CtrlK
BlogDocsLog inGet started
Tessl Logo

github

GitHub API integration via HTTP tool with automatic credential injection

56

Quality

64%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/internal/archived-skills/github/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tightly written, highly actionable API reference with copy-paste-ready calls and clear response-handling guidance. Its main gap is workflow structure: destructive/mutating operations lack an explicit validation-and-feedback-loop sequence.

Suggestions

Add a short numbered workflow for mutating operations (e.g. create PR) that includes an explicit verify step and a fix-and-retry loop on non-2xx responses.

De-duplicate the Authorization-header warning so it lives in only one place, or explicitly mark the repetition as deliberate reinforcement.

Consider splitting the full endpoint catalog into a REFERENCE.md and leaving SKILL.md as an overview, which would let progressive disclosure reach the top anchor.

DimensionReasoningScore

Conciseness

The body is lean and action-oriented and assumes Claude already knows GitHub/API concepts (no 'what is a PR' padding); minor redundancy (the 'do NOT add an Authorization header' warning appears in both the intro and Common Mistakes) keeps it just below 5.

4 / 5

Actionability

Copy-paste-ready http(...) calls cover issues, PRs, repos, search, and authenticated-user queries, and the Response Handling section gives concrete parsing code (e.g. pr = r["body"]; title = pr["title"]) — specific examples cover the common cases.

5 / 5

Workflow Clarity

A request → status-check → parse → surface pattern with fail-fast validation is present in Response Handling, but there is no explicit sequenced workflow or validate→fix→retry feedback loop for destructive operations (create PR/issue), so the destructive-ops cap holds at 3.

3 / 5

Progressive Disclosure

Sections are well-organized (API Patterns, Response Handling, Common Mistakes) and the file is self-contained with no nested references; it stops short of 5 because, with no bundle files and no one-level-deep file references, the endpoint catalog is entirely inline rather than split out.

4 / 5

Total

16

/

20

Passed

Description

53%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description conveys a clear, GitHub-specific niche and mechanism, but it omits any usage-trigger guidance and leans on technical jargon rather than the natural phrases users actually say. It is competent but incomplete as a trigger description.

Suggestions

Add an explicit 'Use when...' clause naming natural triggers, e.g. 'Use when the user asks to list, create, or comment on pull requests, issues, or repos on GitHub.'

Surface concrete actions (create PRs, list issues, comment, fetch diffs) instead of only the integration mechanism.

Swap some implementation jargon ('HTTP tool', 'credential injection') for user-natural terms ('pull requests', 'issues', 'PRs').

DimensionReasoningScore

Specificity

Names the domain ("GitHub API integration") plus 1-2 concrete elements ("via HTTP tool", "automatic credential injection"), but lists no specific user-facing tasks like creating PRs or listing issues, so it is not comprehensive.

3 / 5

Completeness

The "what" is clear ("GitHub API integration via HTTP tool with automatic credential injection"), but there is no "when"/"Use when..." trigger guidance, which caps completeness at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

"GitHub" is a relevant natural keyword a user would say, but the rest is technical jargon ("HTTP tool", "credential injection") and common natural phrases ("pull request", "issue", "PR", "repo") are missing.

3 / 5

Distinctiveness Conflict Risk

"GitHub API integration" names a clear niche with only minor overlap risk against a generic git skill; it stops short of 5 because the description carries no explicit distinct trigger phrases.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
nearai/ironclaw
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.