CtrlK
BlogDocsLog inGet started
Tessl Logo

neon-auth

Add authentication to a new app. Use for "add auth", "add login", Neon Auth (Managed Better Auth), identity routing, sign-up, sign-in, password reset, email OTP, magic links, organizations, phone OTP, OAuth, passkeys, MFA, trusted domains, invalid domain, and @neondatabase/auth. No existing identity: default to Managed Better Auth. Keep working Better Auth, Clerk, Supabase Auth, or another IdP. User asked to migrate from Supabase Auth: Managed Better Auth. A required plugin outside Managed support: self-managed Better Auth on a Neon Function or the existing app host. Also use for auth APIs in @neondatabase/neon-js.

76

Quality

97%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exemplary skill body: lean, decision-first prose carrying only non-obvious Neon-specific facts, copy-paste setup and CLI commands, an explicit verification checklist, and a clean two-file reference split for implementation detail. The inline Supabase-migration inventory and plugin matrix are justified because they drive identity-routing decisions rather than pad the overview.

DimensionReasoningScore

Conciseness

Telegraphic and dense with non-obvious, product-specific constraints ('Password hashes cannot transfer', 'updateUser() cannot change email or password', 'A missing auth.phoneNumber server method is a missing typed helper, not a proxy rejection'); nothing explains concepts Claude already knows. The one date ('Checked 2026-09-17') is a freshness marker paired with a re-fetch instruction, not a dated API switch, so it does not warrant the time-sensitivity penalty.

5 / 5

Actionability

Copy-paste-ready config (defineConfig({ auth: true })), executable commands (neon deploy, neon neon-auth status, neon neon-auth domain add/list/delete), and exact method chains (".token() then data.token", 'getSession() then data.session.access_token'). Framework-specific implementation is delegated to real reference files at the point of need. Not a 4 because the common cases (managed setup, domain fixes, plugin routing) are each executable end-to-end.

5 / 5

Workflow Clarity

Clear sequence: inspect existing identity and required features, route via the situation table, merge auth into neon.ts, deploy, then implement login via the reference. Explicit validation checkpoint in the Verification section (sign-up, sign-in, sign-out, session restoration after reload, protected access, error and loading states, email verification) with a feedback instruction to 'Report any flow that remains unverified'. Not a 4 because checkpoints are explicit and enumerated, not implicit.

5 / 5

Progressive Disclosure

The body keeps identity routing, availability constraints, and the plugin matrix inline where they drive decisions, and delegates implementation depth to two real, well-signaled, one-level-deep references (managed-auth.md, self-managed.md) linked at the point of need; the deep-linked anchor (#organization-invitations) resolves to a real heading and neither reference nests further. Not a 4 because the split follows a consistent principle (decisions inline, how-to in references) with no orphaned or buried references.

5 / 5

Total

20

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, dense description: explicit what-and-when with quoted natural triggers, package-name disambiguation, and routing rules that prevent both missed and wrong-skill invocations. The only soft spot is that the middle portion lists feature names and routing cases rather than a broader set of concrete actions.

DimensionReasoningScore

Specificity

Opens with a concrete action ('Add authentication to a new app') and follows with concrete decision routing ('No existing identity: default to Managed Better Auth', 'Keep working Better Auth, Clerk, Supabase Auth, or another IdP'). Not a 5 because the remaining lists (password reset, email OTP, magic links, passkeys, MFA) name features and trigger terms more than additional concrete actions.

4 / 5

Completeness

Explicitly answers what ('Add authentication to a new app... Neon Auth (Managed Better Auth)') and when ('Use for "add auth", "add login", ...') with concrete quoted trigger phrases. Not a 4 because the when-clause is maximally explicit, including edge-case triggers, rather than merely serviceable.

5 / 5

Trigger Term Quality

Comprehensive natural-language triggers users would actually say ('add auth', 'add login', 'migrate from Supabase Auth') with synonym coverage (sign-up/sign-in/login/auth) and package identifiers (@neondatabase/auth, @neondatabase/neon-js). Nothing common is missing; not a 4 because even error-state phrases ('invalid domain', 'trusted domains') are covered.

5 / 5

Distinctiveness Conflict Risk

Clear niche (Neon Auth / @neondatabase packages) with distinct triggers, and it actively reduces conflict risk by instructing to keep working Better Auth, Clerk, Supabase Auth, or another IdP rather than hijacking them. Not a 4 because the boundary guidance against wrong-skill triggering is explicit, not just implied by specificity.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
stevenknowswhy/ProfessionalBuyer
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.