CtrlK
BlogDocsLog inGet started
Tessl Logo

scripts-and-automation

Choose or maintain repository Make/script workflows, builds, dependency selection, generated artifacts, and security CLI tools. Routes release work and documents local administration and standalone login commands.

62

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.codex/skills/scripts-and-automation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable reference for repository automation: concrete commands, clear side-effect scoping, sequenced workflows with validation, and well-signaled one-level-deep references. The main improvement opportunities are tightening verbose sections and moving long inline target/conformance detail into reference files.

DimensionReasoningScore

Conciseness

The body is dense with repo-specific facts Claude cannot know (Make target semantics, side-effect scopes, pinned tools) and does not explain general concepts, so nearly every token earns its place — fitting 'efficient; minor instances of over-explanation'. It is not a 5 because some sections could be tightened (repeated routing to release-and-versioning, the long Security Dependency Version output-formatting detail) and inline version pins (Go 1.26.8, Node 24, tested v1.1.0) add time-sensitive detail.

4 / 5

Actionability

The guidance is fully executable and copy-paste ready: exact make targets with variables ('make build', 'make test', 'TEST_DIR', 'CONFORMANCE_RESULTS'), concrete go commands, and two complete bash snippets for the replacement workflow. Specific examples cover the common cases (build, test, focused test, dependency upgrade, cleanup), matching the 5 anchor.

5 / 5

Workflow Clarity

Multi-step processes like the go-authcrunch replacement (read required version → replace → validate this module → keep until published → remove and test) and dependency upgrade (go get → tidy → verify → inspect diff) are clearly sequenced with explicit validation steps, and the Acceptance criteria section acts as a checklist for batch/destructive operations like cleanup and license rewrites. It falls short of 5 because some flows (devbuild, fmtcfg, OIDC conformance runs) describe pre-checks but lack explicit post-run validation or error-recovery loops.

4 / 5

Progressive Disclosure

Structure is good: a clear overview, well-organized sections, and four real, one-level-deep reference files (caddy-authenticator.md, test-resources.md, codeql.md, local-user-commands.md) each clearly signaled with a stated purpose, plus cross-links to sibling skills. It is not a 5 because substantial detail (the ~60-line Command Selection target list, OIDC conformance bullets, and Security Dependency Version output formats) is inlined in SKILL.md where a reference file would better keep the overview lean.

4 / 5

Total

17

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, third-person description with a clear 'what' and mostly distinct territory, but it lacks any explicit 'when to use' trigger guidance, which caps completeness and weakens discoverability. Adding a 'Use when...' clause with natural user phrasings would lift the two lowest-weighted dimensions.

Suggestions

Append a trigger clause such as 'Use when asked to run or maintain make targets, build or clean the repository, update Go dependencies, or use the security CLI commands.'

Include natural user phrasings and synonyms users would actually say (e.g., 'make targets', 'run tests', 'update dependencies', 'clean build artifacts') alongside the current terminology.

State the testing/validation scope explicitly (e.g., 'go test and report generation') so the 'what' coverage is comprehensive.

DimensionReasoningScore

Specificity

The description lists several concrete action areas — "Choose or maintain repository Make/script workflows, builds, dependency selection, generated artifacts, and security CLI tools" plus "Routes release work and documents local administration and standalone login commands" — with only minor gaps in coverage (e.g., testing/CI validation is not named). It matches the anchor 'Lists several specific actions; minor gaps in coverage' rather than 5, which would require comprehensive coverage, and clearly exceeds the 1-2 concrete actions of a 3.

4 / 5

Completeness

The 'what' is clear (choose/maintain Make workflows, builds, dependencies, artifacts, security CLI; route release work; document admin/login commands), but there is no 'Use when...' clause or equivalent explicit trigger guidance, which per the judging guidelines caps completeness at 3. It is not a 4 because the 'when' is entirely absent rather than merely imprecise.

3 / 5

Trigger Term Quality

Natural terms users would say are present — "Make/script workflows", "builds", "dependency selection", "security CLI tools", "release" — but common variations like "make targets", "run tests", "update dependencies", or "clean up artifacts" are missing. Good keyword coverage with a few natural terms absent fits the 4 anchor; it falls short of 5's comprehensive synonym/extension coverage.

4 / 5

Distinctiveness Conflict Risk

The combination of repository Make/script workflows, security CLI tools, and explicit routing of release/administration/login work carves a mostly distinct niche, with explicit routing reducing conflict. Minor overlap risk remains with sibling skills covering release-and-versioning and testing/CI, so it fits 'mostly distinct; minor overlap risk' rather than the minimal-conflict 5.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 14 suspicious

Warning

referenced_paths_exist

Referenced path issues: 5 missing, 4 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
greenpau/caddy-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.