CtrlK
BlogDocsLog inGet started
Tessl Logo

npm

npm registry ops: login, whoami, names, publish; 1Password tmux.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/npm/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

90%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exemplary lean, executable runbook: concrete helper scripts with described validation and retry behavior, explicit stop conditions, and a working offline test harness. Its only real gaps are the unordered Auth rule list and minor consistency issues in how bundle scripts are referenced.

DimensionReasoningScore

Conciseness

The body is lean imperative bullets with zero explanation of concepts Claude already knows; even dense items like npm 11 prompt-piping brittleness and symlink resolution behavior are non-obvious operational knowledge, so every token earns its place (anchor 5).

5 / 5

Actionability

Guidance is fully executable: copy-paste-ready invocations with full paths (publish-package.sh, reserve-packages.sh), a concrete ad-hoc pattern ("scripts/npm-service.sh -- <npm args...>"), and a complete offline regression-test harness — anchor 5.

5 / 5

Workflow Clarity

Sequence and validation are strong — "From the package root, inside the same auth tmux window", the helper "verifies identity, refuses an existing package version... verifies registry visibility", with feedback loops (OTP retry, continue after per-package failures) and explicit stop-and-ask checkpoints — but the Auth section is an unordered rule list rather than an explicit sequence, holding it below anchor 5.

4 / 5

Progressive Disclosure

Sections are well organized and every referenced script (npm-auth.sh, npm-auth-login.mjs, npm-service.sh, publish-package.sh, reserve-packages.sh) exists one level deep in scripts/, but path styles are inconsistent (absolute /Users/... vs. relative scripts/...) and the structure lacks explicit reference pointers for the remaining bundle files — anchor 4.

4 / 5

Total

18

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is terse and domain-distinct, but its heavy compression hurts trigger quality and completeness: it omits any "Use when" guidance and leans on jargon ("registry ops", "1Password tmux") and the ambiguous keyword "names". It names the niche well but under-serves skill triggering.

Suggestions

Add an explicit trigger clause, e.g. "Use when publishing a package to npm, checking package-name availability, or debugging npm registry auth (whoami/login)."

Replace the ambiguous "names" with natural user phrasing such as "package name availability and reservation".

Drop or rephrase "1Password tmux" in the description (move that operational detail to the body) to sharpen distinctiveness and avoid overlap with a 1Password skill.

DimensionReasoningScore

Specificity

"login, whoami, names, publish" lists several concrete registry actions (anchor 4), but coverage has minor gaps — org checks and auth debugging from the body are absent and "names" is cryptic — so it falls short of anchor 5's comprehensiveness while being more concrete than anchor 3.

4 / 5

Completeness

A clear "what" is present ("npm registry ops: login, whoami, names, publish") but there is no "Use when..." clause or equivalent trigger guidance, which caps completeness at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

Natural terms like "npm", "login", "whoami", and "publish" are present, but "registry ops", "names", and "1Password tmux" are operator jargon a user would not naturally say, and common variations like "package", "auth", or "npmjs" are missing — matching anchor 3 rather than anchor 4's good keyword coverage.

3 / 5

Distinctiveness Conflict Risk

The description carves out a clear npm registry niche with distinct triggers, but "1Password tmux" creates minor overlap risk with a dedicated 1Password skill — anchor 4 rather than anchor 5's minimal conflict risk.

4 / 5

Total

14

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
steipete/agent-scripts
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.