CtrlK
BlogDocsLog inGet started
Tessl Logo

dmr-from-dj-rest-auth

Migrate an existing Django auth API from dj-rest-auth to django-modern-rest, moving account flows onto django-allauth headless and rebuilding the transport layer with dmr controllers and auth classes. Use when replacing dj_rest_auth login/logout/registration/password/MFA/social views and their DRF serializers.

76

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is dmr-from-dj-rest-auth in wemake-services/django-modern-rest

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An excellent instruction-only skill body: prescriptive, security-conscious, and tightly sequenced with explicit validation gates and a finish gate. The bulk detail is properly offloaded to a single well-signaled reference file; the only weaknesses are the absence of any copy-paste-ready snippets and minor duplication between the body's auth-transport list and the reference's auth table.

Suggestions

Add one short copy-paste-ready snippet (e.g. a minimal CookieSpec/NewCookie block showing preserved JWT_AUTH_COOKIE flags) to lift actionability toward fully executable.

Replace the step-3 auth-transport bullet list with a pointer to the auth table in references/dj-rest-auth-to-dmr-map.md to remove the duplicated mapping.

DimensionReasoningScore

Conciseness

Lean and dense throughout: assumes Django/DRF/allauth competence ('allauth headless has no user-details endpoint', 'REST_AUTH keys become code, not configuration') and never explains basics. Not 4 because no section reads as padded or over-explained.

5 / 5

Actionability

Highly concrete guidance (exact INSTALLED_APPS entries, class names like 'HeaderJWTSyncAuth' and 'CookieJWTSyncAuth', decorators '@sensitive_post_parameters', 'NO_STORE_HEADERS') but no copy-paste code and some directives require judgment ('update the client', 'run the repository's checks'). Not 5 because nothing is copy-paste ready; not 3 because every step names the specific objects to act on.

4 / 5

Workflow Clarity

Eleven explicitly sequenced steps with stated rationale ('in this order, because later flows depend on being able to log in'), required gates, per-flow validation ('run the repository's checks'), a finish gate ('Do not mark a flow done until linters pass, tests pass'), pitfalls, and an output checklist — feedback loops are present for this risky batch migration. Not 4 because checkpoints are explicit, not implicit.

5 / 5

Progressive Disclosure

The bulky mapping tables (endpoints, settings, serializers) are correctly split into the real one-level-deep references/dj-rest-auth-to-dmr-map.md, clearly signaled ('See the settings table in the local map'). Not 5 because the step-3 auth-transport list partially duplicates the reference file's auth-class table, a minor organization gap.

4 / 5

Total

18

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete third-person actions, an explicit 'Use when' trigger clause enumerating the exact dj_rest_auth views, and highly distinctive package-name keywords. The only minor gap is that token-strategy migration, a real part of the skill, is not mentioned.

DimensionReasoningScore

Specificity

Lists several concrete actions ('Migrate an existing Django auth API', 'moving account flows onto django-allauth headless', 'rebuilding the transport layer with dmr controllers and auth classes') in third-person voice. Not 5 because the transport-layer action is slightly abstract and token-strategy handling is not surfaced.

4 / 5

Completeness

Explicitly answers both: sentence 1 states what the skill does and 'Use when replacing dj_rest_auth login/logout/registration/password/MFA/social views and their DRF serializers' gives concrete when-triggers. Matches the anchor-5 example structure.

5 / 5

Trigger Term Quality

Covers the natural phrases a user would say: 'dj-rest-auth', 'django-modern-rest', 'django-allauth headless', 'login/logout/registration/password/MFA/social views', 'DRF serializers'. Not 4 because the flow-name enumeration is comprehensive for the domain.

5 / 5

Distinctiveness Conflict Risk

Clear niche (migrating specifically from dj-rest-auth to django-modern-rest) with distinct package-name triggers, so it is unlikely to fire for generic Django or allauth work. Not 4 because no meaningful overlap with sibling migration skills is implied.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
wemake-services/django-modern-rest
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.