CtrlK
BlogDocsLog inGet started
Tessl Logo

agent-auth

Log a real human into a dev tool's CLI by opening the OAuth browser popup automatically and letting the login complete itself — no token copy-paste. Use when you need to log in to / authenticate a CLI, when a command like `sanity login` or `netlify login` opens a browser, or on any interactive login / OAuth popup. You make the popup appear and wait; the human just clicks Approve. You NEVER automate the browser or scrape tokens.

70

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A richly actionable, well-structured skill with excellent concrete commands and a clear workflow-plus-reference split. Its main weakness is conciseness: several steps are overloaded with inline parenthetical caveats that hurt scannability.

Suggestions

Break the wall-of-text steps (especially 1 and 4) into crisp sub-bullets and move rare edge-case caveats into references/providers.md or a short 'Pitfalls' section so the Fast-path stays scannable.

Extract the long `env -u` / `noninteractive` / `expect` recipes into a small code block per step rather than burying them mid-paragraph.

Trim redundant restatements of the same warning (e.g. the 'don't fire it repeatedly' / 'stay until it returns' / 'keep one session' cluster) into a single consolidated checkpoint.

DimensionReasoningScore

Conciseness

Expert-level content that avoids explaining basics Claude already knows, but several steps (notably 1 and 4) are single dense paragraphs stuffed with inline parenthetical caveats and em-dash asides that should be tightened or deferred, landing between 'mostly efficient' and 'noticeably verbose'.

3 / 5

Actionability

Fully executable, copy-paste-ready guidance throughout — concrete `env -u ... <cli> login` commands, a complete `expect -c` recipe, `npx noninteractive ...` PTY recipes, and worked Sanity/Netlify examples covering the common cases.

5 / 5

Workflow Clarity

A clear 5-step 'Fast-path (do this every time)' sequence with an explicit verify-identity checkpoint and feedback loops (read error → follow hint → device-code mode; wrong-account detection), slightly muddyed by the dense prose interleaving checkpoints with caveat dumps.

4 / 5

Progressive Disclosure

Good structure with clear section headers and a single one-level-deep reference (references/providers.md, verified real and well-organized) for per-provider detail; minor gap is the large amount of edge-case prose inlined in the body that could arguably live in references.

4 / 5

Total

16

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A precise, well-triggered description that clearly conveys both the capability and the activation conditions, with concrete command examples and a sharp non-automation boundary. The only blemish is a second-person clarifying sentence, which costs one specificity point under the rubric's voice rule.

DimensionReasoningScore

Specificity

Lists multiple concrete actions (auto-open OAuth popup, wait for completion, human clicks Approve, never scrape tokens or automate the browser), which is comprehensive; reduced from 5 per the rubric's second-person penalty for 'You make the popup appear and wait'.

4 / 5

Completeness

Explicitly answers both what (log a human into a CLI by auto-opening the OAuth popup, no token copy-paste) and when ('Use when you need to log in to / authenticate a CLI ... or on any interactive login / OAuth popup') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural trigger coverage — 'log in to / authenticate a CLI', concrete commands 'sanity login' / 'netlify login', 'opens a browser', 'interactive login / OAuth popup' — with synonyms and command-style triggers users actually say.

5 / 5

Distinctiveness Conflict Risk

Clear niche — human-in-the-loop OAuth browser-popup login for CLIs — with concrete trigger commands and an explicit 'NEVER automate the browser or scrape tokens' boundary that separates it from generic token/auth skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
team2027/2027-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.