CtrlK
BlogDocsLog inGet started
Tessl Logo

agent-agentic-payments

Agent skill for agentic-payments - invoke with $agent-agentic-payments

69

2.22x
Quality

53%

Does it follow best practices?

Impact

100%

2.22x

Average score across 3 eval scenarios

SecuritybySnyk

High

Do not use without reviewing

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/agent-agentic-payments/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers strong, parameter-level API coverage and a sensible six-step workflow, but it is a monolithic single-file skill with no headers, no external references, and redundant standards sections. Most critically for a payments skill, the workflow lacks explicit validation checkpoints and error-recovery loops for money-moving operations.

Suggestions

Add explicit validation gates to the workflow, e.g. 'Verify mandate signature before authorizing', 'Only capture after consensus threshold is met — if verification fails, revoke and report', with fix-and-retry guidance.

Split the ~70-line tool API reference into a references/api.md file (with markdown headers in SKILL.md pointing to it) and trim the redundant 'Security standards'/'Quality standards' sections into one.

Convert the workflow and protocol sections to markdown headers (##) so the file is navigable, and drop unverifiable marketing metrics like '<1ms verification' and 'zero-delay cancellation'.

DimensionReasoningScore

Conciseness

The toolkit section is dense and useful, but there are padded, overlapping sections — 'Security standards', 'Quality standards', and 'Real-world use cases you enable' restate the same guarantees with marketing fluff ("<1ms verification", "zero-delay cancellation", "full compliance tracking"). Mostly efficient with some unnecessary explanation that could be tightened, matching anchor 3; not score 4 because the redundancy across three sections is more than minor.

3 / 5

Actionability

The toolkit gives concrete tool invocations with realistic parameters for all common cases (create/sign/verify mandates, authorize payment, request/verify consensus, revoke, list, get status), which is mostly executable guidance. Not score 5 because the examples are not copy-paste runnable (illustrative JavaScript-style calls with placeholder values like "ed25519_private_key" and no invocation context or return-shape guidance); not score 3 because they are concrete parameter-level examples, not pseudocode.

4 / 5

Workflow Clarity

The six-step workflow ('Mandate Creation' → 'Cryptographic Signing' → 'Payment Authorization' → 'Multi-Agent Consensus' → 'Status Tracking' → 'Revocation Management') gives a clear sequence, but validation checkpoints are only implicit ('Verify mandate validity before authorizing purchases') with no explicit verify-then-proceed gates or error-recovery loops. Because payment authorization moves money — a destructive, hard-to-reverse operation — the missing feedback loops cap this at 3 per the rubric's destructive-operation rule.

3 / 5

Progressive Disclosure

The body has recognizable sections (responsibilities, toolkit, workflow, protocols, use cases, standards) but no markdown headers, and the full API/tool reference (~70 lines) is inlined in SKILL.md where it belongs in a separate reference file. No bundle files exist (no references/, scripts/, or assets/ directories), so everything is monolithic — anchor 3 (some structure, content that should be separate is inline).

3 / 5

Total

13

/

20

Passed

Description

48%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a distinct niche but reads as a role tagline rather than a capability-plus-trigger description: no concrete actions, no natural trigger terms, and no 'Use when' guidance. The file also contains duplicated YAML frontmatter blocks (an outer scaffold block and an inner one), which makes the effective description ambiguous to any parser.

Suggestions

Add an explicit trigger clause, e.g. 'Use when authorizing AI agent purchases, creating or revoking spending mandates, or verifying multi-agent payment consensus'.

List 3-4 concrete actions instead of a role label: 'Create and revoke Active Mandates with spend caps, sign and verify payments with Ed25519, coordinate multi-agent consensus for high-value transactions'.

Fix the duplicated frontmatter blocks (two `---` sections with conflicting names) so a single unambiguous description is parsed, and add natural keywords like 'mandates', 'spending limits', 'agent checkout'.

DimensionReasoningScore

Specificity

The description names the domain ("payment authorization specialist for autonomous AI commerce") but the 'actions' are minimal and generic — "cryptographic verification and Byzantine consensus" are capability labels, not concrete actions like 'create spending mandates', 'sign transactions', or 'track payment status' that the body actually performs. It fits anchor 2 (names the domain, actions minimal/generic) better than anchor 3, which expects 1-2 concrete named actions.

2 / 5

Completeness

The 'what' is reasonably clear (multi-agent payment authorization with cryptographic verification), but the 'when' is entirely absent — there is no "Use when..." clause or equivalent trigger guidance, which caps completeness at 3 per the judging guidelines. Not score 4 because the when-clause is not merely weak, it is missing; not score 2 because the what is explicit rather than vague.

3 / 5

Trigger Term Quality

Some relevant keywords exist ("payment authorization", "cryptographic verification", "AI commerce"), but common natural variations users would say are missing: "mandates", "spending limits", "agent checkout", "transactions", "approve purchases". "Byzantine consensus" is technical jargon a user would rarely say, so this sits between anchor 3 (relevant keywords, missing variations) and anchor 4 — noticeably below the midpoint of good coverage.

3 / 5

Distinctiveness Conflict Risk

Agentic payment authorization is a clear niche with little overlap risk against typical skills, and terms like "Byzantine consensus" are distinctive. Not score 5 because the description lacks explicit trigger phrases that would firmly separate it from adjacent payments/checkout skills; not score 3 because the domain itself is genuinely specific rather than broad.

4 / 5

Total

12

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
ruvnet/ruflo
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.