CtrlK
BlogDocsLog inGet started
Tessl Logo

xurl

xurl X API CLI: install, auth, app choice, shortcuts, raw endpoints.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/xurl/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

83%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a lean, highly actionable CLI reference: every section is copy-paste-ready commands with no padding, and setup/auth flows are clearly ordered. Its weaknesses are the absence of validation or confirmation guidance around destructive operations (delete, post), which caps workflow clarity, and no progressive-disclosure split of the full command catalog into a reference file.

Suggestions

Add validation steps for destructive operations, e.g. 'Before xurl delete, run xurl read POST_ID and confirm with the user; verify deletion afterwards' — this would remove the workflow-clarity cap.

Move the full shortcut catalog to a references/ file (e.g. SHORTCUTS.md) and keep the top ~10 commands plus a pointer in SKILL.md.

State the intended sequence explicitly (install → auth status → oauth2 → verify with whoami) near the top so the workflow is checkpointed rather than implied by section order.

DimensionReasoningScore

Conciseness

The body is almost entirely executable command listings under tight section headers (Install, Safety, Auth, Common shortcuts, Raw endpoint mode, Quick checks) with no explanation of concepts Claude already knows. It matches the 'lean and efficient; every token earns its place' anchor; the only near-redundancy (auth status/whoami reappearing in Quick checks) serves as a validation checklist rather than padding.

5 / 5

Actionability

Every section gives copy-paste-ready commands covering the common cases — install variants, 'xurl auth status', 'xurl post "Hello world!"', 'xurl -X POST /2/tweets -d ...' — fully matching the 'fully executable; copy-paste ready' anchor. Nothing is pseudocode or abstract.

5 / 5

Workflow Clarity

The setup sequence is present and ordered (install → auth status → oauth2 → quick checks), but destructive operations ('xurl delete 1234567890', posting, unfollow) are listed with no validation, confirmation, or read-before-write guidance, which per the guidelines caps workflow clarity at 3. It is not a 2 because the install/auth flow is coherent and includes a 'Quick checks' verification section.

3 / 5

Progressive Disclosure

The body is well-structured with clear sections and no buried or nested references (no bundle files exist), fitting the 'good structure; most content appropriately placed; minor organization gaps' anchor. It is not a 5 because the ~35-command shortcut catalog is fully inlined in SKILL.md and could be split into a one-level-deep reference file to keep the overview lean.

4 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, tool-specific, and low-conflict, but it is a compressed keyword list rather than a full sentence: it names capability areas without covering the breadth of operations (post, search, DM) and omits any 'Use when...' trigger guidance. Adding an explicit trigger clause and a few natural user terms would lift completeness and trigger quality.

Suggestions

Add a 'Use when...' clause, e.g. 'Use when the user wants to post, search, read, or manage X (Twitter) content via the xurl CLI or the X API'.

Include natural user vocabulary such as 'tweet', 'post', 'DM', and 'X/Twitter' so the skill triggers on phrases users actually say.

Convert the keyword list into third-person action phrases ('Posts, searches, and manages X content') to make the what more concrete.

DimensionReasoningScore

Specificity

The description lists several concrete capability areas — "install, auth, app choice, shortcuts, raw endpoints" — anchored to a named tool ("xurl X API CLI"), matching the 'several specific actions; minor gaps in coverage' anchor. It is not a 5 because the actions are terse keywords rather than a comprehensive list of concrete operations (posting, searching, DMs are absent).

4 / 5

Completeness

The 'what' is clear ("xurl X API CLI: install, auth, app choice, shortcuts, raw endpoints"), but there is no 'Use when...' or equivalent trigger clause, which per the guidelines caps completeness at 3. It is not a 4 because the 'when' is entirely absent rather than merely implicit or under-specified.

3 / 5

Trigger Term Quality

Terms like "X API", "CLI", "install", "auth", "shortcuts" are natural phrases a user would say when needing this skill, giving good keyword coverage. It falls short of the 5 anchor because common user variations such as "tweet", "post", "DM", or "timeline" are missing.

4 / 5

Distinctiveness Conflict Risk

Naming the specific tool ("xurl") and its narrow niche ("X API CLI") gives it a clear niche with distinct triggers and minimal conflict risk with other skills. It clearly matches the 5 anchor and is not merely 'mostly distinct' as in the 4 anchor.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
steipete/agent-scripts
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.