CtrlK
BlogDocsLog inGet started
Tessl Logo

oma-backend

Implement server APIs, authentication, and application data access. Schema modeling and query tuning use oma-db.

53

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/oma-backend/SKILL.md

The canonical home for this skill is oma-backend in first-fluke/oh-my-agent

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured agent skill with a clear scene-based workflow, explicit validation and recovery steps, and genuinely concrete rules (stack detection, ORM safety, env-with-fallback integration). Its weaknesses are padding where it teaches known concepts (DRY/SOLID/KISS), and a references architecture that is clearly signaled but entirely dangling within this bundle, which undermines progressive disclosure.

Suggestions

Cut the explanation of DRY/SOLID/KISS in Guardrails down to the rule names (or drop the section) — Claude already knows these principles; this is the main conciseness cost.

Ship the referenced files (resources/execution-protocol.md, checklist.md, orm-reference.md, error-playbook.md) with the bundle or inline the essential checklist items, so the VERIFY checkpoint and References section are actually navigable.

Replace the abstract "SSL primitive" Actions table with the concrete router→service→repository skeleton or a stack-specific snippet pointer, which would also raise actionability toward 5.

DimensionReasoningScore

Conciseness

The body is mostly efficient (terse core rules, tables, command snippets), but it explains concepts Claude already knows — "DRY (Don't Repeat Yourself)", "Single Responsibility: Classes and functions should have one responsibility", "KISS: Keep it simple and clear" — and the abstract "SSL primitive" action table adds bulk without execution value.

3 / 5

Actionability

For an instruction-only skill the guidance is concrete: literal stack-detection files ("pyproject.toml, package.json, Cargo.toml, go.mod"), executable commands (`rg --files`, `rg "route|router|service|repository|model|schema|migration" .`), an exact fallback marker format (`// TODO(oma-deferred): integrate <vendor> when key is provisioned`), and 13 specific rules. Minor gaps: no worked code example of the router→service→repository pattern and verification commands are deferred to the project.

4 / 5

Workflow Clarity

The PREPARE→ACQUIRE→ACT→VERIFY→FINALIZE sequence is clear, VERIFY is an explicit validation checkpoint ("Run relevant lint, type, test, migration, and checklist commands"), and there is a stated feedback loop ("If verification fails, fix root cause before handoff") plus a Failure and recovery section. Minor gap: the concrete checklist/validation commands live in referenced files rather than inline, so checkpoints are named but not directly executable from SKILL.md.

4 / 5

Progressive Disclosure

The References section is well-labeled with one-level-deep pointers ("Execution steps (follow for the selected task): resources/execution-protocol.md", "Checklist (run before handoff): resources/checklist.md"), but none of the referenced files (resources/*.md, ../_shared/core/*.md, stack/*, variants/stack.schema.json) exist in the provided bundle — the bundle is SKILL.md alone — so navigation dead-ends, and cross-skill pointers plus inlined stack-manifest details keep this from a 4.

3 / 5

Total

14

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has a clear what and an explicit boundary against the sibling oma-db skill, but it reads as a compressed capability list rather than a trigger-rich description. Adding a "Use when..." clause with natural terms (REST, GraphQL, endpoint, auth, migration, backend) would lift completeness and trigger quality substantially.

Suggestions

Add an explicit trigger clause, e.g. "Use when the user asks for API, endpoint, REST/GraphQL, auth, migration, or server-side work" — this directly addresses the completeness cap of 3 and the missing 'when'.

Include natural trigger vocabulary users actually say ("auth", "REST", "endpoint", "backend", "migration") rather than only formal categories like "application data access".

Mention migrations and background jobs/queues in the what-clause so the description's coverage matches the skill's actual scope.

DimensionReasoningScore

Specificity

"Implement server APIs, authentication, and application data access" names the domain and three capability areas, but they are coarse categories rather than concrete actions, and significant coverage from the body (migrations, background jobs, business logic, repositories) is missing — more than minor gaps.

3 / 5

Completeness

The "what" is clearly stated ("Implement server APIs, authentication, and application data access"), but there is no "Use when..." or equivalent trigger clause; the oma-db sentence is a scope boundary, not usage guidance, which caps completeness at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

"server APIs" and "authentication" are natural user terms, but common variations the body itself lists — REST, GraphQL, endpoint, auth, backend, migration, service, router — are absent, leaving moderate keyword coverage without synonyms.

3 / 5

Distinctiveness Conflict Risk

The backend niche (server APIs, auth, data access) is mostly distinct, and "Schema modeling and query tuning use oma-db" explicitly disambiguates against the closest neighboring skill, leaving only minor overlap risk (e.g., generic "application data access" could still pull ORM/database work).

4 / 5

Total

13

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
first-fluke/oh-my-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.