CtrlK
BlogDocsLog inGet started
Tessl Logo

custom-dependency-pr-solver

Batch-processes Dependabot PRs in Fusion Framework: list, confirm, checkout, rebase, review, changeset, validate, comment, and merge high-confidence updates. USE FOR: process all Dependabot PRs, clear dependency backlog, batch-merge safe dependency updates. DO NOT USE FOR: feature PRs, non-Dependabot PRs, single-PR deep review, or updates needing manual code changes.

83

1.23x
Quality

96%

Does it follow best practices?

Impact

85%

1.23x

Average score across 1 eval scenario

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exemplary instruction-style skill body: lean, command-driven, and sequenced with validation checkpoints, confidence gates, and abort-on-conflict feedback loops appropriate to a batch PR-mutation workflow. Bundle structure is well organized with one-level-deep, clearly signaled asset references.

DimensionReasoningScore

Conciseness

The ~105-line body is lean with zero concept explanation — no 'what Dependabot is', no library primers, no padding. Every section (gates, inputs, workflow, output, safety) earns its tokens, matching the 5 anchor 'every token earns its place'.

5 / 5

Actionability

The workflow is fully executable with copy-paste-ready commands: `gh pr list --author "app/dependabot" --state open --json ...`, `git rebase origin/<base-branch>`, `git push --force-with-lease`, `pnpm install --frozen-lockfile`, `pnpm test && pnpm build && pnpm -w check`, and `gh pr merge <number> --squash --admin`. Delegation steps name concrete artifacts (`fusion-dependency-review`, the instructions file, the two asset templates), so no guidance is vague.

5 / 5

Workflow Clarity

Eight clearly sequenced steps with explicit validation (`pnpm test && pnpm build && pnpm -w check`), feedback loops (abort-on-conflict then mark `needs-manual-intervention` and continue; lockfile fix-and-commit path; trivial-fix-only boundary), confidence-gated merge decisions, and a final per-PR status report. This is a batch/destructive-capable skill and it fully satisfies the validation requirement, matching the 5 anchor.

5 / 5

Progressive Disclosure

The body is a clear overview that cleanly delegates bulk content one level deep: comment templates live in `assets/research-comment-template.md` and `assets/verdict-comment-template.md` (both verified present in the bundle) and are referenced by exact path, and changeset rules defer to `.github/instructions/dependabot-pr.instructions.md`. Content is appropriately split and navigation is easy, matching the 5 anchor.

5 / 5

Total

20

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete, and comprehensive on capabilities, with explicit USE FOR trigger phrases and a DO NOT USE boundary clause that sharply reduces conflict risk. The only weakness is a few missing natural trigger synonyms.

Suggestions

Add one or two more natural trigger variations such as 'update outdated dependencies' or 'handle Dependabot version bumps' to broaden keyword coverage.

Consider mentioning the GitHub/PR context (e.g. 'open pull requests on GitHub') so users phrasing requests around PRs generally still match.

DimensionReasoningScore

Specificity

The description enumerates nine concrete actions — "list, confirm, checkout, rebase, review, changeset, validate, comment, and merge high-confidence updates" — comprehensively covering the workflow in third-person voice. It matches the 5 anchor (multiple specific concrete actions, comprehensive) and is not the 4 anchor because coverage has no visible gaps.

5 / 5

Completeness

Both questions are answered explicitly: what ("Batch-processes Dependabot PRs in Fusion Framework: list, confirm, checkout, rebase, review, changeset, validate, comment, and merge") and when ("USE FOR: process all Dependabot PRs, clear dependency backlog, batch-merge safe dependency updates") with concrete trigger phrases. This matches the 5 anchor exactly and is above the 4 anchor, whose 'when' is less explicit.

5 / 5

Trigger Term Quality

Natural trigger phrases are strong: "process all Dependabot PRs", "clear dependency backlog", "batch-merge safe dependency updates", with synonym coverage (Dependabot PRs / dependency backlog / dependency updates). It falls just below the 5 anchor because a few natural user phrasings (e.g. "update dependencies", "outdated packages", "version bumps") are absent.

4 / 5

Distinctiveness Conflict Risk

The "DO NOT USE FOR: feature PRs, non-Dependabot PRs, single-PR deep review, or updates needing manual code changes" clause plus the tightly scoped Fusion Framework/Dependabot niche gives it a clear niche with distinct triggers and minimal conflict risk, matching the 5 anchor.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_field

'metadata' should map string keys to string values

Warning

Total

15

/

16

Passed

Repository
equinor/fusion-framework
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.