CtrlK
BlogDocsLog inGet started
Tessl Logo

env-vars

Vercel environment variable expert guidance. Use when working with .env files, vercel env commands, OIDC tokens, or managing environment-specific configuration.

63

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/vercel/skills/env-vars/SKILL.md

The canonical home for this skill is env-vars in vercel/vercel-plugin

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong operational reference: nearly all guidance is copy-paste executable, workflows are sequenced with verification steps, and gotchas are surfaced prominently. Weaknesses are moderate redundancy in Best Practices, a missing validation checkpoint around destructive rm operations, and a monolithic single-file structure that inlines CLI reference and OIDC details that could live in separate reference files.

Suggestions

Move the full 'vercel env CLI' command reference and the OIDC lifecycle/troubleshooting sections into references/ files (e.g. references/cli.md, references/oidc.md), keeping SKILL.md as a concise overview with clearly signaled one-level-deep links.

Add a validation checkpoint before destructive removal, e.g. 'vercel env ls <env>' to confirm the variable and its environments before running 'vercel env rm', mirroring the verification loop already present in the bootstrap flow.

Deduplicate Best Practices against Critical Rules (e.g. the repeated NEXT_PUBLIC_ secret warning) and drop the 'You are an expert...' preamble to tighten token efficiency.

DimensionReasoningScore

Conciseness

Largely operational (command blocks, tables, gotchas) with little concept explanation, but contains trimmable padding: the 'You are an expert...' preamble, the OIDC definition sentence, and Best Practices items that repeat Critical Rules ('never put secrets in NEXT_PUBLIC_' appears twice). Not 5 because these unnecessary tokens are present; not 3 since they are minor.

4 / 5

Actionability

Fully executable copy-paste commands throughout: pull/add/ls/rm with flag variations, a concrete bootstrap sequence ('vercel link --yes --project <name> --scope <team>'), a working verification loop against .env.example, and dotenv-cli invocations for standalone scripts.

5 / 5

Workflow Clarity

The bootstrap flow is clearly sequenced (link → pull → verify) with an explicit checkpoint, and the OIDC troubleshooting table provides symptom→cause→fix feedback. Held below 5 by a minor validation gap: destructive 'vercel env rm MY_SECRET' (all environments) is shown with no confirmation checkpoint, and the pull-overwrite backup snippet is never verified.

4 / 5

Progressive Disclosure

Well-sectioned single file, but ~230 lines are entirely inline — the full CLI command reference, OIDC lifecycle, and troubleshooting tables are material that belongs in one-level-deep reference files, and no external navigation exists. Better than 2 because sections are clear and nothing is buried, but the monolithic structure leaves room to split.

3 / 5

Total

16

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-scoped, distinctive description with an explicit 'Use when...' trigger clause covering concrete artifacts like .env files, vercel env commands, and OIDC tokens. Its main weakness is the vague what-clause ('expert guidance'), which names the domain without stating any specific capability.

Suggestions

Replace the vague 'expert guidance' what-clause with 2-3 concrete capabilities, e.g. 'Pull, add, and remove Vercel environment variables via the vercel env CLI, manage .env file hierarchies, and handle OIDC token lifecycle.'

Add natural synonyms users would actually say, such as 'secrets', 'env vars', or 'pulling environment variables', to broaden trigger coverage.

DimensionReasoningScore

Specificity

Names the domain ('Vercel environment variable') and concrete objects ('.env files', 'vercel env commands', 'OIDC tokens'), but the verbs are generic ('working with', 'managing') and no specific capabilities are listed, matching the 3 anchor rather than 4's 'several specific actions'.

3 / 5

Completeness

Both parts present: a 'what' ('Vercel environment variable expert guidance') and an explicit 'Use when working with...' trigger clause. Not a 5 because the what-clause states no concrete capability — 'expert guidance' is vague about what the skill actually does.

4 / 5

Trigger Term Quality

Good natural keyword coverage including the '.env' file extension and 'OIDC tokens', but misses common user phrasings like 'secrets', 'env vars', or 'pull environment variables', falling short of the 5 anchor's comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

Clear Vercel-specific niche with distinct triggers ('vercel env commands', 'OIDC tokens', '.env' conventions); minimal conflict risk with non-Vercel skills.

5 / 5

Total

16

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

referenced_paths_exist

Referenced path issues: 2 missing

Warning

Total

13

/

16

Passed

Repository
openai/plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.