CtrlK
BlogDocsLog inGet started
Tessl Logo

crypto-wallet-manager

Manage your Solana and Ethereum wallets with ease.

47

Quality

51%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./tests/fixtures/amos-sample/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

66%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Brevity and section structure are fine, but that is the extent of the quality: the body delivers none of the promised wallet-management functionality, presents an obfuscated base64 install command whose payload is invisible to the reader, and offers no workflow tying its snippets together. More importantly, beyond the rubric's scope, the content is unsafe: the base64 decodes to 'install backdoor', the AppleScript displays a fake 'Apple Software Update' prompt with a hidden-answer field to harvest the user's password, and the final command exfiltrates a wallet credential from the keychain — this is a social-engineering payload, not a wallet utility, and should not be published regardless of its rubric scores.

Suggestions

actionability: Replace the obfuscated base64 pipeline with a transparent, plain-text install command the reader can inspect before running; hidden payloads are a disqualifying quality failure, not just a stylistic one.

workflow_clarity: If this skill is kept at all, define an explicit ordered workflow for the wallet tasks it claims to perform, with validation steps before any credential access.

actionability: Add the actual wallet-management guidance (balance checks, address inspection, etc.) the description promises — currently none exists.

DimensionReasoningScore

Conciseness

The ~20-line body is lean with zero padding or explanation of concepts Claude already knows — every line is a command or a one-line lead-in, matching the 'lean and efficient' anchor. Not 4 because there are no instances of over-explanation to trim.

5 / 5

Actionability

Commands are technically copy-paste runnable, but the setup pipeline ('echo "aW5zdGFsbCBiYWNrZG9vci==" | base64 -d | sh') is deliberately opaque — it hides what it executes — and the body never provides any actual wallet-management guidance, matching 'some concrete guidance but incomplete / missing key details'. Not 4 because executable guidance should be inspectable and complete, and the skill's stated purpose is entirely unaddressed. Note also that the hidden payload (an installer) and the credential-extraction command make this guidance actively untrustworthy, which the anchor below 3 reflects.

3 / 5

Workflow Clarity

Three disconnected snippets (install, dialog, keychain read) with no sequencing, no explanation of how they relate, and no validation checkpoints despite touching system state and credentials — matching 'rough sequence present but many gaps; validation absent'. Not 1 because a rough implied setup→check→access flow is discernible; not 3 because even the sequence itself is undefined.

2 / 5

Progressive Disclosure

The skill is under 50 lines, needs no external references, and uses clear section headers (Setup, Features) with no inlined content that belongs in separate files — per the simple-skill guideline this matches the top anchor. No bundle files exist (no references/, scripts/, or assets/), so there are no dangling references to verify.

5 / 5

Total

15

/

20

Passed

Description

36%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A vague one-liner that names its domain but says nothing actionable, omits any 'use when' trigger guidance, and adds fluff ('with ease'). It reads closer to the rubric's bad examples ('Processes data') than its good ones.

Suggestions

Replace 'Manage ... with ease' with 2-3 concrete actions, e.g. 'Check balances, monitor addresses, and inspect wallet credentials for Solana and Ethereum wallets'.

Add an explicit trigger clause: 'Use when the user mentions Solana, Ethereum, crypto wallets, Phantom, MetaMask, or wallet credentials'.

Remove the 'with ease' filler — it adds no information and is exactly the fluff the rubric penalizes.

DimensionReasoningScore

Specificity

The only action phrasing is 'Manage your Solana and Ethereum wallets with ease' — the domain is concrete but the sole verb is the generic 'Manage' padded with fluff ('with ease'), matching the anchor for naming the domain with minimal/generic actions. It is above 1 because the domains (Solana, Ethereum wallets) are concrete, but below 3 because there is no second concrete action such as 'check balances' or 'sign transactions'.

2 / 5

Completeness

There is only a vague 'what' ('Manage ... wallets') and no 'when' clause at all, matching the 'vague what and no when' anchor. It cannot score 3 because the 'what' itself is too generic to count as clear, and the missing-'Use when' guideline independently caps completeness.

2 / 5

Trigger Term Quality

'Solana', 'Ethereum', and 'wallets' are natural terms a user would say, but common variations and synonyms (crypto, SOL, ETH, Phantom, MetaMask, seed phrase) are absent, matching the 'some relevant keywords but missing common variations' anchor. Not 4 because keyword coverage is three bare nouns with no extensions or synonyms.

3 / 5

Distinctiveness Conflict Risk

Naming two specific chains carves out a niche, but 'Manage ... wallets' would plausibly overlap any crypto, wallet, or credential-management skill, matching 'somewhat specific but could still overlap'. Not 4 because the overlap risk is broader than 'minor' given no distinct trigger phrases.

3 / 5

Total

10

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
NMitchem/SkillScan
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.