CtrlK
BlogDocsLog inGet started
Tessl Logo

review-wall-of-apps-prs

Audit maintainer-side Wall of Apps pull requests in App-Store-Connect-CLI. Use when the user asks to review new app submissions, check Wall PRs for injected or unrelated changes, validate app metadata, approve with a personalized welcome, or merge legitimate Wall entries.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered procedural skill: lean, dense with real constraints, concrete commands at the decisive moments (validation check, branch update, merge), and a validation checkpoint before and after every risky action. Weaknesses are minor: some judgment-based validation steps lack detection methods, and the approval-authority and re-fetch rules are stated slightly redundantly across paragraphs.

Suggestions

Tighten the 'Approve and merge' section: the approval-intent sources and the pre-merge re-fetch requirements each appear twice across paragraphs 32-46 and the Automation contract; consolidate them into one intent rule and one re-fetch rule to cut tokens without losing constraints.

Add one or two concrete detection hints for the judgment-call validation steps (e.g., a jq/grep snippet for finding duplicate app names or non-canonical URLs in docs/wall-of-apps.json) to lift actionability to fully executable coverage.

DimensionReasoningScore

Conciseness

The body is dense with operational policy and explains nothing Claude already knows — no concept tutorials, no filler. It is not a clean 5 because a few passages could be tightened: the approval-intent paragraphs ("That intent may come from the current request, preserved session context, or a persisted automation prompt...") and the re-fetch requirements are each stated in two places, and the very long merge/approval paragraph mixes several rules that could be trimmed. It is well above the level-3 anchor ('some unnecessary explanation') since nearly every sentence carries a real constraint.

4 / 5

Actionability

Concrete, executable guidance is present: `ASC_BYPASS_KEYCHAIN=1 make check-wall-of-apps`, `gh pr update-branch <number>`, `gh pr merge <number> --merge --match-head-commit <sha>`, an exact approval-body recipe, and named outcome labels (safe/needs-fix/suspicious/blocked). It stops short of the level-5 anchor ('specific examples cover the common cases') because several validation steps remain judgment calls with no detection method or example — e.g., 'Check for duplicate apps, misleading destinations, tracking or redirect abuse, and suspicious metadata' — leaving the operator to invent the how; still clearly above level 3's pseudocode/incompleteness.

4 / 5

Workflow Clarity

The sequence is explicit and validation-saturated: discover/classify → validate → approve/merge → automation contract → hand off, with checkpoints at every risky boundary (inspect diff before checkout, revalidate after branch updates, re-fetch head/reviews/checks/mergeability immediately before merge, confirm the commit reached origin/main after merge). This is exactly the level-5 anchor: clear sequence, explicit validation, feedback loops (changed head → fresh validation), and a pre-merge checklist; a batch operation with strong error-recovery guidance.

5 / 5

Progressive Disclosure

The skill is a single self-contained file with no references/, scripts/, or assets/ bundle, and nothing in the body needs to be split out — it uses clear section headers (Discover and classify, Validate the entry, Approve and merge, Automation contract, Hand off) that make navigation trivial. The one external pointer (`AGENTS.md`) is a repo authority document clearly signaled and only one level deep. This matches the guideline for self-contained skills scoring 5 with well-organized sections; it is not the level-4 case, which allows minor organization gaps.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, concrete action verbs, an explicit 'Use when' clause with multiple natural trigger phrases, and a tightly scoped niche that minimizes conflict with other skills. The only minor gap is that a few additional synonyms for the Wall-submission workflow could broaden trigger coverage.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — "Audit maintainer-side Wall of Apps pull requests", "review new app submissions", "check Wall PRs for injected or unrelated changes", "validate app metadata", "approve with a personalized welcome", "merge legitimate Wall entries" — giving comprehensive coverage of the skill's capabilities. It clearly matches the anchor 'Lists multiple specific concrete actions; comprehensive coverage' rather than the level-4 anchor, which allows minor gaps in coverage; no capability area is missing.

5 / 5

Completeness

The first sentence explicitly answers 'what' ("Audit maintainer-side Wall of Apps pull requests...") and the second explicitly answers 'when' ("Use when the user asks to review new app submissions, check Wall PRs... approve... or merge..."). This matches the level-5 anchor — both what and when with concrete trigger phrases — and not level 4, where the 'when' would be less specific.

5 / 5

Trigger Term Quality

Natural phrases a user would say are well covered: "review new app submissions", "check Wall PRs", "validate app metadata", "approve", "merge", plus the repository name "App-Store-Connect-CLI". It falls just short of the level-5 anchor ('comprehensive coverage of natural terms including synonyms and file extensions') because a few plausible variations (e.g., 'wall entry', 'new app on the wall') are absent, while clearly exceeding level 3 ('missing common variations or synonyms') since it names the Wall and PR vocabulary several ways.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear niche: maintainer-side auditing of Wall of Apps PRs in a named repository (App-Store-Connect-CLI), with triggers tied to that specific workflow. It would not naturally fire for generic PR review or unrelated app-store tasks, matching the level-5 anchor 'Clear niche with distinct triggers; minimal conflict risk'.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
rorkai/App-Store-Connect-CLI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.