CtrlK
BlogDocsLog inGet started
Tessl Logo

webiny-admin-security-catalog

admin/security — 15 abstractions.

53

Quality

67%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/user-skills/generated/admin/security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an efficient, well-structured pointer catalog: a terse usage workflow followed by 15 entries with copy-paste imports and exact source paths. It leans appropriately on the source files for interfaces rather than inlining them. The only structural gap is that the entire catalog lives inline in SKILL.md with no reference files to split the payload.

DimensionReasoningScore

Conciseness

The body is a lean catalog: a three-step usage instruction ('Find the abstraction you need below', 'You MUST read the source file to get the exact interface and types!') followed by pure reference data with no padded prose or explanation of concepts Claude already knows. Every line is either an entry name, a copy-paste import, or a source path, so every token earns its place.

5 / 5

Actionability

Each entry provides a copy-paste-ready import statement ('import { AuthenticationContext } from "webiny/admin/security"') and an exact source path to read, which is concrete and executable guidance. It falls short of anchor 5 only in that no signatures or usage snippets are inlined, deferring entirely to the source files.

4 / 5

Workflow Clarity

This is a simple single-purpose lookup skill and its workflow ('1. Find the abstraction you need below / 2. You MUST read the source file / 3. Import: ...') is numbered and completely unambiguous. No destructive or batch operations are involved, so no validation checkpoints are required and the simple-skill exception applies.

5 / 5

Progressive Disclosure

The body has clear structure ('How to Use' and 'Abstractions' sections separated by rules) and each entry's Source path is a clearly labeled one-level pointer to a real file in the codebase. It scores below anchor 5 because at 103 lines the catalog is monolithic in a single SKILL.md with no split or external reference files, and the under-50-line exception for scoring 5 on sections alone does not apply.

4 / 5

Total

18

/

20

Passed

Description

28%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a bare domain label plus an inventory count. It fails to state what the skill does, when to use it, or include any natural trigger terms, though it does carve out a distinct niche. Almost all of the evaluative work is left to the reader's inference.

Suggestions

State what the skill does in third person, e.g., 'Catalogs the 15 security abstractions of the Webiny admin app (authentication, identity, permissions) with import paths and source locations.'

Add an explicit 'Use when...' clause covering natural triggers such as: working with Webiny admin security, permissions checks, login/logout flows, or identity/auth context hooks.

Replace the jargon term 'abstractions' with concrete user-facing keywords (permissions, authentication, login, identity) so the description matches what a user would naturally say.

DimensionReasoningScore

Specificity

The description 'admin/security — 15 abstractions.' names the domain (admin/security) and a count, but contains no action verbs whatsoever. It names the domain without any concrete actions, matching the anchor 'Names the domain but actions are minimal or generic' rather than anchor 1, since a concrete module scope is given rather than pure abstract language like 'Helps with documents'.

2 / 5

Completeness

There is no 'Use when...' clause or equivalent trigger guidance, which caps completeness at 3, and the 'what' is only a vague inventory count ('15 abstractions') rather than any statement of purpose. This matches anchor 2: 'Has a vague what and no when'.

2 / 5

Trigger Term Quality

'admin' and 'security' are somewhat natural terms, but 'abstractions' is technical jargon users would not say, and common natural phrases a user would actually use ('permissions', 'login', 'identity', 'authentication') are missing. This sits between anchor 2 (generic keywords, missing natural phrases) and anchor 3, closer to 2 because the operative noun is jargon.

2 / 5

Distinctiveness Conflict Risk

'admin/security' delineates a real niche within a Webiny codebase, so it is not broadly generic, but without any trigger phrases it could still overlap with other security or admin-related skills. This matches anchor 3: 'Somewhat specific but could still overlap with similar skills'.

3 / 5

Total

9

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
webiny/webiny-js
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.