CtrlK
BlogDocsLog inGet started
Tessl Logo

use-devbox

Run commands inside a devbox environment when a directory provides one. If a `devbox.json` exists in the current directory (or an ancestor/subdir root), devbox can supply tools and scripts the bare shell lacks — e.g. psql, python, gcloud, node. If a binary is provided by devbox, prefer it over the system binary.

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured instruction skill: every command is concrete and executable, and error-recovery guidance (PATH fallback, search-before-add, ask-before-install) is present. The main cost is redundancy — the 'Key facts' section duplicates five points already stated, inflating token spend without adding information.

Suggestions

Delete or drastically trim the 'Key facts' section: all five bullets repeat earlier sections (install check, devbox.json location, PATH-inside-run-only, prefer run over shell, first-run slowness) — state each fact once in its own section.

Fold the detection/install/run steps into one short numbered sequence at the top so the end-to-end workflow is visible at a glance instead of implied across sections.

Consider moving the Services and Global packages sections (situational, less common) into a single 'Beyond one-off commands' section or a reference file to shorten the always-loaded body.

DimensionReasoningScore

Conciseness

The body is mostly lean and operational, but the 'Key facts' section restates five points already made verbatim-earlier ('check with `command -v devbox` and install via curl', 'devbox.json may live in the repo root or a subdir root', 'Prefer `devbox run` over `devbox shell`', 'first run ... can be slow'). That duplication is more than 'minor instances that could be trimmed', so it fits the 3 anchor rather than 4; it is not a 2 because no space is spent explaining concepts Claude already knows.

3 / 5

Actionability

Every section gives copy-paste-ready commands: `command -v devbox`, the curl install one-liner, `ls devbox.json 2>/dev/null || find . -maxdepth 2 -name devbox.json`, `devbox run psql "$MASTER_DB_URL" -c 'SHOW wal_level;'`, `devbox search`/`devbox add`, and `devbox services ls/up/stop`. The examples cover the common cases with real invocations, matching the 5 anchor.

5 / 5

Workflow Clarity

There is a clear implicit sequence (detect devbox.json → check installed → install with error recovery for PATH → run) and a numbered decision list for binary sourcing with a `devbox search` checkpoint and a user-confirmation gate before `devbox add`. It is a 4 rather than 5 because the steps are spread across sections with no single end-to-end sequence and some checkpoints (e.g. confirming devbox.json exists before running) are implicit; it is above 3 because checkpoints and error-recovery guidance are present.

4 / 5

Progressive Disclosure

The body is well-organized into clearly signaled sections (When to reach for it, Check it's installed, How to run, Project scripts, Services, Discovering more) with no bundle files, so nothing is buried or nested. It scores 4 rather than 5 because at ~119 lines it exceeds the simple-skill threshold and carries the duplicated 'Key facts' section that should either be merged into the body or split out — a minor organization gap, not the structural problems of a 3.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it clearly states what the skill does, gives an explicit and concrete trigger condition (presence of devbox.json), and occupies a distinctive niche. The only weakness is moderate coverage of capabilities — installation, scripts, and services go unmentioned.

DimensionReasoningScore

Specificity

The description names concrete actions ('Run commands inside a devbox environment', 'prefer it over the system binary') and concrete tools ('psql, python, gcloud, node'), but coverage is incomplete — package installation, project scripts, and services are unmentioned. It lists several specific actions with minor gaps, matching the 4 anchor rather than the comprehensive 5.

4 / 5

Completeness

It explicitly answers both 'what' ('Run commands inside a devbox environment when a directory provides one') and 'when' ('If a `devbox.json` exists in the current directory (or an ancestor/subdir root)') with a concrete trigger phrase. The 'when' is an explicit conditional rather than weakly implied, matching the 5 anchor and not the 4.

5 / 5

Trigger Term Quality

Natural trigger terms are present: 'devbox', '`devbox.json`', 'environment', and the tool names a user would mention. A few natural synonyms/variants (e.g. 'nix', 'jetify') are missing, which fits the 4 anchor (good coverage, a few terms missing) rather than the comprehensive 5.

4 / 5

Distinctiveness Conflict Risk

'devbox' is a unique, specific niche trigger tied to a concrete file ('devbox.json'), with minimal overlap risk against any other skill. This matches the 5 anchor (clear niche with distinct triggers); the 4 anchor would require some overlap with closely related skills, which is not the case.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
jetify-com/devbox
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.