CtrlK
BlogDocsLog inGet started
Tessl Logo

agent-package-manager

Installs, configures, audits, and operates Agent Package Manager (APM) in repositories. Use when initializing apm.yml, installing or updating packages, validating manifests, managing lockfiles, compiling agent context, browsing MCP servers, setting up runtimes, or packaging resolved context for CI and team distribution. Don't use for writing a single skill by hand, generic package managers like npm or pip, or non-APM agent configuration systems.

78

Quality

98%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is agent-package-manager in webmaxru/enonic-agent-skills

SKILL.md
Quality
Evals
Security

Quality

Content

96%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-engineered operational playbook: fully concrete commands, an explicit five-step sequence with validation checkpoints and error-recovery loops, and accurate condition-scoped pointers to a real three-file reference bundle. Its only weakness is mild phrasal looseness in a handful of steps that could be tightened without losing meaning.

Suggestions

Tighten Step 2.2 ('Keep `name` and `version` present at the top level; treat them as required contract fields') to a single clause, and trim the directory enumeration in Step 1.1 to the few paths that actually change the decision.

Compress Step 4.4's explanation of what `apm install` already deploys into a one-line contrast with `apm compile` (e.g. 'compile only generates instruction files like AGENTS.md/CLAUDE.md; install already deploys everything else').

DimensionReasoningScore

Conciseness

The body is dense and command-focused with no explanations of concepts Claude already knows — every step names a concrete CLI action. Minor trimmable instances remain, e.g. 'Keep `name` and `version` present at the top level; treat them as required contract fields' (the second clause restates the first) and the long directory-enumeration list in Step 1.1. Not 5 because a few phrases are restated or spelled out beyond what a competent reader needs; not 3 because there is no genuinely unnecessary explanation or padding.

4 / 5

Actionability

Guidance is fully executable throughout: exact commands (`apm install --dry-run`, `apm compile --validate`, `apm preview <script> -p key=value`, `apm mcp show <server>`) and a concrete worked example (`apm install webmaxru/agent-skills/skills/webmcp`) that covers the common cases. Not 4 because the commands are copy-paste ready and include flags, arguments, and a realistic package-path example with no gaps in the core flows.

5 / 5

Workflow Clarity

A clearly sequenced five-step procedure with explicit validation checkpoints and feedback loops for risky/batch operations: dry-run previews before changes, 'verify the lockfile `resolved_commit` actually changed' after updates, 'verify the resolved state with `apm deps list`/`tree`/`info`', `--watch` only after the one-shot validation path is clean, and `apm pack` only after a successful install — plus a dedicated Error Handling section with fix-then-retry loops. Not 4 because validation is explicit rather than implicit and error recovery is a first-class section, matching the top anchor.

5 / 5

Progressive Disclosure

The SKILL.md body is a lean overview that defers detail to real, one-level-deep bundle files, each clearly signaled with a conditional trigger: references/manifest-and-lockfile.md, references/command-workflows.md, references/troubleshooting.md, and assets/apm.yml.template — all verified present on disk, and named troubleshooting sections ('Stale packages after update', 'Self-referencing dependencies') exist in the referenced file. Not 4 because every reference is condition-scoped, accurate, and exactly one level deep with no inlined content that belongs in a separate file.

5 / 5

Total

19

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This is an exemplary description: it states concrete third-person capabilities, provides explicit multi-condition triggers including a negative scope boundary, and actively disambiguates APM from npm/pip and hand-written skills. Length is justified by content rather than padding.

DimensionReasoningScore

Specificity

The description lists multiple concrete, third-person actions — 'Installs, configures, audits, and operates Agent Package Manager (APM)' plus enumerated capabilities ('initializing apm.yml', 'validating manifests', 'managing lockfiles', 'compiling agent context', 'browsing MCP servers', 'setting up runtimes', 'packaging resolved context for CI and team distribution') — matching the comprehensive-coverage anchor. Not 4 because coverage of the skill's operations has no notable gaps and every verb maps to a real APM capability.

5 / 5

Completeness

It explicitly answers both questions: the 'what' ('Installs, configures, audits, and operates Agent Package Manager (APM) in repositories') and an explicit, multi-trigger 'Use when...' clause, further reinforced by a 'Don't use for...' exclusion. Not 4 because the 'when' is not merely present but concrete and specific, exceeding the 'could be more explicit' level of the 4 anchor.

5 / 5

Trigger Term Quality

Natural user phrases are covered comprehensively: 'installing or updating packages', 'validating manifests', 'managing lockfiles', 'browsing MCP servers', 'setting up runtimes', 'packaging resolved context for CI', plus the concrete file name 'apm.yml'. Not 4 because both the common verb phrasings and domain-specific nouns users would actually say are present; nothing obvious is missing.

5 / 5

Distinctiveness Conflict Risk

It carves out a clear niche by naming the tool ('Agent Package Manager (APM)') and explicitly disambiguates from adjacent skills: 'Don't use for writing a single skill by hand, generic package managers like npm or pip, or non-APM agent configuration systems.' Conflict risk with similar-sounding skills is explicitly handled, matching the clear-niche anchor.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
webmaxru/web-ai-agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.