CtrlK
BlogDocsLog inGet started
Tessl Logo

qodo-setup

Set up Qodo in a coding agent — install the CLI, sign in, and verify tools. Use after plugin installation, on setup requests, or when a Qodo skill finds a missing CLI or login.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An efficient, highly actionable setup guide with a well-gated multi-step workflow and conditionally-loaded references. The main weaknesses are mild redundancy in repeated authorization caveats and minor structural gaps — a depth-two reference chain and unnumbered sections interleaved between numbered steps.

Suggestions

Consolidate the repeated authorization-scoping caveats (plugin-installation-is-not-authorization, approval scope limits, enterprise-install disclosure) into a single short 'Authorization scope' note so each caveat appears once.

Link skill-updates.md directly from the Configuration section (or flatten it), since it is currently only reachable via host-recovery.md's nested link.

Move the Configuration and Error Handling sections after '## 4. Hand off' (or renumber them) so the numbered step sequence 1-4 reads contiguously.

DimensionReasoningScore

Conciseness

The body is dense and lean — commands, version gates, and edge-case routing with no explanations of concepts Claude already knows. It sits at 4 rather than 5 because the authorization-scoping caveat is repeated in several forms ("Plugin installation alone is not authorization", "a diagnostic approval does not grant blanket permission", "Runtime/login setup does not authorize enterprise installation"), which could be consolidated.

4 / 5

Actionability

Fully executable, copy-paste-ready commands are given for every step (`qodo --version`, the `${QODO_HOME:-$HOME/.qodo}/bin/qodo` fallback, the full `whoami` and `tools --refresh` invocations with real flags), with the `<qodo>` placeholder explicitly defined. It is above the 4 anchor because the commands cover the common cases completely, including an exact retry command for catalog failure.

5 / 5

Workflow Clarity

A clearly sequenced 4-step workflow (find/install runtime → connect → verify tools → hand off) with explicit validation checkpoints: a minimum version gate before authenticated commands, identity verification that gates step 3 ("Only after identity succeeds"), and per-step error-recovery feedback loops. This is a non-destructive setup skill, so the validation cap for destructive/batch operations does not apply.

5 / 5

Progressive Disclosure

References are conditionally loaded and well signaled (runtime.md for missing CLI/PowerShell, authentication.md for failed identity, host-recovery.md "only when encountered"), and the main body stays a concise overview. It falls short of the 5 anchor due to minor organization gaps: host-recovery.md nests a second-level link to skill-updates.md (which SKILL.md never references directly, hurting discoverability), and the unnumbered Configuration/Error Handling sections interrupt the numbered step sequence between steps 3 and 4.

4 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete actions, explicit 'Use when...' triggers with three specific conditions, and a clearly branded niche. The only gap is modest keyword variation coverage (e.g., missing standalone terms like 'Qodo CLI' or 'authenticate' as natural user phrasings).

DimensionReasoningScore

Specificity

The description lists three concrete actions covering the full setup flow — "install the CLI, sign in, and verify tools" — which is comprehensive for a setup skill. It is not below this anchor (that would mean only 1-2 actions or minor coverage gaps), and there is nothing vague or generic in the phrasing.

5 / 5

Completeness

Both halves are explicit: what ("install the CLI, sign in, and verify tools") and when ("Use after plugin installation, on setup requests, or when a Qodo skill finds a missing CLI or login") with concrete trigger phrases. The 4 anchor would require the 'when' clause to be less explicit or specific, which is not the case here.

5 / 5

Trigger Term Quality

Natural trigger terms include "Qodo", "plugin installation", "setup requests", and "missing CLI or login" — phrases a user would plausibly say. It falls short of the 5 anchor because common variations like "Qodo CLI", "authenticate", or "log in" as standalone triggers are absent, but it is clearly above the 3 anchor ("Works with PDF files"-level keyword coverage).

4 / 5

Distinctiveness Conflict Risk

The Qodo brand name plus tightly scoped triggers ("after plugin installation", "when a Qodo skill finds a missing CLI or login") give it a clear niche with minimal overlap risk against generic setup or installation skills. It is not at the 4 anchor since there is no meaningful overlap with closely related skills implied by the text.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
qodo-ai/qodo-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.