CtrlK
BlogDocsLog inGet started
Tessl Logo

endor-upgrade-impact

Analyze the impact of upgrading a dependency before you do it. Use when the user says "should I upgrade lodash", "what breaks if I update express", "upgrade impact", "endor upgrade", "breaking changes from upgrading", or wants to find the safest version that fixes vulnerabilities. Uses pre-computed Endor Labs data — no scanning required. Do NOT use for just checking vulnerabilities (/endor-check) or applying a fix (/endor-fix).

100

Quality

100%

Does it follow best practices?

Impact

Pending

No eval scenarios have been run

SecuritybySnyk

Advisory

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Discovery

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This is an excellent skill description that covers all key dimensions thoroughly. It provides specific actions, natural trigger phrases users would actually say, explicit 'Use when' and 'Do NOT use' clauses, and clear boundaries distinguishing it from related skills. The negative boundary guidance is particularly effective for disambiguation in a multi-skill environment.

DimensionReasoningScore

Specificity

Lists concrete actions: analyze upgrade impact, find safest version that fixes vulnerabilities, uses pre-computed Endor Labs data. Also specifies what it does NOT do (checking vulnerabilities, applying fixes), which adds clarity.

3 / 3

Completeness

Clearly answers both 'what' (analyze dependency upgrade impact, find safest version fixing vulnerabilities) and 'when' (explicit 'Use when' clause with multiple trigger examples, plus 'Do NOT use' negative boundaries).

3 / 3

Trigger Term Quality

Excellent coverage of natural trigger phrases: 'should I upgrade lodash', 'what breaks if I update express', 'upgrade impact', 'endor upgrade', 'breaking changes from upgrading'. These are realistic phrases users would actually say.

3 / 3

Distinctiveness Conflict Risk

Highly distinctive with explicit negative boundaries distinguishing it from /endor-check and /endor-fix. The focus on pre-upgrade impact analysis creates a clear niche that is unlikely to conflict with vulnerability scanning or fix-application skills.

3 / 3

Total

12

/

12

Passed

Implementation

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is an excellent skill that provides a clear, actionable workflow for dependency upgrade impact analysis. It's concise without sacrificing completeness, has well-structured progressive disclosure with appropriate external references, and includes proper error handling. The conditional steps (filtering for specific packages, fetching CIA only on request) demonstrate thoughtful workflow design.

DimensionReasoningScore

Conciseness

The content is lean and efficient. It doesn't explain what dependencies are, what vulnerabilities are, or how Endor Labs works conceptually. Every section serves a direct purpose with no padding or unnecessary context.

3 / 3

Actionability

Provides fully executable bash commands with specific flags, filters, and field masks. The output template is copy-paste ready with clear placeholder variables. The table format for presenting results is concrete and specific.

3 / 3

Workflow Clarity

Clear 4-step sequence with explicit checkpoints: stop if project not found, filter based on user intent, escalate CIA details only on request. The conditional logic (specific package vs general, high-risk on demand only) is well-defined with clear decision points.

3 / 3

Progressive Disclosure

The main workflow is concise and self-contained. Advanced details (install commands, data source policy, authentication recovery) are referenced as one-level-deep links to separate files. CIA details are deferred to Step 4 only when needed.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation11 / 11 Passed

Validation for skill structure

No warnings or errors.

Repository
endorlabs/skills-ideas
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.