CtrlK
BlogDocsLog inGet started
Tessl Logo

ci-validation-gates

Defensive CI/CD patterns: semver validation, token checks, retry logic, and draft detection

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.copilot/skills/ci-validation-gates/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, actionable pattern catalog with executable code, explicit validation checkpoints, and failure-mode analysis — no filler or over-explanation. Main gaps are minor: undefined variables in the retry snippet, no code for the draft-release gate, and slight redundancy between the patterns and failure-modes table.

DimensionReasoningScore

Conciseness

The body is lean and incident-derived (e.g. "Propagation: typically 5-30s, up to 2min in rare cases") with no padding of concepts Claude already knows, but the Known Failure Modes table partially restates the pattern sections, leaving minor trimmable redundancy that keeps it below a 5.

4 / 5

Actionability

Two copy-paste-ready YAML snippets with real commands and concrete parameters (Automation-token creation path, 5 attempts at 15s intervals) anchor the guidance, but $PACKAGE/$VERSION are used undefined in the retry snippet and the draft-release gate gives no code, leaving minor gaps.

4 / 5

Workflow Clarity

Each pattern carries explicit validation and failure output (semver check exits 1, retry loop exits on success and fails after max attempts, "MUST verify the package manifests and lockfile are unchanged afterward") with feedback loops present; it is a pattern catalog rather than an end-to-end sequenced workflow with checklists, so it fits anchor 4 rather than 5.

4 / 5

Progressive Disclosure

Well-organized sections with no buried or nested references, and no bundle files exist so nothing is misplaced in SKILL.md; at ~95 lines it exceeds the <50-line simple-skill exception and the installer-gates section is denser than the rest, fitting anchor 4 rather than 5.

4 / 5

Total

16

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, appropriately concise description in third person that names four concrete capabilities, but it lacks any "when to use" trigger guidance and misses natural user phrasings like npm publish or release workflow. Adding a Use-when clause would lift both completeness and trigger quality.

Suggestions

Append an explicit trigger clause, e.g. "Use when creating or debugging npm publish, release, or CI workflows, or when publishes fail with EOTP, 4-part versions, or 404 verification errors."

Include natural user-vocabulary keywords such as "npm publish", "release workflow", and "GitHub Actions" so the description matches how users actually phrase these requests.

Consider mentioning the installer/generated-artifact gates so description coverage matches the body's actual scope.

DimensionReasoningScore

Specificity

Lists several concrete, named actions in third person ("semver validation, token checks, retry logic, and draft detection") matching the anchor-4 example, but omits installer/artifact gates covered in the body, so coverage is not comprehensive enough for a 5.

4 / 5

Completeness

The "what" is clear (defensive CI/CD patterns with four named capabilities), but there is no "Use when..." clause or equivalent trigger guidance, which the judging guidelines explicitly cap at 3.

3 / 5

Trigger Term Quality

"CI/CD" and "semver" are natural domain keywords, but common user phrasings like "npm publish", "release workflow", "pipeline", or "EOTP" are absent, placing it between anchors 3 and 4 but noticeably closer to 3.

3 / 5

Distinctiveness Conflict Risk

The publish/CI-gate niche is clearly distinguishable with distinct triggers (semver validation, token type checks); minor overlap risk remains with broad generic CI/CD skills.

4 / 5

Total

14

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
bradygaster/squad
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.