CtrlK
BlogDocsLog inGet started
Tessl Logo

contrib-pr-review

Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.claude/skills/contrib-pr-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced review protocol with executable commands and explicit decision thresholds throughout. Its main costs are duplicated guidance notes and an over-long inline comment-template section, plus one internally inconsistent test-coverage script that mixes remote and local file access.

Suggestions

Delete or merge the "Important Notes" section: "Security is checked, not publicized", "The bots already reviewed code", and the ask-before-posting rule each restate guidance already given in steps 1 and 6.

Fix step 3's test-coverage script: it lists files via gh api but then runs `find tests/` and `grep -r ... tests/` against a local checkout that is never created — either add a checkout step or query the files remotely via the GitHub code-search/files API.

Move the comment structure templates and both illustrative examples into a references/comment-templates.md file, keeping only the length/style rules and a pointer inline.

DimensionReasoningScore

Conciseness

The body avoids explaining concepts Claude already knows and is mostly dense operational content, but there is real duplication: the "Important Notes" section restates three points already made in steps 1 and 6 ("Security is checked, not publicized", "The bots already reviewed code", the ask-first rule), and the comment-drafting section provides both full structural templates and two illustrative examples that each say "match the wording to the PR". This fits anchor 3 (mostly efficient but could be tightened) better than anchor 4's minor-trims-only bar.

3 / 5

Actionability

Nearly everything is executable: complete gh api/gh pr commands, numeric size thresholds ("< 200 lines: ✅ Excellent size"), output templates, and structured comment formats. The gap is step 3's test-coverage script, which pipes remote gh api file listings into local `find tests/` and `grep -r ... tests/` commands that assume a checkout never established in the workflow — concrete guidance with a genuine flaw, matching anchor 4.

4 / 5

Workflow Clarity

Six numbered steps in a coherent sequence with explicit gates ("Do NOT approve until issues addressed or confirmed false positives", "Always ask user before posting", draft-and-show-before-posting for security concerns). Not a destructive or batch operation, so no validation cap applies; step 2's workflow-enable logic is loosely reasoned (the requested_reviewers call does not actually report workflow status), keeping it below anchor 5.

4 / 5

Progressive Disclosure

The single SKILL.md is well sectioned with clear headers and no nested references, but roughly 70 lines of comment templates and illustrative examples in the "Draft PR Comment" section are inline content that belongs in a references file for a skill this size. Good structure with a minor organization gap fits anchor 4.

4 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concise, with a clear what and an explicit when-to-use clause. Its weaknesses are minor — the trigger vocabulary could include more synonyms, and it omits the PR-comment drafting that the skill body spends half its length on.

DimensionReasoningScore

Specificity

Names the domain (contribution PR review) and lists four concrete check areas ("security concerns, test coverage, size appropriateness, and intent alignment"), but the comment-drafting workflow that makes up half the skill is unmentioned — a minor coverage gap matching anchor 4 rather than the comprehensive coverage of anchor 5.

4 / 5

Completeness

It answers both questions: a clear what ("Review a contribution PR for safety, quality, and readiness" plus the enumerated checks) and an explicit when ("Use when reviewing external contributions"). The when-clause is present but narrower and less phrase-rich than anchor 5's concrete trigger phrases, so it fits anchor 4.

4 / 5

Trigger Term Quality

"contribution PR", "reviewing external contributions", and the named check areas are natural phrases a user would say, but common synonyms like "pull request", "first-time contributor", or "open source" are missing, fitting anchor 4 (good coverage, a few natural terms missing) rather than anchor 5's synonym-and-extension completeness.

4 / 5

Distinctiveness Conflict Risk

The external-contribution framing ("Use when reviewing external contributions") carves a distinct niche from own-branch code-review skills, with only minor overlap risk against a generic "review this PR" request; this matches anchor 4 (mostly distinct) rather than anchor 5's minimal-conflict niche or anchor 3's broader overlap.

4 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
homeassistant-ai/ha-mcp
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.