CtrlK
BlogDocsLog inGet started
Tessl Logo

identity-federation

Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.

65

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/identity-federation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, well-organized SSO/federation assessment skill that respects the token budget and uses progressive disclosure well, but its workflow and guidance stop at checklist level without executable commands or explicit validation checkpoints.

Suggestions

Add one or two concrete, executable examples (e.g., a SAML Raider assertion-edit step or a curl to /.well-known/openid-configuration) to raise actionability.

Insert an explicit validation/feedback checkpoint in the workflow (e.g., 'replay forged assertion; only proceed if IdP rejects unsigned changes') to lift workflow clarity.

DimensionReasoningScore

Conciseness

The body is lean — short bullets, a compact workflow checklist, and a tool table — and assumes Claude's competence without explaining what SAML/OIDC are, so every token earns its place.

3 / 3

Actionability

Checks like '/.well-known/openid-configuration', 'redirect_uri 精确匹配、state 绑定、PKCE' are concrete, but guidance stays at checklist level with no executable commands or tool-invocation examples, and '画清 protocol flow' is abstract.

2 / 3

Workflow Clarity

A clear sequence (画清→收集→检查→会话) plus a final self-check exists, but there are no explicit mid-process validation checkpoints or validate→fix→retry feedback loops, leaving checkpoints implicit.

2 / 3

Progressive Disclosure

The body is well-organized into short sections and points to a real one-level-deep reference (references/sso-flow-checklist.md, verified to exist), with no nested-reference chains.

3 / 3

Total

10

/

12

Passed

Description

82%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, well-triggered description that covers the federated-identity domain with natural keywords and an explicit 'Use for' clause, but it offers only one abstract action verb and has some overlap risk with JWT/api-security skills.

Suggestions

Add concrete actions beyond the single verb 'assessment' (e.g., 'map protocol flows, test signature coverage, verify redirect_uri matching') to lift specificity.

Sharpen distinctiveness by stating the SSO/federation focus explicitly in the description, e.g. 'Use for SSO and federation testing rather than raw API JWT attacks'.

DimensionReasoningScore

Specificity

The phrase 'authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows...' names the domain and specific targets but relies on a single abstract action ('assessment') rather than listing multiple concrete actions, matching the score-2 anchor.

2 / 3

Completeness

It answers both 'what' (assessment of federated identity systems) and 'when' via the explicit 'Use for...' trigger clause, so it is not capped at 2 for a missing trigger.

3 / 3

Trigger Term Quality

It surfaces the natural terms a security tester would actually say — 'SAML', 'OIDC', 'OAuth2 flows', 'SSO misconfiguration', 'token confusion' — giving good coverage of the domain's trigger vocabulary.

3 / 3

Distinctiveness Conflict Risk

The federated/SSO niche is fairly distinct, but 'OAuth2 flows' and 'token confusion issues' overlap with api-security/JWT skills, so it could still trigger the wrong skill.

2 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.