CtrlK
BlogDocsLog inGet started
Tessl Logo

dependency-triage

Scan package manifests and lockfiles for outdated and vulnerable dependencies. Classify by severity and update type.

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./starters/dependency-sweeper-opencode/skills/dependency-triage/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

80%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is lean, actionable, and well-organized for a simple skill, but it lacks explicit validation/verification checkpoints for batch dependency updates, capping workflow clarity.

Suggestions

Add an explicit verification step before escalating or applying changes, e.g. 'After classifying, verify the suggested version resolves the listed CVE and has no peer-dependency conflicts before recommending an action.'

Include a feedback loop for lockfile conflicts (detect → re-resolve or escalate-human) rather than only stating the conflict condition.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — output schema, classification rules, and a short rules list with no padding or explanation of basic concepts, so every token earns its place.

3 / 3

Actionability

It gives a concrete copy-paste-ready output template plus explicit, executable classification and action rules ('patch', 'escalate-human', 'skip', 'denylist → escalate-human'), providing fully actionable guidance.

3 / 3

Workflow Clarity

Classification rules and per-package actions are sequenced, but for a batch dependency operation there are no explicit validation/verification checkpoints or feedback loops, which the rubric caps at 2 for destructive/batch operations.

2 / 3

Progressive Disclosure

A simple skill under 50 lines with no external references needed; content is well-organized into clear sections (output, classification, rules), which per the simple-skills note can score 3.

3 / 3

Total

11

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-differentiated with concrete actions and a clear niche, but it lacks an explicit 'Use when...' trigger clause and under-covers common user-facing trigger phrases.

Suggestions

Add an explicit 'Use when...' clause naming natural user phrasings such as 'Use when the user asks to check for outdated or vulnerable dependencies, update packages, or review lockfiles.'

Broaden trigger terms to include everyday phrasings like 'outdated dependencies', 'update packages', and 'security advisories' alongside the current technical vocabulary.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Scan package manifests and lockfiles for outdated packages and known CVEs' and 'Groups updates by risk (patch, minor, major)' — matching the level-3 anchor of multiple specific concrete actions.

3 / 3

Completeness

It clearly answers 'what' (scan and group updates by risk) but the 'when' is only implied via 'Use in dependency sweeper loops' rather than an explicit 'Use when...' trigger, which the guidelines cap at 2.

2 / 3

Trigger Term Quality

Relevant keywords like 'package manifests', 'lockfiles', 'CVEs', and 'dependency' are present, but common user-facing phrasings such as 'outdated dependencies', 'update packages', or 'vulnerable dependencies' are under-covered.

2 / 3

Distinctiveness Conflict Risk

The niche is clearly distinct — manifests/lockfiles, CVE scanning, and risk grouping for dependency sweeper loops — making it unlikely to trigger for unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
cobusgreyling/loop-engineering
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.