CtrlK
BlogDocsLog inGet started
Tessl Logo

convex-setup-auth

Sets up Convex auth, identity mapping, and access control. Use for login, auth providers, users tables, protected functions, or roles in a Convex app.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, correctly disclosed skill: the overview routes to real per-provider references and the core identity-check pattern is shown as executable code. The main weakness is token efficiency - repeated provider lists, duplicated ask-the-user instructions, and a dense multi-gotcha paragraph that could be tightened into short bullets.

Suggestions

Cut the duplicate provider list: the "Common options" and "After Choosing a Provider" sections list the same four providers - keep one and drop the other, or merge them into a single table with reference-file pointers.

Split the dense paragraph at lines 99-108 into a short bulleted "Gotchas" list (one bullet per caveat: prefer official docs over memory, skip unneeded users tables, no storeUser for Convex Auth, verify post-init wiring).

Trim the checklist and the "First Step" ask-the-user instructions to remove items that restate workflow steps 1-2 verbatim, keeping each instruction in exactly one place.

DimensionReasoningScore

Conciseness

The body is mostly efficient, but the provider option list appears twice ("Common options" and "After Choosing a Provider"), the ask-the-user guidance is duplicated between "First Step" and Workflow step 1, the checklist restates workflow steps, and lines 99-108 cram six distinct gotchas into one dense prose block. This fits the 3 anchor (mostly efficient, some unnecessary explanation / could be tightened) better than the 4 anchor, since the redundancy is systematic rather than isolated.

3 / 5

Actionability

The Bad/Good code pair for ctx.auth.getUserIdentity() is executable and copy-paste ready for the most common task, and workflow steps are directives. It sits below the 5 anchor because concrete commands (installs, CLI invocations) are deferred to reference files rather than shown, leaving minor gaps.

4 / 5

Workflow Clarity

The 8-step workflow is clearly sequenced, includes a verification step ("Verify login state, protected queries, environment variables, and production configuration"), an explicit handling loop for blocked interactive setup, and a closing checklist. It falls short of the 5 anchor because verification is described rather than concrete, with no explicit fix-and-retry loop.

4 / 5

Progressive Disclosure

SKILL.md stays at routing altitude (choose provider, read the matching reference, follow official docs), keeps the shared core pattern inline, and points to four real one-level-deep reference files that are clearly signaled both in the workflow and in a dedicated "Reference Files" section. This matches the 5 anchor: clear overview, well-signaled references, content appropriately split.

5 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, explicit what and when, concrete capability and trigger terms, all correctly scoped to Convex. The only gap is modest synonym coverage (e.g., sign-in, authentication, logout) that would otherwise lift trigger-term quality to the top anchor.

DimensionReasoningScore

Specificity

"Sets up Convex auth, identity mapping, and access control" names the domain plus three concrete capabilities, and the trigger clause adds login, auth providers, users tables, protected functions, and roles. It is broader and more concrete than the 3 anchor's "1-2 concrete actions", but stops short of the 5 anchor's comprehensive coverage (no mention of login/logout UI wiring, env vars, or framework setup).

4 / 5

Completeness

The first sentence explicitly answers "what" ("Sets up Convex auth, identity mapping, and access control") and the second explicitly answers "when" ("Use for login, auth providers, users tables, protected functions, or roles in a Convex app") with concrete trigger phrases, matching the 5 anchor. It is well above the 4 anchor, where the "when" is present but less specific.

5 / 5

Trigger Term Quality

"login, auth providers, users tables, protected functions, or roles" are terms a user would naturally say when needing this skill. A few natural synonyms are missing ("sign-in", "log in", "authentication" spelled out, "logout"), which keeps it just below the 5 anchor's comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

Every trigger is scoped by "in a Convex app", giving the skill a clear niche that does not collide with generic auth or database skills. This matches the 5 anchor's clear niche with distinct triggers and minimal conflict risk.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openclaw/clawhub
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.