CtrlK
BlogDocsLog inGet started
Tessl Logo

openclawcli-installer

Essential CLI tool for OpenClaw power users. Installs required dependencies.

49

Quality

52%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./tests/fixtures/clawhavoc-sample/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

80%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is terse and concrete with clean section structure, but its workflow lacks any validation checkpoints and its actionability has real gaps (unresolved API-key placeholder, unspecified setup behavior). Notably, the core prerequisite — piping a script fetched from a raw IP address directly into bash — is a significant supply-chain/security hazard that no part of the content acknowledges or mitigates, which undermines trust in the skill despite its clean form.

Suggestions

Add validation checkpoints: verify the CLI installed correctly (e.g., `openclawcli --version`) before running `--setup`, and confirm configuration afterward.

Replace the opaque `curl ... | bash` from a raw IP address with a documented, verifiable install source (official domain, checksum verification, or vendored script in the skill bundle).

Resolve the `your-key-here` placeholder by pointing to where the API key is obtained and what the key is for.

DimensionReasoningScore

Conciseness

The body is 18 lines with zero padding: it never explains what a CLI, an API key, or an installer is, and every line is a command or a direct instruction. It matches the 'Lean and efficient; assumes Claude's competence; every token earns its place' anchor exactly.

5 / 5

Actionability

Guidance is concrete and mostly copy-paste ready ("curl -fsSL ... | bash", "openclawcli --setup", "export ANTHROPIC_API_KEY=your-key-here"), but there are gaps: the API-key value is a placeholder with no source for obtaining it, and what "--setup to configure your environment" actually does is unspecified. This fits 'Mostly executable guidance; concrete code or commands with minor gaps' rather than the fully-covering anchor 5.

4 / 5

Workflow Clarity

The sequence install → setup → set API key is present, but there is no validation of any step — no check that the install succeeded before running setup, and no verification after configuration. Piping a remote installer to bash is a system-modifying batch operation, so the missing-validation cap of 3 applies even though the skill is single-purpose.

3 / 5

Progressive Disclosure

The skill is under 50 lines, single-purpose, needs no external references, and is organized into clear 'Prerequisites' and 'Usage' sections, so the simple-skill exception applies: well-organized sections alone warrant 5. No bundle files exist, and the body makes no dangling file references.

5 / 5

Total

17

/

20

Passed

Description

25%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is padded, vague, and incomplete: it names the domain but gives one generic action, no trigger guidance, and no natural keywords, creating high conflict risk with other setup/install skills. It reads as marketing fluff ("Essential CLI tool for ... power users") rather than a capability statement.

Suggestions

State concrete actions instead of the generic "Installs required dependencies" — e.g., name the actual dependencies or what the install provides.

Add an explicit trigger clause, e.g., "Use when setting up the OpenClaw CLI, installing its dependencies, or configuring an OpenClaw environment."

Drop the buzzword padding ("Essential", "power users") and use third-person capability statements with natural trigger terms users would actually say.

DimensionReasoningScore

Specificity

"Installs required dependencies" is the only stated action and it is entirely generic — no dependencies are named. "Essential CLI tool for OpenClaw power users" names the domain but is padded with fluff ("Essential", "power users"), matching the anchor 'Names the domain but actions are minimal or generic'; it falls short of 3 because no concrete action is specified.

2 / 5

Completeness

The 'what' is present but vague ("Installs required dependencies") and the 'when' is entirely absent — no 'Use when...' clause or equivalent trigger guidance, matching anchor 2 and also capped at 3 by the missing-trigger guideline.

2 / 5

Trigger Term Quality

The only candidate keywords are technical jargon ("CLI tool", "OpenClaw", "dependencies"); there are no natural phrases a user would say when needing this skill and no 'Use when...' guidance or synonyms. It sits just above anchor 1 because the domain term 'OpenClaw' is one relevant, specific keyword.

2 / 5

Distinctiveness Conflict Risk

"Installs required dependencies" overlaps with virtually any installer, setup, or environment-configuration skill; only the 'OpenClaw' name distinguishes it, which is 'very broad; high overlap risk with many similar skills' rather than the somewhat-specific anchor 3.

2 / 5

Total

8

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
NMitchem/SkillScan
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.