CtrlK
BlogDocsLog inGet started
Tessl Logo

secops-setup-gemini

Helps the user configure the Google SecOps Remote MCP Server for Gemini CLI. Use this when the user asks to "set up" or "configure" the security tools for Gemini CLI.

86

2.94x
Quality

80%

Does it follow best practices?

Impact

100%

2.94x

Average score across 3 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actionable setup walkthrough with concrete commands and a clear sequence including a verification step. It could improve by adding an error-recovery feedback loop and reconciling the region/URL handling in the config block.

Suggestions

Add an explicit feedback loop after verification, e.g. 'If the prompt fails with an auth error, re-run gcloud auth application-default login and set-quota-project, then retry'.

Reconcile the REGION prerequisite with the config block's hardcoded chronicle.us.rep URL, or note that the URL must be adjusted for non-us regions, to close the actionability gap.

DimensionReasoningScore

Conciseness

The body is mostly lean with code blocks and direct steps and no padding about concepts Claude already knows; the opening persona line ('You are an expert...') and the conversational 'Ask if... / If not, guide...' phrasing are minor over-explanation that keep it just below 5.

4 / 5

Actionability

It provides concrete, copy-paste-ready commands (uv install curl, gcloud auth, JSON config block, verification prompt), but the hardcoded httpUrl does not vary with the collected REGION and only the us case is exemplified, leaving a minor gap versus the fully comprehensive 5 anchor.

4 / 5

Workflow Clarity

The flow is clearly sequenced (prerequisite checks -> configuration -> verification) with a final validation command, but there is no explicit feedback loop ('if the test fails, do X'), so it sits at 4 rather than 5; the operation is non-destructive so the batch/destructive cap does not apply.

4 / 5

Progressive Disclosure

The skill is under 50 lines, single-purpose, and organized into well-labeled sections (Prerequisite Checks, Configuration Steps, Verification) with no need for external reference files, meeting the simple-skill exception for a 5.

5 / 5

Total

17

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is clear, third-person, and explicitly answers both what the skill does and when to trigger it with natural user phrasings. Its main weakness is specificity, listing only the single action 'configure' rather than enumerating the concrete setup sub-tasks.

Suggestions

Expand the 'what' clause to list concrete actions, e.g. 'Checks prerequisites (uv, gcloud auth), gathers project/customer/region config, and updates ~/.gemini/config.json' to lift specificity toward 4-5.

Add a couple more natural trigger synonyms (e.g. 'connect', 'onboard SecOps') to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

The description names the domain ('Google SecOps Remote MCP Server for Gemini CLI') and one concrete action ('configure'), but lists only a single action rather than several specific actions, so it sits at the 3 anchor and below 4 which requires multiple concrete actions.

3 / 5

Completeness

It explicitly states both what it does ('configure the Google SecOps Remote MCP Server for Gemini CLI') and when to use it ('Use this when the user asks to "set up" or "configure" the security tools for Gemini CLI') with concrete trigger phrases, matching the 5 anchor.

5 / 5

Trigger Term Quality

It includes natural user phrasings like 'set up' and 'configure' with synonyms, plus 'security tools' and 'Gemini CLI', giving good keyword coverage; it falls short of 5 only because the term set is narrow and lacks the broader synonym spread the 5 anchor implies.

4 / 5

Distinctiveness Conflict Risk

The narrowly scoped 'Google SecOps Remote MCP Server for Gemini CLI' with its specific trigger phrases carves a clear niche with minimal overlap against other skills, matching the 5 anchor.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
google/mcp-security
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.