CtrlK
BlogDocsLog inGet started
Tessl Logo

managing-packages

Manages Python package dependencies. Use when adding, upgrading, removing, or syncing Python/pypi packages in projects or libs.

90

1.52x
Quality

85%

Does it follow best practices?

Impact

99%

1.52x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

87%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exceptionally lean and fully executable skill body — every command is copy-paste ready and nothing over-explains. The only weakness is the absence of any verification guidance after environment-mutating operations (upgrade/remove/sync), which the rubric caps at 3 for workflow clarity.

Suggestions

Add a brief verification step after upgrade/remove/sync, e.g. "After upgrading or removing, run `cd {path} && uv run pytest` (or the project's test command) to confirm nothing broke".

Note how to confirm the dependency change took effect, such as checking `uv lock --check` or reviewing the `uv.lock` diff before committing.

For `uv sync`, mention the flag to avoid pruning extraneous packages (e.g., `uv sync --inexact`) when only adding dependencies, since sync can remove unrelated installed packages.

DimensionReasoningScore

Conciseness

The body is nothing but executable command blocks, a path listing, and three terse notes ("Always use `uv`, never `pip`"; "Commit both `pyproject.toml` and `uv.lock`"); there is no padding or explanation of concepts Claude already knows — every token earns its place, matching anchor 5.

5 / 5

Actionability

All five commands (add, add --dev, upgrade via `{package}@latest`, remove, sync) are copy-paste ready with a `cd {path} &&` prefix and consistent placeholders, and the project-path list plus `uv run` note give fully executable coverage of the common cases — anchor 5.

5 / 5

Workflow Clarity

Each single command is unambiguous, but operations like `uv remove` and `uv sync` destructively or batch-modify the project environment, and no validation/verification step is given (e.g., run tests or `uv lock --check` after upgrading); per the rubric this cap at 3 takes precedence over the simple-skill exception, and the score cannot be 4 because a checkpoint is entirely absent rather than minor.

3 / 5

Progressive Disclosure

The skill is under 50 lines with no external reference files needed; it uses clean, well-organized sections (Commands with per-operation subsections, Project paths, Notes), so per the rubric's simple-skill guideline it earns 5 on structure alone.

5 / 5

Total

18

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that explicitly pairs a capability statement with a concrete "Use when" trigger clause. The main gaps are generic phrasing of the core capability and missing natural trigger synonyms such as "install" or "uv".

DimensionReasoningScore

Specificity

The description enumerates several concrete actions ("adding, upgrading, removing, or syncing" packages), but the headline capability "Manages Python package dependencies" is generic, so coverage is strong with minor gaps rather than comprehensive — matching anchor 4, not the fully concrete anchor 5.

4 / 5

Completeness

It clearly answers both questions: "Manages Python package dependencies" states the what, and "Use when adding, upgrading, removing, or syncing Python/pypi packages in projects or libs" gives an explicit when with concrete trigger phrases — a direct match for anchor 5.

5 / 5

Trigger Term Quality

Natural terms like "Python", "pypi", "packages", and the action verbs (adding, upgrading, removing, syncing) give good keyword coverage, but common variations users would actually say — "install", "uv", "pip", "requirements" — are missing, placing it between anchors 3 and 5 at 4.

4 / 5

Distinctiveness Conflict Risk

The "Python/pypi packages" qualifier carves out a clear niche with low conflict risk against non-Python skills, but it does not distinguish itself from other Python dependency managers (pip, poetry) and "projects or libs" is vague, so minor overlap risk keeps it at anchor 4 rather than 5.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SpecterOps/Nemesis
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.