CtrlK
BlogDocsLog inGet started
Tessl Logo

neon-functions

Long-running, serverless Node.js HTTP functions deployed onto your Neon branch, with DATABASE_URL injected automatically and compute that runs next to your data. Use when a user wants to host an API, an AI agent with long streaming responses, a WebSocket or server-sent-events (SSE) server, a webhook handler, a Discord bot, an MCP server, or any request/response workload that risks timing out on short, lambda-style serverless functions — and wants it to branch with their database. Also use for Function Triggers: a cron or an object-storage event that POSTs to a function. Triggers include "serverless function", "deploy an API", "long-running function", "streaming agent", "SSE server", "WebSocket server", "webhook handler", "MCP server", "cron", "function trigger", "scheduled function", "cron job", "object storage trigger", "on upload", "run code next to my database", "function that won't time out", "function logs", "Neon Functions", "Neon Compute", "DDoS protection", "rate limiting", and "production hardening".

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/neon-functions/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable body packed with platform-specific knowledge Claude cannot infer, with genuine validation checkpoints and a clean one-level reference bundle. Its weaknesses are verbosity from duplicated warnings and repeated region lists, the fully inlined WebSocket section that breaks the otherwise good progressive-disclosure pattern, and a few undefined helper functions in otherwise executable code.

Suggestions

Deduplicate repeated content: state the supported-region list and the missing-env-value warning (empty-string coercion deleting live keys) once and cross-reference them, and consolidate the pooled/unpooled DATABASE_URL guidance.

Move the WebSocket cross-isolate playbook (three fan-out strategies, heartbeat, and reconnect client) into a references/websocket.md, mirroring how the SSE pattern is split into references/sse.md.

Define or explicitly flag the undefined helpers in code examples (cors(request), verifyToken, persist) so the snippets are copy-paste ready, and prefer relative reference paths over full neon.com URLs where the bundled file exists.

DimensionReasoningScore

Conciseness

The body is dense with non-obvious, platform-specific facts (15-minute TTFB/heartbeat/waitUntil limits, env-var coercion deleting live keys, JWKS issuer verification, cross-isolate fan-out pitfalls), so most tokens earn their place — above the verbose anchors. But it is not 4: the supported-region list is repeated three times, the "never coerce a missing process.env value to an empty string / KEY= is also \"\"" warning appears nearly verbatim in both "Develop Locally and Deploy" and "Environment Variables", and pooled/unpooled connection-string guidance is duplicated between the env table and "Connecting to Postgres" — several sections could be tightened or consolidated.

3 / 5

Actionability

Mostly fully executable guidance: complete Hono+Drizzle setup, JWT verification with jose, WebSocket upgrade via upgradeWebSocket, heartbeat keepalive, Postgres polling fan-out, LISTEN/NOTIFY, SSE ReadableStream endpoint, and exact CLI commands (neon dev, neon deploy --env, neon functions get <slug>, neon config plan). Falls short of 5 on minor gaps: the cors(request) helper in the JWT snippet, verifyToken in the WebSocket snippets, and persist in the broadcast example are used but never defined, so those examples are not copy-paste complete.

4 / 5

Workflow Clarity

A clear overall sequence (availability precondition → setup in neon.ts → local dev → deploy → env vars → connecting → limits → workload patterns) with real checkpoints: "Check this precondition before setting anything up" (region), neon config plan dry-run before apply, "add --update-existing only after reviewing those changes", and explicit auth validation ("Exercise two users: each can access their own data; cross-user access is denied. Repeat after restarting the Function"). Not 5 because the deploy workflow is spread across several sections without a single ordered procedure, and validation feedback loops (validate → fix → retry) are implied rather than explicit.

4 / 5

Progressive Disclosure

Good structure scored against the actual bundle: eight one-level-deep reference files exist in references/ and are each clearly signaled from the body (native-binaries, production-hardening, function-triggers, ai-sdk, mastra-studio, mcp, sentry, sse). Not 5 because the ~120-line WebSocket playbook (three fan-out strategies plus a reconnect client) is fully inline while its SSE counterpart is properly split into references/sse.md — an inconsistency showing content that should be separate is inline — and half the reference links point to full neon.com URLs rather than the bundled relative paths.

4 / 5

Total

15

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, explicit use-when guidance with an extensive natural trigger list, and a clearly anchored Neon niche. The only deductions are the second-person possessive phrasing and a few broad trigger terms with mild overlap risk against generic serverless/hosting skills.

DimensionReasoningScore

Specificity

The description lists multiple concrete, comprehensive capabilities ("Long-running, serverless Node.js HTTP functions", "DATABASE_URL injected automatically", host "an API, an AI agent with long streaming responses, a WebSocket or server-sent-events (SSE) server, a webhook handler, a Discord bot, an MCP server", cron and object-storage triggers), matching the 5 anchor. However, "deployed onto your Neon branch" uses second-person possessive voice, which the guidelines penalize by reducing the specificity score by 1.

4 / 5

Completeness

Explicitly answers both what ("Long-running, serverless Node.js HTTP functions deployed onto your Neon branch, with DATABASE_URL injected automatically and compute that runs next to your data") and when ("Use when a user wants to host an API... a webhook handler, a Discord bot, an MCP server... Also use for Function Triggers: a cron or an object-storage event that POSTs to a function") with concrete trigger phrases. Matches the 5 anchor exactly; a 4 would require a less explicit 'when' clause, which is not the case here.

5 / 5

Trigger Term Quality

Comprehensive natural trigger coverage including synonyms and variations: "serverless function", "deploy an API", "long-running function", "streaming agent", "SSE server", "WebSocket server", "cron", "cron job", "scheduled function", "object storage trigger", "on upload", "run code next to my database", "function that won't time out", "Neon Functions", "Neon Compute" — all phrases a user would naturally say. Not below 5 because nothing common is missing; not applicable above.

5 / 5

Distinctiveness Conflict Risk

The Neon anchoring ("Neon branch", "Neon Functions", "Neon Compute", "run code next to my database") gives a clear niche with mostly distinct triggers, but broad terms like "serverless function", "deploy an API", "DDoS protection", and "rate limiting" carry minor overlap risk with generic hosting/serverless skills. Mostly distinct with minor overlap — the 4 anchor.

4 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (667 lines); consider splitting into references/ and linking

Warning

metadata_version

'metadata.version' is missing

Warning

Total

14

/

16

Passed

Repository
stevenknowswhy/ProfessionalBuyer
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.