CtrlK
BlogDocsLog inGet started
Tessl Logo

accessible-authentication

Use when reviewing sign-in, sign-up, MFA, CAPTCHA, recovery, and re-auth flows. Evaluate the full authentication path, including error handling and backup methods, not just the primary login form.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/accessible-authentication/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured overview with concrete review guidance and a properly signaled one-level reference file that delivers what it promises. The main costs are the near-duplicate 'Code Review' section (token waste and workflow ambiguity) and the absence of any fix-verification step in the body.

Suggestions

Remove or merge the 'Code Review' section into 'Check' — both instruct the reviewer to flag memorization, transcription, and blocked tooling in auth flows, so the duplication adds tokens without new guidance.

Add a verification step after 'Fix' — e.g., 'Verify fixes against the automated and manual checks in `references/rule.md`' — to close the workflow's validation gap.

State the memorization/transcription rule once (in Quick Reference) and have 'Check' build on it rather than repeating the phrasing again in 'Code Review'.

DimensionReasoningScore

Conciseness

The Quick Reference bullets and the Fix section are tight and useful, but the "Code Review" section ("Review authentication pages, MFA steps, recovery flows, and security controls... Flag exact steps that require memorization, transcription, blocked assistive tooling") nearly duplicates the Check section, and the memorization/transcription rule is stated three times. Mostly efficient but includes unnecessary repetition that could be tightened — matches the 3 anchor rather than 4's 'only minor trimming needed'.

3 / 5

Actionability

Concrete, executable guidance for a review skill: "Support OTP autofill and paste with appropriate semantics such as `autocomplete="one-time-code"`", "Do not block paste or password managers", "Add password-manager-friendly fields", and a specific list of things to flag. Not a 5 because inline code examples and specifics of what compliant fields look like are deferred entirely to the reference file, leaving minor gaps.

4 / 5

Workflow Clarity

A Check → Fix → Explain sequence is present and each step has concrete content, but there are no validation checkpoints (e.g., nothing verifies that a fix resolves the flagged issue — the Verification section exists in references/rule.md but is never surfaced), and the redundant "Code Review" section runs parallel to "Check", muddying which workflow to follow. This matches 'steps listed but validation gaps' rather than 4's 'most checkpoints present'.

3 / 5

Progressive Disclosure

The body is a clear overview (Quick Reference, Check, Fix, Explain) with a well-signaled, one-level-deep reference: "For full implementation details, code examples, and framework-specific guidance, see `references/rule.md`" — and references/rule.md exists and contains exactly that (HTML/React code examples, best practices, standards, verification checks). Content is appropriately split with easy navigation.

5 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: explicit 'Use when' triggers with concrete natural keywords, and a clear statement of what the skill evaluates. The main weaknesses are missing common synonyms (log in, 2FA, two-factor) and the unstated accessibility angle, which slightly blurs its distinction from general auth-security review skills.

DimensionReasoningScore

Specificity

The description lists several concrete review targets — "reviewing sign-in, sign-up, MFA, CAPTCHA, recovery, and re-auth flows" and "Evaluate the full authentication path, including error handling and backup methods, not just the primary login form" — which matches the anchor for several specific actions with minor gaps. It stays below 5 because the only actions named are reviewing/evaluating; no other capability (e.g., fixing or explaining) is stated.

4 / 5

Completeness

Both halves are explicit: "Use when reviewing sign-in, sign-up, MFA, CAPTCHA, recovery, and re-auth flows" gives concrete trigger phrases, and "Evaluate the full authentication path, including error handling and backup methods, not just the primary login form" clearly states what the skill does. This matches the anchor for clearly and explicitly answering both what and when.

5 / 5

Trigger Term Quality

Strong natural keywords users would actually say: "sign-in", "sign-up", "MFA", "CAPTCHA", "recovery", "re-auth", and "login form". It falls at 4 rather than 5 because common synonyms are missing — "log in", "two-factor", "2FA", "password reset" — though coverage is otherwise good.

4 / 5

Distinctiveness Conflict Risk

The auth-flow review niche is distinct with specific triggers (MFA, CAPTCHA, recovery, re-auth), so conflict risk is low. It is not a 5 because the description never mentions the accessibility focus (despite the skill name and metadata), so it would also trigger for general security reviews of login flows — minor overlap with closely related skills.

4 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.