CtrlK
BlogDocsLog inGet started
Tessl Logo

list-npm-package-content

List the contents of an npm package tarball before publishing. Use when the user wants to see what files are included in an npm bundle, verify package contents, or debug npm publish issues.

90

1.47x
Quality

87%

Does it follow best practices?

Impact

100%

1.47x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-structured body for a simple single-purpose skill: the command is executable, the script reference is real, and the inclusion-rule facts are genuinely useful. The only minor gap is a slight ambiguity about where the script path resolves from.

DimensionReasoningScore

Conciseness

Roughly 30 lean lines with no padding or explanation of concepts Claude already knows; the npm inclusion rules (files field precedence, always-included README/LICENSE/CHANGELOG) are non-obvious specifics that earn their tokens. Not 4 because no over-explanation was found to trim.

5 / 5

Actionability

Provides a concrete copy-paste command ('bash scripts/list-package-files.sh') backed by a real, complete script, and summarizes its behavior accurately. Not 5 because 'Run the script from the package directory (e.g., packages/ai)' leaves ambiguous whether the relative path resolves from the package directory or the skill directory, and the pnpm-vs-npm tooling assumption is unstated.

4 / 5

Workflow Clarity

A single-action skill whose one step is unambiguous: run the script, which builds, packs, lists, and cleans up (matching the actual script). The rm only removes the tarball the script itself created, so the destructive-operation cap does not apply.

5 / 5

Progressive Disclosure

Under 50 lines with well-organized sections (Usage, Understanding Package Contents) and one real, one-level-deep script reference that exists in the bundle. No external references are needed for a skill this size.

5 / 5

Total

19

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with explicit what/when structure and natural trigger terms. The only weakness is that it lists a single capability, making the 'what' slightly less comprehensive than the best examples.

DimensionReasoningScore

Specificity

Names the domain ('npm package tarball') and one concrete action ('List the contents... before publishing'), but offers no additional capabilities such as inspecting sizes or diffing against the files allowlist. It is not 4 because only a single action is listed, and not 2 because the action and domain are concrete rather than generic.

3 / 5

Completeness

Explicitly answers both what ('List the contents of an npm package tarball before publishing') and when ('Use when the user wants to see what files are included in an npm bundle, verify package contents, or debug npm publish issues') with concrete trigger phrases, matching the anchor 5 example structure.

5 / 5

Trigger Term Quality

Includes several natural phrases users would say ('npm bundle', 'verify package contents', 'debug npm publish issues'). It is not 5 because common variants like '.tgz' or 'what's in my package' are missing, and not 3 because coverage goes beyond a couple of generic keywords.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (pre-publish npm tarball inspection) with distinct triggers ('npm bundle', 'npm publish issues') and minimal overlap with generic packaging or publishing skills.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
vercel/ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.