CtrlK
BlogDocsLog inGet started
Tessl Logo

auth-testing

Test OAuth2 token refresh and session expiry locally. Use when working on auth, tokens, SSO, OIDC, or session management features.

88

1.11x
Quality

83%

Does it follow best practices?

Impact

100%

1.11x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete commands, config snippets, and clear numbered test scenarios. Conciseness dips slightly from restating well-known session/token concepts, and workflows lack explicit pass/fail validation checkpoints.

Suggestions

Trim the 'How it works' and 'Difference from token expiry' sections to the non-obvious specifics, since session/token expiry mechanics are generally known.

Add an explicit validation step to each test scenario (e.g., 'Pass: /auth/refresh returns 200 with new token; Fail: 401 or no refresh request') so outcomes are unambiguous.

Move the 'Current Default Values' and 'Key Relationships' reference tables into a separate references file if the skill grows, to keep the overview lean.

DimensionReasoningScore

Conciseness

Mostly efficient with concrete tables and code blocks, but sections like 'How it works' and the maxSessionDuration explanation restate concepts Claude likely already knows about session/token mechanics.

3 / 5

Actionability

Fully executable guidance: exact commands (pnpm dev:with-auth, curl endpoints), concrete config snippets with file paths, and copy-paste ready YAML/TypeScript edits.

5 / 5

Workflow Clarity

Testing scenarios are clearly numbered with concrete steps and explicit config precondition statements, but there is no validation checkpoint confirming the observed behavior constitutes pass/fail.

4 / 5

Progressive Disclosure

Well-organized sections with clear headers and a Related Files index; no bundle files exist so all content is appropriately inline, with only minor bulk that could in principle be split.

4 / 5

Total

16

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: concrete actions, comprehensive natural trigger terms, explicit what-and-when guidance, and a clearly distinct niche. Minor room for broader action coverage but otherwise excellent.

DimensionReasoningScore

Specificity

Names concrete actions ('Test OAuth2 token refresh and session expiry locally') but covers only two test behaviors rather than a comprehensive action set.

4 / 5

Completeness

Explicitly answers both what ('Test OAuth2 token refresh and session expiry locally') and when ('Use when working on auth, tokens, SSO, OIDC, or session management features'). Uses third person.

5 / 5

Trigger Term Quality

Comprehensive natural trigger coverage including 'auth, tokens, SSO, OIDC, or session management' — terms users would naturally say.

5 / 5

Distinctiveness Conflict Risk

Clearly scoped niche (OAuth2/OIDC token refresh and session expiry testing) with distinct triggers unlikely to conflict with other skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
temporalio/ui
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.