CtrlK
BlogDocsLog inGet started
Tessl Logo

1password

Set up op CLI, sign in, and read or inject secrets.

59

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./optional-skills/security/1password/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, executable skill body: real commands with verification steps, an error-recovery loop, and clean one-level reference structure. The main weaknesses are minor — a Linux install gap whose referenced file doesn't deliver the promised distro links, and duplication between the body's examples and cli-examples.md.

Suggestions

Add the actual Linux install commands (or at least the official apt/dpkg instruction) to references/get-started.md so the body's 'distro-specific links' pointer resolves to real content.

Trim the overlap between Common Operations and references/cli-examples.md — keep one canonical example per operation in the body and push the fuller set to the reference file.

DimensionReasoningScore

Conciseness

The body is dense and command-first with almost no concept explanation Claude already knows (e.g., 'Hermes terminal commands are non-interactive by default and can lose auth context between calls' is skill-specific, not filler), fitting 'efficient; minor instances of over-explanation that could be trimmed'. It is not 5 because of small redundancies: the developer.1password.com URLs are repeated across the References section and frontmatter, and the Connect Server and CI/headless sections overlap with the auth-methods guidance.

4 / 5

Actionability

Nearly everything is copy-paste bash: brew/winget installs, `op --version`, `op whoami`, a complete tmux session script, and read/OTP/inject/run examples — matching 'mostly executable guidance with minor gaps'. It is not 5 because the Linux install step is only a comment ('See references/get-started.md for distro-specific links') and that referenced file contains no distro-specific install commands, only a link to the official docs.

4 / 5

Workflow Clarity

Sequences are explicit with real validation checkpoints and an error-recovery loop: install → verify with `op --version`; auth → verify with `op whoami`; the `op run` example includes an explicit runtime check (`[ -n "$DB_PASSWORD" ] && ...`); and the Guardrails section gives a feedback loop ('If command fails with "account is not signed in", run `op signin` again in the same tmux session'). This matches the anchor 'clear sequence with explicit validation steps; feedback loops for error recovery'.

5 / 5

Progressive Disclosure

The SKILL.md body is an overview plus core examples, with two one-level-deep references (references/get-started.md, references/cli-examples.md) that are both listed in a References section and pointed to inline — fitting 'good structure; most content appropriately placed; references mostly clear; minor organization gaps'. It is not 5 because the body's Common Operations substantially duplicate cli-examples.md content, and the inline promise of 'distro-specific links' in get-started.md is not fulfilled by that file.

4 / 5

Total

17

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, third-person description with a clear 'what', but it omits the 1Password brand name (the strongest trigger term), any 'when to use' clause, and the op run capability. It is functional but below the quality of the reference good examples, which pair concrete actions with explicit trigger guidance.

Suggestions

Include 1Password in the description itself, not just the name field, e.g. 'Manage 1Password secrets via the op CLI' — users far more often say '1Password' than 'op CLI'.

Add an explicit trigger clause: 'Use when the user mentions 1Password, op CLI, secret references (op://...), or wants secrets injected instead of plaintext env vars.'

Mention `op run` (running commands with secret env vars resolved at runtime) so the description covers all three core operations the body teaches.

DimensionReasoningScore

Specificity

"Set up op CLI, sign in, and read or inject secrets" names the domain and three concrete actions (set up, sign in, read/inject), matching the 'lists several specific actions; minor gaps in coverage' anchor. It falls short of 5 because notable capabilities from the body (op run for env-var injection at runtime, OTP reads) are absent, and 'Set up op CLI' is more generic than the other verbs.

4 / 5

Completeness

The 'what' is clear (set up, sign in, read/inject secrets), but there is no 'Use when...' clause or equivalent explicit trigger guidance, which per the judging guidelines caps completeness at 3 ('clear what but when is missing or only weakly implied'). It is not 4 because nothing in the text tells Claude when to reach for this skill.

3 / 5

Trigger Term Quality

Terms like "op CLI", "sign in", "read or inject", and "secrets" are relevant, but the description never says "1Password" (the single most natural term a user would say) and omits synonyms like "vault", "credentials", or "op run" — matching 'some relevant keywords but missing common variations or synonyms'. It is above 2 because the keywords present are on-domain rather than generic.

3 / 5

Distinctiveness Conflict Risk

"op CLI" carves out a distinct niche (1Password's CLI) with minimal conflict risk against unrelated skills, fitting 'mostly distinct; minor overlap risk'. It is not 5 because "read or inject secrets" without the 1Password brand name leaves some overlap with generic secret-manager skills (vault, dotenv, sops).

4 / 5

Total

14

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

13

/

16

Passed

Repository
NousResearch/hermes-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.