CtrlK
BlogDocsLog inGet started
Tessl Logo

auth

Authentication integration guidance — Clerk (native Vercel Marketplace), Descope, and Auth0 setup for Next.js applications. Covers middleware auth patterns, sign-in/sign-up flows, and Marketplace provisioning. Use when implementing user authentication.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/vercel/skills/auth/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, code-first reference whose snippets are immediately executable across Clerk, Descope, and Auth0, with good structure and well-signaled cross-references. Its main weaknesses are the complete absence of validation/verification checkpoints in the setup flows and minor boilerplate redundancy.

Suggestions

Add a short verification step at the end of each provider's setup (e.g., 'Run `npm run dev` and confirm visiting /dashboard redirects to /sign-in when signed out') to close the workflow validation gap.

Trim the duplicated RootLayout boilerplate — show the full provider-wrapping example once and note that other providers follow the same pattern with their own Provider component.

Consider moving per-provider deep detail (e.g., the Clerk Core 3 breaking-changes list) into one-level-deep reference files under references/ to keep SKILL.md a leaner overview with clear navigation.

DimensionReasoningScore

Conciseness

The body is code-dominant with almost no explanation of concepts Claude already knows, but it includes minor trim targets: the full RootLayout boilerplate appears nearly identically for both Clerk and Descope, and dual install paths (Marketplace + npm) add slight redundancy. Efficient overall with minor over-explanation, matching anchor 4 rather than the every-token-earns-its-place anchor 5.

4 / 5

Actionability

Every section provides copy-paste-ready code or commands — install commands, middleware config, route protection, provider setup, sign-in/sign-up pages, env vars, and session access — covering the common cases across all three providers, which matches the fully-executable anchor.

5 / 5

Workflow Clarity

The per-provider sequence (install → middleware → provider → pages → access data) is present via section ordering, but there are no validation checkpoints anywhere (e.g., verify env vars were provisioned, confirm unauthenticated redirects work, check the dev server after setup), matching the anchor 'sequence present but checkpoints missing or implicit' rather than 'most checkpoints present'.

3 / 5

Progressive Disclosure

The file is well structured with clear per-provider sections, a decision matrix, clearly signaled cross-references ('⤳ skill: marketplace' etc.) and external doc links, but it is a ~316-line single file whose per-provider detail could plausibly be split into one-level-deep reference files; good structure with minor organization gaps rather than the ideal overview-plus-references split.

4 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that names the domain, three concrete providers, several specific capability areas, and an explicit 'Use when' clause in third person. It falls short of top marks only on trigger specificity and synonym coverage, which slightly limit both completeness and distinctiveness.

DimensionReasoningScore

Specificity

The description lists several concrete actions — 'setup', 'middleware auth patterns', 'sign-in/sign-up flows', and 'Marketplace provisioning' — but coverage is not comprehensive (no mention of session/user-data access or API route protection), matching the anchor for several specific actions with minor gaps rather than the comprehensive anchor.

4 / 5

Completeness

Both 'what' (integration guidance for three named providers covering specific areas) and 'when' ('Use when implementing user authentication') are present, but the trigger clause is generic and could be more specific by naming the providers or flows; not a 5 because the when-clause lacks concrete trigger phrases.

4 / 5

Trigger Term Quality

Natural terms users would say are present ('authentication', 'sign-in', 'sign-up', 'Clerk', 'Descope', 'Auth0', 'Next.js'), but a few common variations are missing ('login', 'OAuth', 'SSO'), placing it at good-but-not-comprehensive keyword coverage.

4 / 5

Distinctiveness Conflict Risk

The named providers create a mostly distinct niche, but the broad trigger 'implementing user authentication' carries minor overlap risk with closely related auth skills (e.g., sign-in-with-vercel, general OAuth), so it does not meet the clear-niche/minimal-conflict bar of a 5.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
openai/plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.