CtrlK
BlogDocsLog inGet started
Tessl Logo

protected-files

Zero-dependency bootstrap files that must never import npm packages or SDK code

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.copilot/skills/protected-files/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

93%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exemplary lean guardrail skill: authoritative path table, unambiguous rules with allowlisted modules, concrete anti-patterns, and a clear procedure for extending the protected list. The only minor gap is that the new-utility workflow doesn't explicitly close the loop by running the regression test it prescribes.

DimensionReasoningScore

Conciseness

The body is lean: a five-row path table, terse ❌/✅ rules, a short anti-pattern list, and a three-step procedure, with no explanations of concepts Claude already knows. Every section carries unique, load-bearing information — fits anchor 5.

5 / 5

Actionability

Guidance is fully concrete: exact file paths, exact prohibitions ('NEVER add `import` or `require` statements referencing packages outside `node:*`'), an enumerated allowlist of built-in modules, and a named test file ('detect-squad-dir-zero-deps.test.ts') as a copyable pattern. For an instruction-only rule skill this is copy-paste-ready guidance — anchor 5.

5 / 5

Workflow Clarity

The 'Adding New Bootstrap Utilities' sequence is clearly numbered and the batch-operation risk (sweeping refactors) has an explicit validation checkpoint ('DO check this list before sweeping refactors' plus regression tests), so the missing-validation cap does not apply. Not 5 because the new-utility workflow stops at 'write a matching regression test' without a step to run it and confirm it passes — anchor 4 ('clear sequence, minor validation gaps').

4 / 5

Progressive Disclosure

No bundle files exist and the ~45-line body needs none; sections are well-organized and non-overlapping, with a single one-level reference to a test file in the repo. Per the simple-skill scoring note, well-organized sections alone warrant anchor 5.

5 / 5

Total

19

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is distinctive and states the core constraint with concrete terminology, but it omits any explicit 'when to use this' trigger guidance and misses the primary natural trigger phrasing (sweeping refactors / fs-to-StorageProvider conversions) that the body itself identifies. Adding a 'Use when...' clause would substantially raise completeness and trigger-term quality.

Suggestions

Add an explicit trigger clause, e.g. 'Use when touching files in packages/squad-cli/src/cli/core/ or when running sweeping refactors that convert fs calls to StorageProvider/SDK abstractions.'

Include the natural user phrasings from the body ('refactor', 'convert fs calls to StorageProvider', 'squad-cli startup') as trigger terms so the skill surfaces when users describe those tasks.

State the consequence briefly ('CLI crashes at startup') to sharpen the 'what' and distinguish this from generic dependency-linting skills.

DimensionReasoningScore

Specificity

Names the domain concretely ('zero-dependency bootstrap files', 'import npm packages or SDK code') and states the key constraint, but lists no concrete capabilities or actions. Fits anchor 3 — domain named, not comprehensive — rather than 2 (not generic) or 4 (no multi-action list).

3 / 5

Completeness

The 'what' is clear (bootstrap files that must never import npm packages or SDK code), but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines. Not 4 because 'when' is entirely absent, not merely imprecise.

3 / 5

Trigger Term Quality

'bootstrap files', 'npm packages', 'SDK code', and 'import' are relevant natural terms for this niche, but the most likely user phrasing for this skill's trigger scenario — 'refactor', 'convert fs calls to StorageProvider' — is absent. Fits anchor 3 ('some relevant keywords but missing common variations or synonyms').

3 / 5

Distinctiveness Conflict Risk

'Zero-dependency bootstrap files that must never import npm packages or SDK code' defines a clear niche with distinct triggers; no other plausible skill overlaps with this phrasing. Fits anchor 5 rather than 4 since no closely related skill would collide.

5 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
bradygaster/squad
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.