CtrlK
BlogDocsLog inGet started
Tessl Logo

1k-pkg-upgrade-review

Reviews package version upgrades — diffs source between versions, traces call sites, and generates compatibility reports.

60

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.skillshare/skills/1k-pkg-upgrade-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a well-structured skill body: concise, immediately actionable, and properly delegating detail to verified reference files. The only meaningful gaps are the missing exact gh pr comment invocation and validation checkpoints that are implicit rather than explicit in the workflow.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence: no basic-concept explanations, no padding, and every section (Quick Reference, When to Use, Workflow Overview, Key Commands, Report Output) instructs rather than describes. Matches the 'lean and efficient; every token earns its place' anchor.

5 / 5

Actionability

Key Commands provides concrete, mostly copy-paste-ready templates (curl/npm view tarball extraction, diff -rq, two grep variants), matching 'mostly executable guidance with minor gaps'. It is not 5 because step 10 ('Post the full report as a PR comment via gh pr comment') never shows the actual command, e.g. 'gh pr comment <PR> --body-file <report>'.

4 / 5

Workflow Clarity

The 10-step Workflow Overview is clearly sequenced from identification through report posting, with verification present (step 7 'Trace each call site to verify argument usage and compatibility'). It stops short of 5 because validation checkpoints are implicit rather than explicit — no 'only proceed when X' gates or error-recovery loops — and the report-writing step has no defined pass/fail check.

4 / 5

Progressive Disclosure

The Quick Reference table cleanly signals three one-level-deep references (review-workflow.md, report-template.md, example-report.md) with descriptions of what each contains, and all three files exist in the bundle. The body stays an overview while details live in the reference files, matching the 'clear overview with well-signaled one-level-deep references' anchor.

5 / 5

Total

18

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a clear, concrete capability set but reads as a one-sided 'what' statement. Its main weakness is the complete absence of 'when to use' trigger guidance, plus thin keyword coverage for the ecosystem terms (Dependabot, Renovate, lockfiles) that users actually say when this skill is needed.

Suggestions

Append an explicit trigger clause, e.g. 'Use when reviewing Dependabot/Renovate PRs that bump dependency versions, or when yarn.lock / package-lock.json changes in a PR.'

Include natural synonyms users would say — 'dependency upgrade', 'version bump', 'lockfile' — alongside 'package version upgrades' to improve trigger-term coverage.

State the concrete output location/delivery (compatibility report posted as a PR comment) to round out the capability coverage and push specificity toward comprehensive.

DimensionReasoningScore

Specificity

The description names the domain ('package version upgrades') and three concrete actions ('diffs source between versions, traces call sites, and generates compatibility reports'), matching the 'several specific actions; minor gaps' anchor. It falls short of 5 because coverage is incomplete — e.g., nothing about npm/registry specifics, lockfile changes, or where the report goes.

4 / 5

Completeness

The 'what' is clear (reviews upgrades via diffing, tracing, and reporting), but there is no 'Use when...' clause or equivalent explicit trigger guidance in the description, which per the judging guidelines caps completeness at 3. It is not 2 because the 'what' is concrete rather than vague.

3 / 5

Trigger Term Quality

'package version upgrades' and 'compatibility reports' are relevant keywords, but common natural variations users would say — 'Dependabot', 'Renovate', 'dependency', 'version bump', 'lock file' — are missing from the description (several appear only in the body, which is not the evaluation target). Matches the 'some relevant keywords but missing common variations or synonyms' anchor.

3 / 5

Distinctiveness Conflict Risk

'Reviews package version upgrades — diffs source between versions' carves out a clear niche that is unlikely to trigger for unrelated skills, matching 'mostly distinct; minor overlap risk'. The generic opening verb 'Reviews' leaves minor overlap risk with general code-review skills, so it does not reach 5.

4 / 5

Total

14

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

relative_links

Relative link issues: 2 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 2 deeper-than-1-level

Warning

Total

13

/

16

Passed

Repository
OneKeyHQ/app-monorepo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.