CtrlK
BlogDocsLog inGet started
Tessl Logo

dotnet-inspect-private-feeds

Inspect packages from private and custom NuGet feeds safely — select and map sources, use credential providers or explicit configuration, diagnose authentication failures, and reason about source-bound caches and offline operation.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/private-feeds/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable and well-organized: nearly every section is anchored by executable commands, failure modes are given precise semantics, and the diagnostic section gives concrete troubleshooting direction. Its main weaknesses are verbose, jargon-heavy prose in the workspace/credential-retention and cache sections and the absence of any progressive-disclosure split for the deepest reference material.

Suggestions

Tighten the Inspect Web credential-retention paragraph — replace terms like "activation-local copies", "settlement", and "incumbent-recovery binding" with plain statements of what persists where and when.

Trim overlapping version-query examples (six near-identical `--source ./feed` invocations) to the two or three that illustrate distinct flags.

Consider splitting the folder-feed versioning/peer-failure minutiae and cache-provenance rules into a reference file linked from a short overview section, to shorten SKILL.md's always-loaded footprint.

DimensionReasoningScore

Conciseness

The body mostly assumes competence (no explanation of what NuGet or credential providers are) and commands are dense with information, but several passages are padded and convoluted — e.g. "activation-local copies are cleared after settlement, while the active realization or incumbent-recovery binding may retain them until replacement or disposal", and six near-identical version-query commands. These could be tightened without losing content.

3 / 5

Actionability

Nearly every section provides copy-paste-ready executable commands (dnx invocations, NuGet.Config XML, packageSourceMapping XML, Azure Pipelines YAML, provider install and env-var setup), and the examples cover the common cases: source selection, workspace sharing, folder feeds, API/history probes, credential providers, explicit credentials, and cache diagnostics.

5 / 5

Workflow Clarity

There is a clear progression — select the feed, credential-free config plus provider or explicit credentials, then "Diagnose failures and caches" with concrete failure semantics ("401 Unauthorized means the source was unreadable, not that the package is absent") and what to check (provider discovery, URI matching, token scope, expiration). It falls short of anchor 5 because there is no explicit validate→fix→retry loop; it is reference-style rather than a checkpointed sequence.

4 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are all absent), so the skill is a single self-contained file; it is well-sectioned with clear, scannable headers and no nested references. It misses anchor 5 only because deep minutiae (Inspect Web credential-lifecycle semantics, folder-feed peer-failure and cache-provenance rules) are inlined in SKILL.md where a progressive-disclosure design would split them into reference files.

4 / 5

Total

16

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, distinctive, and rich in domain-appropriate trigger terms, but it omits any explicit "use when" guidance, which caps its completeness and limits how reliably a user or Claude would know when to invoke it. Adding a trigger clause (e.g., "Use when a package resolves from a private feed, Azure Artifacts, or an authenticated NuGet source") would raise it substantially.

Suggestions

Add an explicit trigger clause, e.g. "Use when packages come from Azure Artifacts, MyGet, GitHub Packages, or other private/authenticated NuGet feeds rather than NuGet.org."

Include a few more natural synonyms users say — "Azure Artifacts", "authenticated feed", "personal access token (PAT)", "nuget.config" — to broaden trigger-term coverage.

Drop the adverb "safely" and make the final clause more concrete (e.g., "inspect packages offline from authorized caches") to tighten specificity.

DimensionReasoningScore

Specificity

The description names the domain ("private and custom NuGet feeds") and lists several concrete actions: "select and map sources", "use credential providers or explicit configuration", "diagnose authentication failures". It stops short of anchor 5 because "reason about source-bound caches and offline operation" is more abstract than the fully concrete action lists in the top anchor, and "safely" is minor padding.

4 / 5

Completeness

The "what" is clear and multi-part (inspect packages, select/map sources, credential providers, diagnose auth failures, caches/offline), but the description contains no "Use when..." clause or equivalent explicit trigger guidance, which caps completeness at 3 per the judging guidelines.

3 / 5

Trigger Term Quality

Strong natural keywords: "private NuGet feeds", "custom NuGet feeds", "credential providers", "authentication failures", "offline" — phrases a user with this problem would plausibly say. Not anchor 5 because common synonyms and specific trigger phrases like "Azure Artifacts", "authenticated feed", "personal access token", or "nuget.config" are absent.

4 / 5

Distinctiveness Conflict Risk

"Private and custom NuGet feeds" is a clear niche with distinct triggers (credential providers, source-bound caches) that would not naturally fire for other skills; overlap risk is minimal.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
richlander/dotnet-inspect
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.