CtrlK
BlogDocsLog inGet started
Tessl Logo

dependabot-tooling-downgrade

Use a validated tooling downgrade when Dependabot flags an unpatchable transitive vulnerability in build-only dependencies.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.squad/skills/dependabot-tooling-downgrade/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is lean, actionable, and well-sequenced with explicit validation checkpoints appropriate to a dependency/security change; only minor conciseness and command-detail gaps prevent a perfect score.

DimensionReasoningScore

Conciseness

Lean content with no over-explanation of concepts Claude already knows; the only trim opportunity is the somewhat verbose 2026-04-26 revalidation example, which keeps it just below the 'every token earns its place' anchor.

4 / 5

Actionability

Provides concrete named packages, version ranges, and executable commands (npm audit, npm run package) with a real worked example; minor gaps (no exact npm install/lockfile refresh command line) keep it at 4 rather than 5.

4 / 5

Workflow Clarity

A clear 5-step sequence with explicit validation checkpoints ('Validate the exact release command after the change', 'verify the packaging path') and a feedback-oriented revalidation example; fully matches the explicit-validation anchor.

5 / 5

Progressive Disclosure

Under 50 lines, single-purpose, with well-organized sections and no bundle files needed; the simple-skill exception applies, so well-organized sections alone justify a 5.

5 / 5

Total

18

/

20

Passed

Description

65%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and well-targeted to a distinct niche, but omits an explicit 'Use when...' trigger clause and lists only one concrete action, capping completeness and specificity.

Suggestions

Add an explicit trigger clause, e.g. 'Use when Dependabot or npm audit flags a transitive vulnerability in a build-only dependency and no patched version exists on the current major line.'

Name a couple more concrete actions in the description (e.g. 'downgrade the tool, refresh the lockfile, and verify the package command') to lift specificity toward 4-5.

Include common synonyms like 'dev dependency', 'supply chain alert', or 'npm audit' to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Names the domain (Dependabot/transitive vulnerability in build-only deps) and one concrete action (validated tooling downgrade), but does not enumerate several specific actions; fits the 'domain + 1-2 concrete actions' anchor rather than the multi-action anchor above.

3 / 5

Completeness

Has a clear 'what' (validated tooling downgrade for unpatchable transitive vulns) but lacks an explicit 'Use when...' trigger clause in the description, which per the rubric caps completeness at 3.

3 / 5

Trigger Term Quality

Includes natural terms a user would say ('Dependabot', 'transitive vulnerability', 'build-only dependencies') but is missing common synonyms such as 'supply chain', 'dev dependency', or 'npm audit' that a user might also say.

4 / 5

Distinctiveness Conflict Risk

Targets a very specific niche (unpatchable transitive vuln in build-only deps under Dependabot) with distinct triggers and minimal realistic overlap with other skills.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sbroenne/mcp-server-excel
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.