CtrlK
BlogDocsLog inGet started
Tessl Logo

pr-monitor

Monitors Dependabot and Snyk dependency upgrade PRs, automatically merging them when builds pass. Handles javax/jakarta compatibility validation and provides detailed status reporting. Use when the user says "monitor PRs", "watch builds", "auto-merge PRs", "merge passing PRs", or "watch dependency PRs".

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.opencode/skills/pr-monitor/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable skill body with a clear workflow and safety gates around auto-merging. Its main weaknesses are padding (duplicated purpose, example-session dialogue, session-specific remarks), reliance on a script that is absent from the bundle, and no feedback loop for merge failures before they occur.

Suggestions

Ship `pr-monitor.sh` in the bundle (e.g., `scripts/pr-monitor.sh`) and reference it bundle-relatively; the skill's core behavior currently depends on a file that does not exist in this bundle.

Delete the 'Purpose' section (it duplicates the frontmatter description), the 'Example Session' dialogue block, and the '(like in today's session)' remark — together they are the bulk of the unnecessary tokens.

Add a pre-merge checklist (verify branch protection / required reviews before attempting the merge, and what to do on merge failure other than reporting) to close the validation gap around the destructive batch merge.

DimensionReasoningScore

Conciseness

Mostly efficient — the workflow, tool usage, and error-handling sections are lean — but there is more than minor padding: the 'Purpose' section repeats the frontmatter description verbatim, the 'Example Session' section (~15 lines of sample dialogue) adds little actionable value, and 'Integration with Dependabot' contains a session-specific artifact ('like in today's session'). This fits 'Mostly efficient but includes some unnecessary explanation or could be tightened' rather than the 4 anchor's 'minor instances'.

3 / 5

Actionability

Quotes: 'gh pr list --json number,title,createdAt,author --jq ...', 'gh pr merge <number> --squash --auto', 'gh auth status', and three concrete script invocations (`.opencode/skills/pr-monitor/pr-monitor.sh today`, `... 2001 2005 2006`, `... --check-once 2001`). The inline commands are copy-paste ready, matching 'Mostly executable guidance; concrete code or commands with minor gaps' — the gap being that the core logic is delegated to `pr-monitor.sh`, which is not included in this bundle, so it cannot score 5 as fully self-contained executable guidance.

4 / 5

Workflow Clarity

Steps are clearly sequenced (identify PRs → check status → handle each state → monitor loop) with an explicit safety gate before the destructive batch merge ('FAILING builds: ... Do NOT merge', 'jakarta-namespace incompatibility: Do NOT merge'), so the batch-operation validation cap is not triggered. It stops short of the 5 anchor because there is no explicit validate→fix→retry loop (e.g., re-checking branch protection/required reviews before attempting merge is only covered reactively under 'Merge fails'), matching 'Clear sequence with most checkpoints present; minor validation gaps'.

4 / 5

Progressive Disclosure

The body is well-sectioned and references only one external file, one level deep, but that reference is broken: no `scripts/`, `references/`, or `assets/` directories exist in this bundle, so the referenced `pr-monitor.sh` is missing, and it is addressed by an environment path (`.opencode/skills/pr-monitor/pr-monitor.sh`) rather than a bundle-relative reference. Per the judging guideline to score against the actual bundle structure, this fits 'references present but not clearly signaled / could be better organized' rather than the 4 anchor's 'references mostly clear'.

3 / 5

Total

14

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete, comprehensive on both what and when, with natural trigger phrases. Only weakness is that a couple of trigger terms ('watch builds', 'monitor PRs') are generic enough to slightly overlap with general PR/CI monitoring skills.

DimensionReasoningScore

Specificity

Quotes: 'Monitors Dependabot and Snyk dependency upgrade PRs, automatically merging them when builds pass. Handles javax/jakarta compatibility validation and provides detailed status reporting.' Four concrete actions (monitor, merge, validate compatibility, report) comprehensively cover the skill's domain, matching the anchor 'Lists multiple specific concrete actions; comprehensive coverage'; only 'provides detailed status reporting' is mildly generic, which is not enough to drop below the 5 anchor.

5 / 5

Completeness

The 'what' is explicit (monitor Dependabot/Snyk upgrade PRs, auto-merge passing builds, validate javax/jakarta, report status) and the 'when' is explicit with concrete trigger phrases ('Use when the user says...'), exactly matching the anchor 'Clearly and explicitly answers both what AND when with concrete trigger phrases'.

5 / 5

Trigger Term Quality

Quotes: 'Use when the user says "monitor PRs", "watch builds", "auto-merge PRs", "merge passing PRs", or "watch dependency PRs".' Five natural phrasings a user would plausibly say, with synonyms for both monitoring and merging, matching the comprehensive-synonyms anchor; not the 4 anchor since no common variation is obviously missing.

5 / 5

Distinctiveness Conflict Risk

Quotes: 'Dependabot and Snyk dependency upgrade PRs' and 'javax/jakarta compatibility validation' carve a clear niche with minimal conflict risk, but triggers like 'watch builds' and 'monitor PRs' are somewhat generic and could overlap a general CI/PR-watching skill — matching 'Mostly distinct; minor overlap risk with closely related skills' rather than the 5 anchor's 'minimal conflict risk'.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
mock-server/mockserver-monorepo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.