CtrlK
BlogDocsLog inGet started
Tessl Logo

fix-dependabot

Fix a Dependabot PR by updating all monorepo instances of the dependency, running bun install, and pushing

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/fix-dependabot/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A tight, highly actionable skill: concrete commands at every step, an explicit verification checkpoint before pushing, and failure-handling notes, all within a lean single file that needs no external references. The only soft spot is that placeholders aren't backed by explicit extraction details (e.g., pulling old/new versions from the PR body).

DimensionReasoningScore

Conciseness

The body is lean: every step is a command or a one-line instruction, and the opening paragraph states only the necessary why (Dependabot touches one package.json and never runs bun install) rather than generic padding. Matches anchor 5 — every token earns its place.

5 / 5

Actionability

Concrete executable commands throughout — `gh pr view <number> --json ...`, the `rg` search with a glob, git checkout/add/commit/push, and a commit-message template. Minor gaps keep it at anchor 4 rather than 5: placeholders (<dependency>, <old-version>) must be filled per-PR and extracting old/new versions from the PR body isn't spelled out.

4 / 5

Workflow Clarity

A clear 7-step sequence with an explicit Verify checkpoint ("Run `git status` to confirm only `bun.lock` and the expected `package.json` files were modified... investigate before proceeding") and error recovery in Notes (bun install failure → close PR and comment; major-version caution). This batch operation does have validation, so the cap-3 rule doesn't apply, but it falls short of anchor 5 because there's no explicit re-validation loop after investigating unexpected changes.

4 / 5

Progressive Disclosure

No bundle files exist (no references/, scripts/, or assets/), and the skill is under 50 lines with well-organized ## Steps and ## Notes sections. Per the rubric's simple-skill guideline, this earns a 5 with just well-organized sections and no external references needed.

5 / 5

Total

18

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, distinctive description that names concrete actions and natural trigger terms, but it completely lacks a "when to use this" clause, which caps its completeness. Adding a trigger clause and common synonyms (lockfile, dependency bump) would raise the two weakest dimensions.

Suggestions

Add a trigger clause, e.g. "Use when fixing a Dependabot PR in a bun monorepo, when the bun.lock is out of date, or when the user mentions dependabot, lockfile conflicts, or dependency bumps."

Include natural synonyms users would say — "lockfile", "bun.lock", "dependency update/bump" — so the description matches more phrasings of the request.

Mention lockfile regeneration explicitly ("regenerating bun.lock") to round out the action coverage for comprehensiveness.

DimensionReasoningScore

Specificity

Lists three concrete actions — "updating all monorepo instances of the dependency, running bun install, and pushing" — in a specific domain. Matches anchor 4 (several specific actions, minor gaps): it stops short of anchor 5's comprehensiveness by omitting lockfile regeneration and verification.

4 / 5

Completeness

The "what" is clear (fix Dependabot PRs by updating instances, installing, pushing), but there is no "when" — no "Use when..." clause or equivalent trigger guidance. Per the rubric guideline, a missing trigger clause caps completeness at 3, matching anchor 3.

3 / 5

Trigger Term Quality

Natural trigger terms are present ("Dependabot PR", "monorepo", "bun install") — exactly what a user would say. Falls short of anchor 5 because common synonyms like "lockfile", "bun.lock", "dependency bump", or "update dependency" are missing.

4 / 5

Distinctiveness Conflict Risk

"Dependabot PR", "monorepo", and "bun" carve out a clear niche with distinct triggers and minimal overlap risk with any other skill, matching anchor 5. The niche is narrower than anchor 4's 'minor overlap risk with closely related skills'.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
remotion-dev/remotion
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.