CtrlK
BlogDocsLog inGet started
Tessl Logo

claims

Claims-based authorization for agents and operations. Grant, revoke, and verify permissions for secure multi-agent coordination. Use when: permission management, access control, secure operations, authorization checks. Skip when: open access, no security requirements, single-agent local work.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/claims/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an efficient, command-rich reference with good section structure. Its weakest area is workflow clarity: the claim lifecycle (grant → verify → use → revoke) has no validation checkpoints, and the federated tool set is named without usage examples.

Suggestions

Add a short claim-lifecycle workflow with validation, e.g. after granting: check the claim with `npx claude-flow claims check` and only proceed when it returns the expected claim, and verify revocation succeeded before assuming access is removed.

Give one-line invocation examples for the runtime tools (`claims_claim`, `claims_release`, `claims_handoff`) the way the CLI commands have them, so the federated section is executable rather than nominal.

Move the federated reduction rules and channel-scoping caveats into a reference file (e.g. references/federation.md) and keep a brief summary with a clearly signaled pointer in SKILL.md.

DimensionReasoningScore

Conciseness

The body is dominated by lean tables and copy-paste commands with almost no concept explanation, fitting 'efficient; minor instances of over-explanation that could be trimmed'. Not 5 because the Best Practices list ('principle of least privilege', 'revoke claims when no longer needed') restates what Claude already knows, and the version tag '(v3.40.0+)' is time-sensitive detail placed outside any deprecation section.

4 / 5

Actionability

Concrete executable commands like `npx claude-flow claims grant --agent agent-123 --claim write --scope "/src/**"` cover the core operations, matching 'mostly executable guidance; concrete code or commands with minor gaps'. Not 5 because the runtime tools (`claims_claim`, `claims_handoff`, `claims_steal`) are listed by name only with no invocation examples.

4 / 5

Workflow Clarity

A partial sequence exists ("claim, sync, and proceed only if you are the acknowledged owner") but there are no validation checkpoints — nothing like verifying a claim took effect after granting, or checking ownership before revoking. Since granting/revoking claims are security-sensitive operations without validation steps, the rubric's cap of 3 applies; not 2 because the ordering and ownership rules are stated coherently.

3 / 5

Progressive Disclosure

Sections are well organized with clear tables and explicit signposting to external material ("See the `cross-host-federation` skill", "See the `open-federation` skill for channel mechanics"), fitting 'good structure; most content is appropriately placed'. Not 5 because the dense federated-reduction rules and channel-scoping blocks (~40 lines) are advanced content inlined in SKILL.md rather than split into a reference file, and no bundle files exist to offload them.

4 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, explicit what/when/skip-when structure, and concrete action verbs. Its main gaps are missing common synonyms (e.g., 'permissions', 'RBAC') and not naming the concrete claim types it manages.

DimensionReasoningScore

Specificity

"Grant, revoke, and verify permissions for secure multi-agent coordination" lists several concrete actions, matching the 'lists several specific actions; minor gaps in coverage' anchor. Not 5 because it stops short of naming the concrete claim types or resources it works with; not 3 because it goes beyond 1-2 actions.

4 / 5

Completeness

It explicitly answers what ("Claims-based authorization for agents and operations. Grant, revoke, and verify permissions") and when ("Use when: permission management, access control, secure operations, authorization checks"), with a bonus "Skip when" clause — concrete trigger phrases on both sides.

5 / 5

Trigger Term Quality

"permission management, access control, secure operations, authorization checks" are natural phrases a user would say, fitting 'good keyword coverage; a few natural terms missing'. Not 5 because variations like 'permissions', 'RBAC', or 'grant access' are absent.

4 / 5

Distinctiveness Conflict Risk

"Claims-based authorization" carves a clear niche distinct from generic security skills, fitting 'mostly distinct; minor overlap risk'. Not 5 because triggers like "access control" and "secure operations" are broad enough to overlap with other security or permissions skills.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ruvnet/ruflo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.