CtrlK
BlogDocsLog inGet started
Tessl Logo

plugin-installer

Install validated Codex plugins from trusted sources with quarantine validation, provenance, and rollback. Use when distribution and installation are the primary goals.

61

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Failed to scan

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./Plugins/plugin-factory/fixtures/budget-archive/2026-04-21/deferred-store/skills/infrastructure_ops/plugin-installer/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An efficiently written, well-organized instruction skill hampered by missing referenced files and a stub install script pointing at a nonexistent .pyw, which leaves the core flow non-executable from the body.

Suggestions

Add the missing references/workflow.md (or inline the staged install protocol) so the quarantine → validate → install → rollback sequence is visible with explicit checkpoints.

Provide the missing install-plugin-from-github.pyw the CLI stub runs, or inline executable install code, so the central action is copy-paste ready.

Either create the other referenced files (contract.yaml, evals.yaml, task-profile.json) or remove them from the References list to keep navigation intact.

DimensionReasoningScore

Conciseness

Lean, terse bullet structure that assumes Claude's competence and never pads with explanations of what plugins or provenance are; every section earns its place.

5 / 5

Actionability

Concrete validation command, allowlist URLs, and explicit input/output field lists are present, but the core install flow is delegated to a missing references/workflow.md and the install script stub targets a nonexistent .pyw, so the central action is not executable from the body.

3 / 5

Workflow Clarity

Validation and fail-fast checkpoints exist, but the staged install sequence (quarantine → validate → install → rollback) is delegated to a missing workflow.md rather than shown in-body; the destructive/batch cap of 3 applies.

3 / 5

Progressive Disclosure

Clear section structure with well-signaled 'Read when:' navigation and one-level-deep references, but several referenced files (references/workflow.md, contract.yaml, evals.yaml, task-profile.json) do not exist in the bundle, so navigation is partly broken.

4 / 5

Total

15

/

20

Passed

Description

80%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states capabilities and an explicit use-trigger. The main weakness is a generic 'when' clause and missing natural synonyms a user might actually say.

Suggestions

Replace the generic 'Use when distribution and installation are the primary goals' with concrete user-facing trigger phrases (e.g., 'Use when the user asks to install, add, or deploy a plugin from a GitHub ref').

Add common synonyms and variations to broaden trigger matching (e.g., 'add', 'deploy', 'marketplace install', '.codex plugin').

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Install validated Codex plugins', 'quarantine validation, provenance, and rollback' — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both what (install validated plugins with provenance/rollback) and when ('Use when distribution and installation are the primary goals'), though the 'when' is generic rather than a concrete trigger-phrase list.

4 / 5

Trigger Term Quality

Natural phrases like 'install plugins' and 'distribution and installation are the primary goals' are present, but it misses common synonyms and variations a user might say.

4 / 5

Distinctiveness Conflict Risk

'Codex plugins from trusted sources' carves a clear install niche distinct from sibling creator/builder skills, with only minor overlap risk on shared 'plugin' territory.

4 / 5

Total

17

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

relative_links

Relative link issues: 1 missing, 1 suspicious

Warning

referenced_paths_exist

Referenced path issues: 6 missing

Warning

Total

13

/

16

Passed

Repository
jscraik/Agent-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.