CtrlK
BlogDocsLog inGet started
Tessl Logo

authentication-patterns

Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.

72

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured reference skill: highly actionable with specific thresholds, prioritized rules, executable code, and a shipping checklist. Its main weaknesses are modest — some boilerplate code Claude doesn't need, and all detail inlined in SKILL.md where provider-specific setup could be split into a reference file.

Suggestions

Trim or drop the bcrypt/argon2 code snippets — Claude already knows this API; the checklist line 'bcrypt (cost 12+) or argon2id' already carries the guidance.

Move the provider comparison table and the NextAuth setup pattern into a references/ file (e.g., references/providers.md) and keep a one-line pointer per provider in SKILL.md.

Add an explicit validation feedback loop to the security checklist (e.g., 're-run the checklist after fixes until every box is checked') to strengthen the shipping workflow.

DimensionReasoningScore

Conciseness

The body is dense and efficient — tables, P0/P1/P2-priority rules, and checklists rather than padded prose, and it adds genuinely non-obvious material (rotation policy, storage trade-off matrix, mistake/fix table). However, the bcrypt/argon2 snippets and the NextAuth boilerplate are basic usage Claude already knows and could be trimmed. Efficient with minor instances of over-explanation — the score-4 anchor, not the score-5 'every token earns its place' anchor.

4 / 5

Actionability

Guidance is fully concrete and executable: specific numbers ('15 min expiry', 'cost 12+', '5-10 attempts/min', 'min 8, max 128'), copy-paste-ready TypeScript for NextAuth setup and password hashing, a decision guide mapping situations to approaches, and a mistake→risk→fix table. Specific examples cover the common cases, matching the score-5 anchor.

5 / 5

Workflow Clarity

As a reference skill it has no single procedure, but it sequences decisions well: a decision guide for approach selection, a token lifecycle diagram showing the refresh-rotation flow, and a 'Before Shipping Auth' checklist acting as validation checkpoints. It lacks explicit feedback loops (validate→fix→retry), keeping it at the score-4 anchor rather than 5; it is not a destructive/batch skill, so the cap-at-3 rule does not apply.

4 / 5

Progressive Disclosure

The single SKILL.md (~165 lines) is well organized into clearly labeled sections with a scannable WHEN_TO_USE entry point and no buried references — and there are no bundle files, so nothing is mis-filed. The provider comparison and NextAuth setup pattern are the kind of deeper detail that could live in a separate reference file, which is the minor organization gap that keeps this at 4 rather than the fully-split structure of the score-5 anchor.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concise, names concrete capabilities covering the skill's full scope, and includes an explicit 'Use when...' clause with natural trigger phrases. The only gap is a few missing everyday synonyms (login, sign-in) that would make triggering even more robust.

DimensionReasoningScore

Specificity

The description lists multiple concrete capabilities — 'session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes' — which comprehensively cover the skill's scope with no vague filler. It clearly exceeds the score-4 anchor ('several specific actions; minor gaps') since all major sections of the skill are named explicitly.

5 / 5

Completeness

It explicitly answers both questions: the what ('session vs JWT vs OAuth comparison, provider selection, security checklist, and common mistakes') and the when ('Use when implementing auth, reviewing auth flows, or choosing auth providers') with concrete trigger phrases. This matches the score-5 anchor example almost exactly in structure.

5 / 5

Trigger Term Quality

Good keyword coverage: 'implementing auth, reviewing auth flows, choosing auth providers' plus named technologies (session, JWT, OAuth, NextAuth, Clerk, Supabase Auth). However, common natural synonyms users would say — 'login', 'sign-in', 'sign up', 'identity', 'MFA' — are missing, so it falls just short of the comprehensive-synonyms anchor at 5.

4 / 5

Distinctiveness Conflict Risk

The auth niche is clearly delimited and triggers ('implementing auth', 'reviewing auth flows', 'choosing auth providers') are specific to this domain, with named providers further narrowing it. Minimal overlap risk with adjacent skills (e.g., a generic security skill would not claim provider selection).

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.