CtrlK
BlogDocsLog inGet started
Tessl Logo

oma-qa

Quality assurance specialist for security, performance, accessibility, comprehensive testing, and quality standard alignment. Use for test, review, security audit, OWASP, coverage, lint work, and ISO/IEC 25010 or ISO/IEC 29119-aligned QA recommendations.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/oma-qa/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

62%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill has a well-sequenced, validated review workflow and some concrete commands, but it is padded with abstract process-meta scaffolding and references resource files that are not present in the bundle. Tightening the template overhead and supplying the referenced resources would lift conciseness and progressive disclosure.

Suggestions

Trim the meta-framework scaffolding (Scheduling subsections, the SSL-primitive Actions table, parallel Scenes/Transitions/Effects framing) to lean, action-oriented guidance so conciseness reaches the level-3 pattern.

Provide the referenced bundle files (resources/execution-protocol.md, examples.md, iso-quality.md, checklist.md, self-check.md, error-playbook.md) or remove the dangling references so progressive disclosure points to real, navigable content.

Expand the canonical command path into stack-specific, copy-paste-ready commands with expected output checks so actionability reaches the level-3 executable pattern.

DimensionReasoningScore

Conciseness

The body is mostly efficient and free of basic-concept explanation, but carries heavy meta-framework scaffolding (the "Scheduling" section, an Actions table with an "SSL primitive" column of READ/SELECT/CALL_TOOL tokens, and parallel Scenes/Transitions/Effects framing) that is template overhead Claude does not need; not the lean level-3 pattern.

2 / 3

Actionability

Concrete commands are present ("npm audit", "bandit -r .", "lighthouse <url>") and severity definitions are specific, but much of the body is abstract process description (PREPARE/ACQUIRE/REASON scenes, "Branches by review type") rather than executable, copy-paste-ready guidance, matching the level-2 'some concrete guidance but incomplete' anchor.

2 / 3

Workflow Clarity

The PREPARE→ACQUIRE→REASON→VERIFY→FINALIZE sequence is explicit, and the VERIFY scene ("Reproduce findings and reject false positives") plus the failure-recovery rule ("If a finding cannot be reproduced, do not report it as a finding") form a clear validation feedback loop, matching the level-3 anchor.

3 / 3

Progressive Disclosure

References are one level deep and clearly listed, but the body is a single monolithic file holding the full meta-framework inline, and the referenced resources (resources/execution-protocol.md, examples.md, iso-quality.md, etc.) do not exist in any bundle directory, so navigation points to missing files; caps at level-2.

2 / 3

Total

9

/

12

Passed

Description

90%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states the specialty, gives an explicit 'Use for' trigger clause with natural terms, and occupies a distinct QA/security-audit niche. The only weakness is that it catalogs capability domains rather than concrete actions, keeping specificity at 2 rather than 3.

DimensionReasoningScore

Specificity

Names the QA specialty domains ("security, performance, accessibility, comprehensive testing, and quality standard alignment") but lists domains rather than concrete actions like 'run npm audit' or 'reproduce findings'; not the level-3 multiple-concrete-action pattern, yet clearer than the level-2 'names domain and some actions'.

2 / 3

Completeness

It explicitly answers both what ("Quality assurance specialist for...") and when ("Use for test, review, security audit, OWASP, coverage, lint work..."), matching the level-3 anchor with an explicit 'Use for' trigger clause.

3 / 3

Trigger Term Quality

The "Use for test, review, security audit, OWASP, coverage, lint work, and ISO/IEC 25010 or ISO/IEC 29119-aligned QA recommendations" clause covers natural terms a user would actually say when needing this skill.

3 / 3

Distinctiveness Conflict Risk

The QA/security-audit/standards niche with distinct triggers (OWASP, WCAG, ISO/IEC 25010, ISO/IEC 29119, lint, coverage) is clearly distinguishable from general coding skills and unlikely to trigger the wrong skill.

3 / 3

Total

11

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
first-fluke/oh-my-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.