CtrlK
BlogDocsLog inGet started
Tessl Logo

golang-dependency-management

Dependency management for Golang projects — go.mod and go.sum, `go get` install and upgrade flows, Minimal Version Selection, conflict resolution with replace/exclude/retract, `govulncheck` scanning of the module tree, outdated dependency and binary size auditing, vendoring, `tool` directives, and go.work workspaces. Use when adding, removing, or upgrading Go dependencies, deciding whether to take on a package, resolving version conflicts, or auditing what a module pulls in. Covers choosing and upgrading dependency versions, not the surrounding tooling: do NOT use for fixing an exploitable vulnerability in code (→ See `samber/cc-skills-golang@golang-security` skill) or for wiring Dependabot/Renovate update bots into CI workflows (→ See `samber/cc-skills-golang@golang-continuous-integration` skill).

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body with executable commands, clear references, and verification steps. It could tighten a few explanatory passages and add an explicit fix-and-retry loop for batch dependency changes.

Suggestions

Add an explicit feedback loop for batch/destructive operations (e.g., 'if govulncheck reports vulns, fix or pin before release; re-run until clean') to push workflow_clarity to 5.

Trim rationale padding such as the 'AI Agent Rule' intro restating the ask-before-add requirement and 'every dependency increases attack surface, maintenance burden, and binary size' to improve conciseness.

Consolidate the cross-reference list (Deep Dives vs Cross-References sections) so each sibling skill is pointed to once, reducing repetition.

DimensionReasoningScore

Conciseness

Mostly lean — command tables, copy-paste code blocks, and terse rules — with a few rationale sentences ('go.sum MUST be committed — it records cryptographic checksums...') and the repeated 'AI Agent Rule' framing that could be trimmed slightly.

4 / 5

Actionability

Provides fully executable, copy-paste-ready commands and go.mod examples covering the common cases (`go get -u=patch ./...`, `go get -tool ...`, `go mod tidy`, `govulncheck ./...`).

5 / 5

Workflow Clarity

The upgrade workflow is clearly sequenced with validation checkpoints (`go get -u=patch`, `go mod tidy`, `go test`, `go vet`, `govulncheck`) and an ask-before-adding rule, but lacks an explicit error-feedback loop for batch/destructive operations.

4 / 5

Progressive Disclosure

SKILL.md is a well-organized overview with one-level-deep references to six real, verified files in ./references/, each clearly signaled in the Deep Dives section; no nested reference chains.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly delineates its scope and triggers, with explicit boundary guidance to avoid mis-routing. Minor room for more synonym/extension breadth in trigger terms.

DimensionReasoningScore

Specificity

Lists many concrete capabilities — `go get` install/upgrade flows, Minimal Version Selection, replace/exclude/retract conflict resolution, `govulncheck` scanning, vendoring, `tool` directives, go.work workspaces — giving comprehensive coverage rather than just a few actions.

5 / 5

Completeness

Explicitly states both what it does (the enumerated dependency-management capabilities) and when to use it ('Use when adding, removing, or upgrading Go dependencies...'), with concrete trigger phrases and explicit boundary guidance.

5 / 5

Trigger Term Quality

Includes natural trigger phrases users would say ('adding, removing, or upgrading Go dependencies', 'resolving version conflicts', 'deciding whether to take on a package') plus file references (go.mod, go.sum, go.work), though a few synonyms are absent.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear Go-dependency niche and reduces conflict risk with explicit 'do NOT use' redirects to sibling skills (golang-security, golang-continuous-integration).

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_field

'metadata' should map string keys to string values

Warning

Total

15

/

16

Passed

Repository
samber/cc-skills-golang
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.