CtrlK
BlogDocsLog inGet started
Tessl Logo

xurl

A CLI tool for making authenticated requests to the X (Twitter) API. Use this skill when you need to post tweets, reply, quote, search, read posts, manage followers, send DMs, upload media, or interact with any X API v2 endpoint.

86

1.44x
Quality

81%

Does it follow best practices?

Impact

97%

1.44x

Average score across 3 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable commands, clear workflows, and a genuine feedback checkpoint for media processing, plus excellent secret-safety guidance. Its weaknesses are the duplicated command catalog (Quick Reference table vs. Command Details) and a monolithic single-file structure with no progressive disclosure into reference files.

Suggestions

De-duplicate the Quick Reference table and the Command Details sections — keep the compact table as the index and move the per-category examples into a single detailed section or reference file instead of restating every command.

Split the full command catalog, global flags, raw API, and streaming sections into references/ files (e.g., commands.md, raw-api.md) linked one level deep from SKILL.md, keeping the body as a concise overview.

Add a pre-verification step before destructive operations (e.g., 'xurl read POST_ID' to confirm the target before 'xurl delete POST_ID', and check auth with 'xurl auth status' before batch writes).

DimensionReasoningScore

Conciseness

The body avoids concept explanations and is mostly tables and command blocks, but the Quick Reference table is restated nearly command-for-command in 'Command Details' (e.g., 'xurl post "Hello world!"' appears in both), which is more than the 'minor instances' tolerated at 4.

3 / 5

Actionability

Every command is copy-paste ready and executable, with concrete flag usage, JSON output and error shapes shown, and workflows that spell out placeholder substitution (e.g., 'xurl post "Check this out" --media-id MEDIA_ID'), fully covering common cases per the 5 anchor.

5 / 5

Workflow Clarity

Multi-step workflows are clearly numbered ("1. Upload the image / 2. Copy the media_id from the response, then post") with an explicit validation checkpoint ('xurl media status --wait' polls until done) and error feedback (non-zero exit codes, JSON errors, re-auth guidance), but destructive commands (delete, block, unfollow) lack any pre-verification step, preventing a 5.

4 / 5

Progressive Disclosure

No bundle files exist and the entire reference — full command catalog, global flags, raw API mode, streaming, and notes — is inlined in a single ~430-line SKILL.md; section headers provide structure, but content that clearly belongs in separate reference files is inline, which is the anchor-3 pattern rather than 2 (structure is good, not minimal).

3 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: third-person voice, a comprehensive list of concrete capabilities, and an explicit 'Use this skill when...' clause with natural trigger terms. Its only weakness is moderate synonym coverage — a few common user phrasings (like, retweet, timeline) are absent.

DimensionReasoningScore

Specificity

"post tweets, reply, quote, search, read posts, manage followers, send DMs, upload media" lists multiple specific concrete actions with comprehensive coverage of the tool's surface, matching the 5 anchor rather than 4 (which requires minor gaps in coverage).

5 / 5

Completeness

Explicitly answers both what ("A CLI tool for making authenticated requests to the X (Twitter) API") and when ("Use this skill when you need to post tweets... or interact with any X API v2 endpoint") with concrete trigger phrases, exactly matching the 5 anchor.

5 / 5

Trigger Term Quality

Natural phrases users would say ("post tweets", "search", "DMs", "followers", "X (Twitter) API") give good keyword coverage, but common user terms like "like", "retweet/repost", "timeline", and "mentions" are missing, so it falls short of the comprehensive-synonyms bar for 5.

4 / 5

Distinctiveness Conflict Risk

The X/Twitter API niche with distinct triggers (tweets, DMs, X API v2 endpoints) is highly unlikely to fire for the wrong skill, matching the 5 anchor for minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
trpc-group/trpc-agent-go
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.