CtrlK
BlogDocsLog inGet started
Tessl Logo

1password

Set up and use 1Password CLI for authentication, secret references, command injection, and safe configuration templating.

66

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-crafted, actionable skill body: executable commands, a validated workflow with error-recovery feedback loops, and clean progressive disclosure into two real reference files. The only minor weakness is a few explanatory sentences that marginally trim conciseness.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — it never explains what 1Password or a CLI is — with executable command blocks and directive guardrails. It is efficient but carries a few explanatory prose sentences (e.g. service-account vault limits, desktop IPC behavior) that could be trimmed, so 4 rather than 5.

4 / 5

Actionability

Provides copy-paste-ready, executable bash throughout — `op --version`, `op whoami`, `op vault list`, the tmux sign-in block, and `op run`/`op inject`/`op read` patterns — covering the common cases with concrete commands rather than pseudocode.

5 / 5

Workflow Clarity

A clearly sequenced 6-step workflow with explicit validation checkpoints (`op --version`, `op whoami` before secret-consuming operations) and feedback loops for error recovery (pause/resume around sign-in prompts, fixing an expired mode rather than silently switching). The Guardrails section acts as a checklist for the sensitive secret-handling process.

5 / 5

Progressive Disclosure

Clear overview structure (References, Workflow, Authentication modes, Guardrails) with two well-signaled, one-level-deep references — `references/get-started.md` and `references/cli-examples.md` — both of which exist as real bundle files. Content is appropriately split and easy to navigate.

5 / 5

Total

19

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description that clearly conveys what the skill does and is unlikely to trigger for unrelated skills. Its main weakness is the absence of an explicit "Use when…" trigger clause, which caps completeness.

Suggestions

Add an explicit trigger clause, e.g. "Use when the user needs to retrieve or inject 1Password secrets via the `op` CLI, configure secret references, or template config files with secrets."

Replace "command injection" with a clearer natural phrase such as "injecting secrets into commands" to improve both trigger quality and specificity.

Include natural synonyms users actually say — "op CLI", "secrets", "credentials" — to broaden trigger coverage.

DimensionReasoningScore

Specificity

Lists several concrete actions — "authentication, secret references, command injection, and safe configuration templating" — rather than vague language. Falls short of 5 because "command injection" is slightly ambiguous and coverage is not fully comprehensive.

4 / 5

Completeness

The description gives a clear "what" (set up and use the 1Password CLI for four named purposes) but provides no "Use when…" clause or equivalent trigger guidance. Per the rubric guideline, a missing explicit trigger caps completeness at 3.

3 / 5

Trigger Term Quality

"1Password CLI", "secret references", and "authentication" are natural terms a user would say, but "command injection" is jargon and common variants like "op CLI", "secrets", or "credentials" are absent. Good coverage with a few natural terms missing, so 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

Tightly scoped to the 1Password CLI with distinct triggers ("1Password CLI", "secret references"), giving it a clear niche with minimal overlap risk against other skills.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
EKKOLearnAI/hermes-studio
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.