CtrlK
BlogDocsLog inGet started
Tessl Logo

dependency-resolver

Identify, analyze, and manage software dependencies before deployment. Use this skill when preparing applications for deployment, resolving dependency conflicts, updating dependencies, auditing security vulnerabilities, managing package versions, or troubleshooting dependency-related issues. Supports multiple package managers (npm, pip, maven, cargo, go mod, composer) and provides actionable recommendations for dependency management.

77

1.02x
Quality

79%

Does it follow best practices?

Impact

71%

1.02x

Average score across 3 eval scenarios

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/dependency-resolver/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable commands and realistic examples, but it is over-long for a SKILL.md, inlines reference material and known concepts that belong in separate files, and its core destructive workflow lacks the validation feedback loops the rubric requires. The cited reference files are also missing from the bundle.

Suggestions

Add explicit validation checkpoints to the core workflow (e.g., after proposing a fix, run `npm audit`/`npm ls` and only proceed when clean) to lift workflow_clarity above the destructive-operation cap.

Move the Version Constraint Syntax and Dependency Commands Reference sections into the referenced files, leaving SKILL.md as a lean overview that points to references/npm_yarn.md etc.

Provide the missing references/ bundle files (npm_yarn.md, python_deps.md, maven_gradle.md, cargo.md, go_modules.md) so the signaled progressive-disclosure links resolve.

Trim the Core Capabilities definitions of dependency types and other concepts Claude already knows to improve token efficiency.

DimensionReasoningScore

Conciseness

Mostly useful reference content, but the ~800-line body inlines concepts Claude already knows (dependency-type definitions, semver/PEP 440 syntax tables) and bulk reference material that belongs in separate files, so it is noticeably longer than an overview warrants.

3 / 5

Actionability

Provides concrete, copy-paste-ready commands across ecosystems (npm audit fix, npm install react@^18.0.0, mvn dependency:tree, go mod tidy, pip-audit) with realistic example outputs covering the common cases.

5 / 5

Workflow Clarity

The 5-step workflow is clearly sequenced, but it drives batch/destructive operations (rm -rf node_modules, deleting lock files, audit fix --force, prune) without validate-then-proceed feedback loops, so the missing-validation cap applies despite the simple-skill exception.

3 / 5

Progressive Disclosure

Section headers and one-level-deep ecosystem references are clearly signaled, but the referenced references/*.md files are absent from the bundle and bulk reference material (command and version-syntax tables) is inlined in SKILL.md rather than split out.

3 / 5

Total

14

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that clearly states capabilities and provides explicit 'Use when' trigger guidance with concrete scenarios. Main gap is the absence of file-name/file-extension triggers that would push trigger term quality and distinctiveness to the top anchor.

Suggestions

Add file-name triggers users naturally mention (e.g., package.json, requirements.txt, pom.xml, Cargo.toml, go.mod) to strengthen trigger term quality toward 5.

Tighten the package-manager list into the trigger clause so activation is anchored to concrete manifests rather than the broad 'dependency-related issues' phrasing.

DimensionReasoningScore

Specificity

Lists multiple concrete actions (identify, analyze, manage, resolve conflicts, audit vulnerabilities, update, manage versions) plus six named package managers, giving comprehensive coverage rather than just several actions with gaps.

5 / 5

Completeness

Explicitly answers both 'what' (identify, analyze, manage dependencies) and 'when' via a concrete 'Use this skill when...' clause listing specific scenarios.

5 / 5

Trigger Term Quality

Strong natural trigger phrases (deployment, dependency conflicts, security vulnerabilities, updating dependencies, troubleshooting) but lacks file-extension/file-name triggers like package.json or requirements.txt that the top anchor includes.

4 / 5

Distinctiveness Conflict Risk

Clear niche (pre-deployment dependency management) with distinct triggers and named package managers, but the deployment/dependency domain is broad enough to risk minor overlap with general deploy skills.

4 / 5

Total

18

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (804 lines); consider splitting into references/ and linking

Warning

relative_links

Relative link issues: 5 missing

Warning

referenced_paths_exist

Referenced path issues: 10 missing

Warning

Total

13

/

16

Passed

Repository
ArabelaTso/Skills-4-SE
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.