CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-implementation-patterns

Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices.

33

Quality

28%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/antigravity-awesome-skills-claude/skills/auth-implementation-patterns/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

35%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill reads as a high-level table of contents rather than actionable guidance. It lacks any concrete code examples, specific commands, or executable patterns for authentication/authorization implementation. The entire value proposition is deferred to a referenced playbook file that doesn't exist in the bundle, leaving the skill body with almost no practical utility.

Suggestions

Add at least one concrete, executable code example for a common auth pattern (e.g., JWT token validation middleware, session setup, or password hashing) directly in the SKILL.md body.

Replace the abstract instruction bullets ('Choose auth strategy', 'Design authorization model') with specific decision criteria and concrete implementation steps, including validation checkpoints for security-sensitive operations.

Include the referenced `resources/implementation-playbook.md` in the bundle, or inline the most critical patterns so the skill is useful even without the external file.

Remove the generic 'Limitations' section—these are standard Claude behaviors that don't need restating and consume token budget.

DimensionReasoningScore

Conciseness

The skill is relatively brief but includes some unnecessary sections like 'Use this skill when' / 'Do not use this skill when' which are meta-guidance Claude doesn't need spelled out at this length. The 'Limitations' section restates generic advice Claude already knows.

2 / 3

Actionability

The instructions are entirely abstract and high-level ('Choose auth strategy', 'Design authorization model') with no concrete code, commands, specific examples, or executable guidance. It describes what to do conceptually but never shows how.

1 / 3

Workflow Clarity

There is a rough sequence in the instructions (define → choose → design → plan → open playbook), but no validation checkpoints, no feedback loops, and no concrete steps. For a security-sensitive domain involving credential storage and token lifecycle, the lack of verification steps is a significant gap.

2 / 3

Progressive Disclosure

The skill references `resources/implementation-playbook.md` for detailed patterns, which is good progressive disclosure structure. However, no bundle files were provided, so the referenced file doesn't exist, and the SKILL.md itself provides almost no substantive content—it's essentially an empty shell pointing to a missing resource.

2 / 3

Total

7

/

12

Passed

Description

22%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This description reads more like a marketing tagline than a functional skill description. It relies heavily on buzzwords ('secure', 'scalable', 'industry-standard', 'modern best practices') without specifying concrete actions or providing any trigger guidance for when Claude should select this skill. The core domain of auth is identifiable but insufficiently detailed.

Suggestions

Add a 'Use when...' clause with explicit trigger terms like 'login', 'sign-in', 'OAuth', 'JWT', 'SSO', 'session management', 'permissions', 'RBAC', 'password hashing'.

Replace vague phrases like 'industry-standard patterns and modern best practices' with specific actions such as 'Implements JWT-based authentication, OAuth2 flows, role-based access control, session management, and password hashing.'

Remove marketing-style adjectives ('secure', 'scalable') and instead describe the concrete outputs or configurations the skill produces.

DimensionReasoningScore

Specificity

The description uses vague, buzzword-heavy language like 'secure, scalable', 'industry-standard patterns', and 'modern best practices' without listing any concrete actions. It doesn't specify what actions are performed (e.g., implement JWT tokens, configure OAuth flows, set up RBAC).

1 / 3

Completeness

The 'what' is vaguely stated as 'build authentication and authorization systems' without specifics, and there is no 'when' clause or explicit trigger guidance at all. The missing 'Use when...' clause would cap this at 2 regardless, but the weak 'what' brings it to 1.

1 / 3

Trigger Term Quality

It includes 'authentication' and 'authorization' which are natural terms users would say, but misses common variations like 'login', 'sign-in', 'OAuth', 'JWT', 'SSO', 'password', 'permissions', 'roles', 'RBAC', 'session management'.

2 / 3

Distinctiveness Conflict Risk

The auth domain is somewhat specific, but 'build secure, scalable systems' is generic enough to overlap with security-focused skills, API development skills, or general backend development skills. The lack of concrete scope boundaries increases conflict risk.

2 / 3

Total

6

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.