CtrlK
BlogDocsLog inGet started
Tessl Logo

convex-auth

Add authentication (passkeys/OAuth) to the current Convex app, including the auth.config.ts wiring.

60

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/convex-auth/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is concise, highly actionable, and well-structured with a clear sequenced workflow and a verification checkpoint. Minor duplication between Workflow and Rules and the absence of an explicit error-recovery loop keep it just short of perfect.

DimensionReasoningScore

Conciseness

Lean and assumes Claude's competence, but the Rules section restates the keygen, wizard-warning, and shadcn guidance already in the Workflow, which is minor duplication that could be trimmed.

4 / 5

Actionability

Fully executable, copy-paste-ready commands throughout: the jose keygen one-liner, `pnpm add jose`, `npx shadcn@latest add`, and MCP `envSet`/CLI `env set` forms with their exact gotchas.

5 / 5

Workflow Clarity

A clear 6-step sequence with an explicit verify checkpoint (step 6 / 'Verify a real sign-in works before finishing'), but it lacks a structured validate->fix->retry error-recovery loop.

4 / 5

Progressive Disclosure

Under 50 lines, single-purpose, with well-organized Workflow and Rules sections and no external references needed — matching the rubric's simple-skill exception for a top score.

5 / 5

Total

18

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and clearly Convex-scoped with concrete actions, but it omits any 'when to use' trigger guidance and common synonyms like login/sign-in. It is solid but incomplete as a trigger description.

Suggestions

Add a 'Use when...' clause, e.g. 'Use when adding login or sign-in to a Convex app'.

Include natural synonyms users say ('login', 'sign-in') alongside 'authentication'.

Mention the remaining concrete pieces (client hooks, sign-in UI) to raise coverage.

DimensionReasoningScore

Specificity

Names the domain ("authentication (passkeys/OAuth)" for a "Convex app") and two concrete actions (add auth, wire "auth.config.ts"), but coverage is not comprehensive — client hooks, sign-in UI, and key generation mentioned in the body are absent.

3 / 5

Completeness

The 'what' is clear (add passkeys/OAuth auth + auth.config.ts wiring), but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

Relevant keywords like "authentication", "passkeys", and "OAuth" are present, but common natural synonyms such as "login" or "sign-in" that users would actually say are missing.

3 / 5

Distinctiveness Conflict Risk

The Convex-specific scope plus passkeys/OAuth and auth.config.ts make it mostly distinct with minimal overlap risk against generic auth skills, though it lacks an explicit use-when trigger.

4 / 5

Total

13

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openclaw/clawhub
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.