mostly distinct.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
netlify/context-and-tools
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.