CtrlK
BlogDocsLog inGet started
Tessl Logo

webiny-api-security-catalog

API — Security & Auth — 53 abstractions. Authentication, API keys, roles, users, teams event handlers and use cases.

56

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/user-skills/generated/api/security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, uniformly structured catalog with copy-paste-ready imports and a clear lookup workflow — strong on actionability and token efficiency for its size. Its main weakness is structure: the entire 53-entry catalog is inlined in SKILL.md with no progressive disclosure into reference files, and a few entries lack descriptions.

Suggestions

Move the 53-entry catalog into a references/ file (e.g. references/abstractions.md) and keep SKILL.md as a short overview with the How-to-Use steps and a clearly signaled link, so the catalog loads only when needed.

Add descriptions to the createPermissionsAbstraction, createPermissionSchema, and createPermissionsFeature entries, which currently have only Name/Import/Source.

Remove the duplicate ApiKeyFactory entry (one of the two import-path variants) and state where the @webiny/api-core source tree can be found so step 2 of How to Use is actionable.

DimensionReasoningScore

Conciseness

Entries are single-line Name/Import/Source/Description records with zero explanation of concepts Claude already knows, and the 'How to Use' section is four terse steps. Not 5: the ApiKeyFactory entry appears twice verbatim (both import paths), and the formulaic 'Hook into X lifecycle after X is Y' phrasing could be tightened.

4 / 5

Actionability

Every entry ships a copy-paste import statement and a source-file path, and step 2 mandates reading the source before use. Not 5: the createPermissionsAbstraction, createPermissionSchema, and createPermissionsFeature entries have no Description, and there is no usage example beyond the import line.

4 / 5

Workflow Clarity

'How to Use' is an ordered, unambiguous lookup sequence (find → read source → import → consult pattern skills), and this reference skill involves no destructive or batch operations requiring validation. Not 5: step 2 points at '@webiny/api-core/...' source files without saying where that tree lives, and the referenced pattern skills are not resolvable from this skill.

4 / 5

Progressive Disclosure

The body inlines a ~390-line, 53-entry catalog that would live better in a references/ file with a short overview here, and no bundle files are provided to offset that. Structure is consistent (## How to Use, ## Abstractions, uniform per-entry format), which lifts it above anchor 2's 'minimal structure', but content that should be separate is inline and the two referenced pattern skills are external and not clearly signaled.

3 / 5

Total

15

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly states what the catalog contains via concrete domain nouns, but omits any 'when to use' trigger guidance and never names Webiny, limiting both completeness and distinctiveness. It reads as a table-of-contents line rather than a trigger-optimized description.

Suggestions

Add an explicit 'Use when...' clause, e.g. 'Use when working with Webiny security, authentication, API keys, roles, users, or teams in the webiny/api packages.'

Mention 'Webiny' in the description so it is distinguishable from generic security/auth skills and sibling catalog skills.

Include the common trigger synonyms users would say — 'permissions', 'identity', 'authorization', 'JWT' — alongside the existing 'API keys, roles, users, teams' list.

DimensionReasoningScore

Specificity

Names the domain ('API — Security & Auth') and concrete item categories ('Authentication, API keys, roles, users, teams event handlers and use cases'), but lists objects rather than actions — nothing states what the skill does with these abstractions. It sits between anchor 3 and 4: more concrete than a generic domain label, but no actions are described.

3 / 5

Completeness

The 'what' is clear — a catalog of 53 security/auth abstractions — but there is no 'Use when...' clause or equivalent trigger guidance, which caps completeness at 3 per the judging guidelines. Not 2 because the 'what' is explicit rather than vague.

3 / 5

Trigger Term Quality

'Authentication', 'API keys', 'roles', 'users', 'teams', 'Auth', 'Security' are natural terms a user would say when needing this skill. Coverage is good but misses common variations such as 'permissions', 'identity', 'authorization', 'JWT', or 'Webiny'.

4 / 5

Distinctiveness Conflict Risk

'API — Security & Auth' is a common domain and the description never mentions Webiny, so it could be confused with generic auth/security skills or sibling Webiny security skills. Somewhat specific, but overlap risk remains.

3 / 5

Total

13

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
webiny/webiny-js
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.