CtrlK
BlogDocsLog inGet started
Tessl Logo

critique

Expertise in auditing and fixing repository scripts and GitHub Actions workflows to ensure technical robustness and security.

57

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./tools/gemini-cli-bot/.gemini/skills/critique/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a lean, highly actionable critique checklist with concrete commands, exact output strings, and specific detection examples. Its weak points are the missing fix-then-re-validate feedback loop in the batch workflow and the undefined structured-markdown format it mandates for logging.

Suggestions

Add an explicit re-validation step after applying fixes, e.g. 'After fixing, re-run the full checklist on the modified files before re-staging and issuing a verdict.'

Define or reference the 'Structured Markdown' format for lessons-learned.md (Task Ledger and Decision Log entry shapes) so the mandated logging is reproducible.

Fix the checklist numbering (two items are numbered 6) and consolidate the repeated 'git add' override instruction into one statement to trim redundancy.

DimensionReasoningScore

Conciseness

The body is a dense checklist that assumes Claude's knowledge of git, gh, and Node and explains no basics, but the 'You MUST use git add' instruction is repeated three times and the checklist numbering is broken (two items numbered 6), fitting anchor 4 (efficient with minor instances that could be trimmed).

4 / 5

Actionability

Concrete commands (git diff --staged --name-only, git add <file>, git reset <file>), exact magic strings ([REJECTED]/[APPROVED]), and specific detection examples (execSync, console.log('metric_name,123'), 'ignore all rules') make the guidance mostly executable, but the mandated 'Structured Markdown' format for lessons-learned.md is referenced without being defined anywhere, leaving a minor gap.

4 / 5

Workflow Clarity

The sequence (find staged files, run checklist, fix, re-stage, update ledger, output verdict) is clearly laid out and the checklist acts as validation, but this batch review-and-fix operation has no fix-then-re-validate feedback loop; it proceeds straight from applying fixes to the final verdict, so the rubric's cap for batch operations missing validation feedback loops applies.

3 / 5

Progressive Disclosure

A single-file skill with no bundle files and well-organized, clearly headed sections that are appropriately sized for an instruction skill; it falls short of anchor 5 only because at ~145 lines the detailed checklist and the undefined lessons-learned format could reasonably live in a referenced one-level-deep file.

4 / 5

Total

15

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description communicates a clear, reasonably specific capability around auditing and fixing repository scripts and GitHub Actions workflows, with a distinctive niche. Its main weaknesses are the complete absence of any 'when to use' trigger guidance and missing common synonyms like CI or pipeline.

Suggestions

Add an explicit 'Use when...' clause, e.g. 'Use when reviewing or fixing CI workflows, GitHub Actions, or repository automation scripts after a change.'

Include natural trigger synonyms such as CI, pipeline, automation, or continuous integration to broaden keyword coverage.

Replace the abstract 'to ensure technical robustness and security' with one or two more concrete actions (e.g. 'checks error handling, timing logic, and injection payloads').

DimensionReasoningScore

Specificity

"auditing and fixing repository scripts and GitHub Actions workflows" names the domain plus two concrete actions, but the qualifier "to ensure technical robustness and security" is abstract, matching anchor 3 (domain + 1-2 concrete actions, not comprehensive) rather than anchor 4's several specific actions.

3 / 5

Completeness

The description clearly states what the skill does (audit and fix scripts/workflows for robustness and security) but contains no 'Use when...' clause or any trigger guidance for when to invoke it, which the rubric explicitly caps at 3.

3 / 5

Trigger Term Quality

"GitHub Actions workflows", "repository scripts", "auditing", "fixing", and "security" are natural user phrases with good coverage, but common synonyms like CI, pipeline, automation, or continuous integration are missing, fitting anchor 4 (good coverage, a few natural terms missing).

4 / 5

Distinctiveness Conflict Risk

The niche of auditing repository scripts and GitHub Actions workflows is fairly distinct with concrete triggers, but it carries minor overlap risk with generic code-review or security-audit skills, matching anchor 4 (mostly distinct, minor overlap risk).

4 / 5

Total

14

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
google-gemini/gemini-cli
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.