CtrlK
BlogDocsLog inGet started
Tessl Logo

agent-authentication

Agent skill for authentication - invoke with $agent-authentication

66

2.23x
Quality

48%

Does it follow best practices?

Impact

96%

2.23x

Average score across 3 eval scenarios

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/agent-authentication/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a solid agent-persona definition with a genuinely useful, concrete MCP toolkit and a coherent workflow, but it is held back by persona fluff, a duplicated frontmatter block, and a 'Validate' step that asserts validation without specifying what to check or how to recover. Tightening it to the toolkit plus a concretized workflow would lift it a full point.

Suggestions

Concretize the 'Validate Results' step: specify what to inspect in each tool's response (e.g., session/token fields from user_login, success/error codes) and name a recovery path for common failures (invalid credentials, expired reset token).

Delete the stray second frontmatter block (lines 6–10) — it duplicates metadata and belongs nowhere in the body.

Trim the fluff: drop the 'seamless/comprehensive' expertise sentence, the final 'always prioritize...' paragraph, and merge 'Quality standards' into the responsibilities list to cut ~15 lines of redundancy.

DimensionReasoningScore

Conciseness

The toolkit, workflow, and scenarios are tight, but there is measurable padding: "Your expertise lies in seamless user onboarding, secure authentication flows, and comprehensive account management" (marketing fluff), a redundant closing paragraph ("always prioritize security, user experience, and clear communication..."), a 'Quality standards' section that restates the responsibilities list, and a stray duplicated frontmatter block. This fits anchor 3 ('Mostly efficient but includes some unnecessary explanation or could be tightened'); it is not anchor 4 because several sections, not just minor phrases, could be trimmed.

3 / 5

Actionability

The toolkit gives concrete MCP tool calls with parameter shapes for the common cases (user_register, user_login, user_profile, user_update_profile, user_reset_password, user_update_password). Not anchor 5 because these are call signatures rather than complete executable examples — no response handling (e.g., what user_login returns, token/session usage), no real error examples, and placeholder values like "user_id" are unexplained.

4 / 5

Workflow Clarity

The 5-step sequence (Assess → Execute → Validate → Guidance → Security Check) is clearly listed, but the 'Validate Results' checkpoint is implicit and unexplained — 'Confirm authentication success and handle any error states' names validation without saying what to check (returned token? session_id? error code?) or how to recover. This matches anchor 3 ('Steps listed but validation gaps; checkpoints missing or implicit').

3 / 5

Progressive Disclosure

No bundle files exist and none are needed; the ~65-line body is divided into clear, well-labeled sections (responsibilities, toolkit, workflow, scenarios, standards) with no nested or buried references. This earns anchor 4 ('Good structure; most content is appropriately placed') rather than 5: it slightly exceeds the under-50-line simple-skill threshold and the stray second frontmatter block plus the inlined quality-standards list are minor organization gaps.

4 / 5

Total

14

/

20

Passed

Description

36%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a stub: it names a domain and an invocation token but gives no capabilities, no use-when triggers, and no natural user phrasing. Notably, a far richer description exists in a stray second frontmatter block in the body ("Flow Nexus authentication and user management specialist. Handles login, registration, session management...") that should replace the outer one.

Suggestions

Replace the outer description with the fuller one already present in the body's inner frontmatter, e.g. 'Handles user registration, login, session management, password reset, and profile updates via Flow Nexus MCP tools. Use when users need to sign in, register, reset a password, or manage account settings.'

Add an explicit 'Use when...' trigger clause listing natural phrases users would say: login, sign in / sign up, password reset, account recovery, session management.

State concrete capabilities (registration, login, password reset, email verification, profile updates) instead of the bare word 'authentication' so the skill is distinguishable from generic auth skills.

DimensionReasoningScore

Specificity

"Agent skill for authentication" names the domain but lists zero concrete actions — the only other phrase, "invoke with $agent-authentication", is an invocation instruction, not a capability. It matches the anchor 'Names the domain but actions are minimal or generic' (e.g. 'Processes PDF files'); it is above anchor 1 only because a concrete domain is named.

2 / 5

Completeness

There is a vague 'what' ("agent skill for authentication" — domain only, no actions) and no 'when' clause at all; "invoke with $agent-authentication" tells how to invoke, not when to use it. This matches anchor 2 ('Has a vague what and no when') and stays below 3, whose example still conveys several concrete capabilities.

2 / 5

Trigger Term Quality

"authentication" is a strong, natural keyword users would say, but no variations or synonyms appear — no 'login', 'sign in', 'password reset', 'registration', 'sessions', or 'user accounts' — and "$agent-authentication" is internal syntax no user would utter. This matches anchor 3 ('Some relevant keywords but missing common variations or synonyms') rather than 4, which requires broader keyword coverage.

3 / 5

Distinctiveness Conflict Risk

"authentication" is a somewhat specific domain, but with no differentiating detail the description would collide with any other auth, security, or account-management skill. This matches anchor 3 ('Somewhat specific but could still overlap with similar skills'); it lacks the distinct tool/capability list that anchor 4's example ('Works with PDF and Word document files') shows.

3 / 5

Total

10

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ruvnet/ruflo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.