CtrlK
BlogDocsLog inGet started
Tessl Logo

dependabot-snyk-pr-management

Interact with Dependabot and Snyk pull requests for dependency upgrades and security fixes. Documents Dependabot commands, javax/jakarta compatibility checks, safe merge workflows, and troubleshooting. Use when managing dependency upgrade PRs or security fix PRs.

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.opencode/skills/dependabot-snyk-pr-management/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced operational skill with strong safety validation and feedback loops for destructive and batch operations. Its weaknesses are repetition of the same commands across redundant sections and a monolithic single-file structure that inlines content better suited to reference files.

Suggestions

Consolidate the repeated @dependabot rebase/merge command examples into the command reference once, and have Scenarios 1, 2, and 4 link to it instead of restating the identical gh pr comment invocations.

Move the six Common Scenarios and the Troubleshooting section into a references/ file (e.g. references/scenarios.md), keeping SKILL.md as a lean overview of commands, safety rules, and the javax/jakarta policy with clearly signaled one-level links.

Trim promotional filler such as the "✅" bullet list justifying the rebase method, replacing it with a single sentence of when rebase is preferred.

DimensionReasoningScore

Conciseness

The body is mostly operational specifics Claude would not know, but repeats the same commands many times ("@dependabot rebase" appears in the workflow section, example usage, and Scenarios 1 and 2; merge commands recur across sections) and the "✅" checklist reads as promotional padding. It fits anchor 3 — could be tightened — rather than 4, where over-explanation would be only minor.

3 / 5

Actionability

Fully executable copy-paste guidance throughout: exact gh CLI commands, exact Dependabot comment commands, a working --jq filter for listing passing PRs, and YAML snippets for dependabot.yml. Only trivial blemish: the mis-indented "cd mockserver && ./mvnw clean test" step, which is still runnable.

5 / 5

Workflow Clarity

Multi-step workflows include explicit validation checkpoints and feedback loops: the Safety Rules checklist gates every merge/rebase/close, the rebase workflow adds a monitor step (gh pr checks --watch), the Snyk workflow has decision branches for each failure mode, and the batch-merge scenario explicitly forbids blind loops. This matches the anchor-5 example's validate -> fix -> retry structure.

5 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are absent); the 356-line SKILL.md inlines the full command table, six scenarios, and troubleshooting, which could live in reference files. Section headers and one-level pointers to repo files (AGENTS.md, .github/dependabot.yml) give it structure, but content that should be separate is inline — anchor 3, not 2, because navigation is still clear.

3 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that names a distinctive niche, lists concrete capabilities, and includes an explicit 'Use when' clause covering both upgrade and security-fix PRs. Its only weakness is a trigger list slightly narrower than the skill's full scope.

DimensionReasoningScore

Specificity

"Documents Dependabot commands, javax/jakarta compatibility checks, safe merge workflows, and troubleshooting" lists several specific actions with only minor gaps; not a 5 because core actions like rebase, ignore, and close are not enumerated.

4 / 5

Completeness

Both a clear what (commands, compatibility checks, merge workflows, troubleshooting) and an explicit when ("Use when managing dependency upgrade PRs or security fix PRs") are present; not a 5 because the when clause is narrower than the body's actual triggers and omits natural verb phrases.

4 / 5

Trigger Term Quality

Includes natural terms like "Dependabot", "Snyk", "pull requests", "dependency upgrades", "security fixes", and "dependency upgrade PRs or security fix PRs", but misses common user phrasings such as "rebase", "outdated", or "vulnerability".

4 / 5

Distinctiveness Conflict Risk

"Dependabot and Snyk" name a well-defined niche with distinct product-specific triggers, so conflict risk with other skills is minimal.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 suspicious

Warning

Total

15

/

16

Passed

Repository
mock-server/mockserver-monorepo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.