CtrlK
BlogDocsLog inGet started
Tessl Logo

github-ops

Operates GitHub via gh CLI and REST/GraphQL — PRs, issues, Actions, repos, collaborators, org permissions, 2FA — with explicit target, authorization, and independent readback. Use when a write reports success but state didn't change, or choosing gh/REST/GraphQL/UI-only. Not for local Git recovery (use git-safety-net), maintainer PR review (use github-review-pr), or upstream contribution (use github-contributor).

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Excellent skill body: a lean operating contract with concrete commands, a rigorously validated workflow (independent readback per mutation type, bounded polling, honest end-state reporting), and clean progressive disclosure through a task-indexed routing table to real reference files. Only marginal tightening of repeated authorization caveats would improve token efficiency.

DimensionReasoningScore

Conciseness

The body is dense and prescriptive — command snippets, a routing table, and a readback table with no explanations of concepts Claude already knows. Minor trimming is possible: the authorization/confirmation caveats recur across sections 1, 3, and 8 (e.g. "Do not send a comment... whose recipient or content was not authorized" vs. later restatements), which fits the efficient-with-minor-over-explanation anchor rather than the every-token-earns-its-place anchor.

4 / 5

Actionability

Guidance is fully executable: copy-paste-ready commands for pre-write verification (gh auth status, gh api user, gh repo view with --json field lists), an ordered interface-preference rule, and a five-command read-only quick reference covering the common inspection cases. With OWNER/REPO substitution the commands run as written, matching the fully-executable anchor.

5 / 5

Workflow Clarity

The eight-step universal operating contract is a clear sequence (classify → bind identity → read authority/preview → choose interface → mutate once → readback → report → authenticate scoped) with explicit validation checkpoints: a per-mutation-type readback table, bounded polling for async state, honest four-state reporting, and failure/partial handling with recovery. The destructive/batch validation cap does not apply because validation and feedback loops are thoroughly present.

5 / 5

Progressive Disclosure

The body is a concise overview with a task→reference routing table pointing to nine one-level-deep reference files, all of which exist in references/ with matching names, plus targeted pointers (e.g. loading references/ghcr_publishing.md before an image push). This matches the clear-overview-with-well-signaled-references anchor.

5 / 5

Total

19

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete, and comprehensive on capabilities, with explicit trigger and exclusion clauses that disambiguate it from neighboring skills. The main gap is that its Use-when triggers cover edge scenarios (failed writes, interface selection) rather than the mainline GitHub operations users most often request.

DimensionReasoningScore

Specificity

The description lists multiple concrete capability areas — "PRs, issues, Actions, repos, collaborators, org permissions, 2FA" — plus operational specifics like "explicit target, authorization, and independent readback", giving comprehensive coverage of the domain. It matches the anchor for multiple specific concrete actions with comprehensive coverage, and is not the level below (which would imply only minor gaps in a shorter action list).

5 / 5

Completeness

The "what" is clear (operates GitHub via gh CLI and REST/GraphQL across named resource types) and an explicit "Use when a write reports success but state didn't change, or choosing gh/REST/GraphQL/UI-only" clause is present, so it is above the both-present-but-weak anchor. It falls short of a 5 because the when-clauses target secondary scenarios — verification failures and interface choice — while mainline requests like "create a PR" or "add a collaborator" have no matching trigger phrase.

4 / 5

Trigger Term Quality

Good keyword coverage of natural terms users say: "PRs", "issues", "Actions", "repos", "collaborators", "2FA", "gh CLI", "REST/GraphQL". A few natural phrases are missing — "pull request" is never spelled out, and common requests like "merge", "branch", or "secret" do not appear — so it fits the anchor for good coverage with a few natural terms missing rather than the comprehensive-with-synonyms anchor.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear niche (GitHub-hosted state via gh/REST/GraphQL) and explicitly disambiguates sibling skills — "Not for local Git recovery (use git-safety-net), maintainer PR review (use github-review-pr), or upstream contribution (use github-contributor)" — minimizing conflict risk, which matches the clear-niche anchor exactly.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
daymade/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.