CtrlK
BlogDocsLog inGet started
Tessl Logo

review-pr

Use when reviewing a pull request - security-focused review following repo agent guidance for breaking changes, malicious patterns, and backward compatibility

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable and presents a well-sequenced workflow with validation checkpoints, but it is verbose in places and monolithic — content that could live in separate reference files is inlined, and an external MIGRATION.md reference is not bundled.

Suggestions

Tighten the Threat Awareness section and other conceptual prose to remove explanations of concepts Claude already knows, improving token efficiency.

Move the contributor-credit rules, integrate-and-fix flow, and review output templates into a referenced file (e.g. references/MERGING.md) so SKILL.md stays a lean overview.

Either bundle MIGRATION.md or inline the operator-contract details instead of pointing to a file that is not part of the skill bundle.

DimensionReasoningScore

Conciseness

The body is long (~460 lines) and sections like Threat Awareness restate concepts Claude already knows ('Coordinated attacks exist', 'Social engineering builds trust before attacking'); mostly efficient but could be tightened.

2 / 3

Actionability

Provides fully executable commands — gh, terraform, codex, gemini invocations — plus copy-paste-ready review and merge templates, matching the 'fully executable code/commands' anchor.

3 / 3

Workflow Clarity

A 9-step sequenced workflow with a DOT graph, mandatory verification (Step 8), CI truth-checking (Step 8.5), checklists, and explicit feedback loops for error recovery.

3 / 3

Progressive Disclosure

No bundle files exist, yet all content is inline in one large file with detail (templates, credit rules, integration flow) that could be split; it also references MIGRATION.md which is not in the bundle.

2 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, uses a natural 'Use when' trigger, and lists concrete review dimensions, clearly answering both what the skill does and when to use it. It is distinct from other skills and avoids vague fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete review dimensions — 'breaking changes, malicious patterns, and backward compatibility' — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Explicitly answers both what ('security-focused review following repo agent guidance for breaking changes, malicious patterns, and backward compatibility') and when ('Use when reviewing a pull request') with an explicit trigger clause.

3 / 3

Trigger Term Quality

'Use when reviewing a pull request' uses the natural term a user would say when needing this skill, matching the good coverage anchor.

3 / 3

Distinctiveness Conflict Risk

Targets a clear niche — security-focused PR review — with distinct triggers unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mysticaltech/terraform-hcloud-kube-hetzner
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.