CtrlK
BlogDocsLog inGet started
Tessl Logo

dotnet-inspect-signals

Surface a dependency's observable signals — provenance, compatibility, dependency risk, unsafe/PInvoke surface, artifact-text containment, and identifier confusion — to judge how much caution it warrants. Observations, not verdicts.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/signals/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, command-first reference: every section leads with concrete, executable dnx commands against realistic targets, and there is no conceptual padding. Sequencing across the sections is implied (Signals rollup first, then focused audits, then SourceLink provenance) rather than explicit, and some dense flag-semantics prose could be trimmed or split into reference files. No bundle files exist, so all guidance is appropriately self-contained.

DimensionReasoningScore

Conciseness

The body is dense and free of padding — no explanations of concepts Claude already knows, and every section centers on concrete commands. It falls short of anchor 5 because a few passages (e.g. the Signals-vs-audit distinction paragraph and the closing category-discovery notes) are intricate enough to need re-reading and could be tightened.

4 / 5

Actionability

Every section supplies copy-paste-ready executable commands ('dnx dotnet-inspect -y -- package Microsoft.Extensions.AI -S Signals', 'dnx dotnet-inspect -y -- library System.Text.Json -D @SourceLink --effective') with real targets and concrete flag combinations that cover the common inspection cases. This matches the fully-executable, specific-examples anchor.

5 / 5

Workflow Clarity

A clear progression exists — Signals as 'the one-stop view', then focused audits (@Audit sections), then SourceLink drill-downs — and the read-only nature of inspection means no validation checkpoints are required. It is not a 5 because the recommended order of operations is implied by section layout ('the one-stop view') rather than stated explicitly as a sequence.

4 / 5

Progressive Disclosure

The body (~80 lines) is organized into clear, well-scoped sections with executable examples inline and cross-references to sibling skills (correctness, sourcelink, compatibility) clearly signaled rather than buried. It is not a 5 because the body exceeds the under-50-line simple-skill threshold and some per-section flag semantics (e.g. the Signals summary rules and category/discovery-mode notes) are inlined material that could live in reference files.

4 / 5

Total

17

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and honest about scope, listing six concrete signal categories and explicitly framing output as observations rather than verdicts. Its main weakness is trigger coverage: it lacks a 'Use when...' clause and the natural vocabulary (package, NuGet, library) users would employ, leaning technical instead. Adding explicit trigger guidance with those synonyms would raise completeness and trigger-term quality.

Suggestions

Add an explicit trigger clause, e.g. 'Use when evaluating a NuGet package or library as a dependency, or when the user asks whether a package is safe, trustworthy, or risky to take.'

Include natural synonyms users actually say — 'package', 'NuGet', 'library', 'supply-chain risk' — alongside the technical signal names like 'artifact-text containment'.

State the concrete output format (e.g. 'reports SourceLink status, unsafe member counts, and dependency risk ratings') so the 'what' includes observable actions, not just signal names.

DimensionReasoningScore

Specificity

The description enumerates six concrete signal areas ('provenance, compatibility, dependency risk, unsafe/PInvoke surface, artifact-text containment, and identifier confusion'), giving it several specific capabilities with only minor gaps. It stops short of anchor 5 because 'Surface' is the sole action verb and the individual actions within each signal area are not enumerated.

4 / 5

Completeness

The 'what' is clear — surface a dependency's observable signals so you can judge how much caution it warrants — but there is no 'Use when...' clause or equivalent explicit trigger guidance, capping completeness at 3 per the rubric guidelines. The 'when' is only weakly implied (when evaluating a dependency).

3 / 5

Trigger Term Quality

It contains relevant domain keywords (dependency, provenance, unsafe/PInvoke) but misses the natural phrases a user would actually say — 'package', 'NuGet', 'library', 'supply-chain risk', 'is this safe to depend on'. This matches 'some relevant keywords but missing common variations or synonyms'; it is not a 4 because natural-term coverage is thin and the phrasing leans technical (e.g. 'artifact-text containment').

3 / 5

Distinctiveness Conflict Risk

The niche is clear — surfacing observable dependency signals with an explicit 'observations, not verdicts' framing — making it mostly distinct with minor overlap risk against generic dependency-audit or security-review skills. It is not a 5 because terms like 'provenance' and 'dependency risk' could plausibly collide with a broader supply-chain-scanning skill.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
richlander/dotnet-inspect
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.