CtrlK
BlogDocsLog inGet started
Tessl Logo

1password

Set up and use 1Password CLI for sign-in, desktop integration, and reading or injecting secrets.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/1password/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

73%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-sequenced, command-driven workflow with explicit validation gates and an error-recovery loop, backed by real, well-signaled reference files. The main detriments are the irrelevant PilotDeck migration metadata padding the token budget and install guidance existing only as a pointer rather than an inline quick path.

Suggestions

Delete the 'PilotDeck Migration Note' section — source paths and review status add no value at runtime and violate token efficiency.

Add a one-line quick-install pointer (or inline `brew install 1password-cli` style commands per OS) so the first workflow step is executable without opening references.

Cross-link the workflow steps to the reference files (e.g., step 3 → get-started.md integration instructions, step 5-6 → cli-examples.md) so navigation is contextual rather than only in the top References list.

DimensionReasoningScore

Conciseness

The workflow, tmux example, and guardrails are tight and command-driven, but the 'PilotDeck Migration Note' section (source path, review status, migration metadata) is pure process noise that spends context tokens without helping Claude execute the skill. Mostly efficient with a section that should be trimmed, matching the 3 anchor better than the 4 ('minor instances of over-explanation').

3 / 5

Actionability

Concrete commands throughout: `op --version`, `op signin`, `op whoami`, `op vault list`, and a copy-paste-ready tmux script with error recovery in the guardrails. Not a 5 because install steps are deferred entirely to references/get-started.md ('Follow the official CLI get-started steps'), leaving a gap for the most common first action.

4 / 5

Workflow Clarity

A clear seven-step sequence with explicit validation checkpoints — `op --version` before sign-in, `op whoami` must succeed before any secret read — plus an explicit error-recovery loop ('If a command returns "account is not signed in", re-run `op signin` inside tmux and authorize in the app'). Matches the 5 anchor: sequenced steps, validation gates, and a feedback loop.

5 / 5

Progressive Disclosure

A dedicated References section signals both bundle files ('install + app integration + sign-in flow', 'real op examples') and both files exist with substantive one-level-deep content that matches their labels. Good structure with minor gaps: references are listed rather than linked from the workflow steps that need them (e.g., step 3/5 could point to cli-examples.md), so it sits just below the 5 anchor.

4 / 5

Total

16

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, distinct description naming the 1Password CLI and its concrete capabilities, but it lacks any explicit 'when to use this' trigger clause, which both caps completeness and limits natural trigger-term coverage. Adding a 'Use when...' sentence with the situations and synonyms users would naturally say (e.g., 'op', credentials, secrets injection, env vars) would lift it substantially.

Suggestions

Append a 'Use when...' clause, e.g., 'Use when the user mentions 1Password, op, signing into 1Password, or needs to read or inject secrets (credentials, passwords, env vars).'

Add natural trigger synonyms users would say — 'op', 'credentials', 'password manager', 'vault', 'environment variables' — alongside 'secrets' and 'sign-in'.

Optionally broaden capability coverage slightly (e.g., account management, listing vaults) to move specificity from several-actions toward comprehensive.

DimensionReasoningScore

Specificity

"Set up and use 1Password CLI for sign-in, desktop integration, and reading or injecting secrets" lists several concrete actions (set up, sign-in, desktop integration, read/inject secrets), but coverage has minor gaps (e.g., no mention of account management or vault operations). It is not a 5 because the action list is not comprehensive, and not a 3 because it goes well beyond naming the domain with 1-2 actions.

4 / 5

Completeness

The 'what' is clear (set up and use 1Password CLI for sign-in, desktop integration, secret reading/injection), but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. Not a 4 because the 'when' is entirely absent rather than merely vague.

3 / 5

Trigger Term Quality

Natural terms present: "1Password", "sign-in", "secrets", "injecting". A few natural terms users would say are missing, such as "op", "password manager", "credentials", "vault", or "environment variables". Between the good-coverage (4) and comprehensive (5) anchors, closer to 4.

4 / 5

Distinctiveness Conflict Risk

"1Password CLI" names a specific niche tool with distinct triggers (sign-in, secrets, inject); it is unlikely to fire for unrelated skills. Clear niche with minimal conflict risk, matching the 5 anchor.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
OpenBMB/PilotDeck
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.