CtrlK
BlogDocsLog inGet started
Tessl Logo

addressing-dependabot

Addresses GitHub Dependabot security alerts by listing open alerts, identifying affected Python/uv, frontend npm, and Titus Go projects, upgrading vulnerable dependencies, running verification, and committing fixes. Use when the user wants to fix Dependabot alerts, upgrade vulnerable packages, or address security vulnerabilities found by Dependabot.

92

1.13x
Quality

88%

Does it follow best practices?

Impact

98%

1.13x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An excellent operational skill: executable commands throughout, well-sequenced workflow with gates, verification, and error-recovery loops. Its weaknesses are mild duplication of gate/tooling instructions and a monolithic single-file layout where the project-path reference and troubleshooting sections would be better split into reference files.

Suggestions

Move the 'Python project paths reference' directory listing and the Troubleshooting section into a references/ file (e.g. references/troubleshooting.md and references/projects.md) and link to them from SKILL.md, shortening the body and enabling progressive disclosure.

Deduplicate the repeated approval-gate wording: state the gate protocol once at the top and mark Steps 2 and 6 with just '[GATE — see protocol above]', and define the REPO detection snippet once.

Consolidate the Go version-format and /usr/local/go/bin/go guidance, which currently appears in both Step 3 and Troubleshooting, into a single location.

DimensionReasoningScore

Conciseness

The body is lean and command-driven with essentially no explanation of concepts Claude already knows — every section is a specific command, decision rule, or template. It falls short of the 'every token earns its place' anchor due to duplicated material: the gate instruction ('Use request_user_input when available; otherwise ask a direct concise question...') appears verbatim twice, the REPO detection snippet is repeated, and the Go version-prefix and /usr/local/go/bin/go guidance appears in both Step 3 and Troubleshooting. This is a level above the 'noticeably verbose' anchor at 3, since the padding is limited to a few verbatim repeats rather than unnecessary explanations.

4 / 5

Actionability

Nearly every instruction is an executable command with clearly marked per-alert substitutions ({package}, {fixed_version}, {project_dir}), including concrete verification commands (npm ls, go list -m, npm audit, pytest) and real failure remedies (EOVERRIDE handling, uv constraint-dependencies, relaxed bounds). The commands are complete and copy-paste ready once the dynamic alert values are filled in, matching the fully-executable anchor rather than the 'minor gaps' level 4.

5 / 5

Workflow Clarity

A clearly numbered six-step sequence with two explicit approval gates, per-ecosystem decision branches (direct vs transitive), an explicit feedback loop ('Investigate whether the failure is caused by the dependency update... fix the issue... and re-run'), and a closing verification checklist. This matches the top anchor (explicit validation steps, error-recovery loops, checklists); since verification and retry-on-failure are present, the destructive/batch cap at 3 does not apply.

5 / 5

Progressive Disclosure

The skill is a single ~350-line file with no bundle (no references/, scripts/, or assets/ exist) and no pointers to external material. Section headers make it navigable, but content that naturally belongs in separate reference files is inlined — notably the 'Python project paths reference' listing of 12 directories and the ~40-line Troubleshooting section — which matches 'some structure but content that should be separate is inline' rather than level 4's 'most content is appropriately placed'.

3 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concise, and specific about both capabilities and trigger conditions. The only improvement space is broader trigger-term coverage (e.g. CVEs, security alerts, dependency updates) to catch more user phrasings.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions covering the full workflow — 'listing open alerts', 'identifying affected Python/uv, frontend npm, and Titus Go projects', 'upgrading vulnerable dependencies', 'running verification', and 'committing fixes' — with no vague filler. It goes beyond the level-4 anchor ('several specific actions; minor gaps') by covering every phase from discovery to commit, so it matches the comprehensive-coverage anchor.

5 / 5

Completeness

It explicitly answers both questions: the 'what' is a concrete multi-action capability statement, and the 'when' is an explicit 'Use when the user wants to...' clause with three concrete trigger phrases. This mirrors the top anchor's structure of clear what-AND-when with concrete triggers; the level-4 anchor requires a 'when' that 'could be more explicit', which does not apply here.

5 / 5

Trigger Term Quality

The 'Use when' clause provides natural phrases users would actually say: 'fix Dependabot alerts', 'upgrade vulnerable packages', 'address security vulnerabilities found by Dependabot'. A few common variants are missing (e.g. 'CVE', 'security alerts', 'dependency updates', 'outdated packages'), placing it just below the comprehensive-synonym anchor at 5.

4 / 5

Distinctiveness Conflict Risk

'GitHub Dependabot security alerts' names a clear niche with distinct triggers ('Dependabot alerts', 'vulnerable packages', 'security vulnerabilities found by Dependabot') that no general dependency-management or security skill would claim. Conflict risk is minimal, matching the clear-niche anchor rather than the level-4 'minor overlap risk with closely related skills'.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SpecterOps/Nemesis
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.