CtrlK
BlogDocsLog inGet started
Tessl Logo

1password

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

69

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-built skill body: executable commands, a validated workflow with error-recovery guidance, and a clean two-file bundle split verified on disk. The only meaningful improvement is tightening the triple-stated tmux requirement and inlining one secret-read example so the primary use case is executable directly from the body.

DimensionReasoningScore

Conciseness

The body is lean — a 7-step workflow, one focused script, and terse guardrails, with no explanations of concepts Claude already knows. It loses a point to redundancy: the tmux requirement is stated three times (workflow step 4 "REQUIRED: create a fresh tmux session", the "REQUIRED tmux session" section, and the guardrail "Do not run op outside tmux"), which anchor 5's 'every token earns its place' would not tolerate.

4 / 5

Actionability

Concrete executable commands throughout ("op --version", "op signin", "op whoami", "op account add") plus a copy-paste-ready tmux script. It stops short of anchor 5 because the core secret-reading workflow is never shown in the body — it's delegated to references/cli-examples.md — and the sign-in example hardcodes a placeholder account, leaving minor gaps in covering the common cases inline.

4 / 5

Workflow Clarity

The 7-step sequence includes explicit validation checkpoints — "Verify CLI present: op --version", "Verify access inside tmux: op whoami (must succeed before any secret read)" — plus a feedback loop in the guardrails ("If a command returns 'account is not signed in', re-run op signin inside tmux"), matching the anchor-5 pattern of clear sequence, explicit validation, and error recovery; not a destructive/batch operation, so no cap applies.

5 / 5

Progressive Disclosure

A concise overview with a References section pointing to two clearly labeled, one-level-deep files (references/get-started.md for install/sign-in, references/cli-examples.md for examples), both verified to exist; content is appropriately split — OS-specific install detail and command catalogs live in the bundle, not the body — matching the anchor-5 structure of well-signaled, shallow references with easy navigation.

5 / 5

Total

18

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description in third person with an explicit 'Use when' trigger clause and multiple concrete capabilities. It clearly communicates both scope and activation conditions with minimal fluff. Only minor gains available from adding a few synonyms (e.g., 'password manager', 'credentials') and covering item/vault management.

DimensionReasoningScore

Specificity

Enumerates several concrete actions — "installing the CLI", "enabling desktop app integration", "signing in (single or multi-account)", "reading/injecting/running secrets via op" — but coverage has minor gaps (e.g., item/vault management, provisioning) and the lead phrase "Set up and use" is generic, matching anchor 4 rather than the comprehensive anchor 5.

4 / 5

Completeness

Explicitly answers both what ("Set up and use 1Password CLI (op)... reading/injecting/running secrets via op") and when via a concrete "Use when..." clause listing four specific triggers, matching the anchor-5 example pattern exactly; not 4 because the 'when' is fully explicit with concrete trigger phrases, not merely present.

5 / 5

Trigger Term Quality

Good natural keyword coverage: "1Password CLI", "op", "installing", "signing in", "secrets" are phrases users would actually say; a few natural variants are missing (e.g., "password manager", "credentials", "environment variables", "OP_ACCOUNT"), so it falls just short of anchor 5's synonym/extension comprehensiveness.

4 / 5

Distinctiveness Conflict Risk

Clear niche — the 1Password CLI tool named as "op" — with distinct triggers (desktop app integration, op signin, secret injection) that no generic secret-management or password skill would claim; minimal conflict risk.

5 / 5

Total

18

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

13

/

16

Passed

Repository
Bitterbot-AI/bitterbot-desktop
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.