CtrlK
BlogDocsLog inGet started
Tessl Logo

api-tester

Test and document API endpoints - validate responses, check status, generate examples

52

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/research-tools/capabilities/api-tester/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is concise and well-sectioned, giving a recognizable API-testing workflow, but nearly half the curl examples contain malformed JSON payloads or stray tokens that make them non-executable, and the workflow lacks inline validation checkpoints. Fixing the broken code blocks and adding explicit verify steps would lift the two weakest dimensions.

Suggestions

Fix the malformed JSON payloads in Step 2, Step 4, and the first Example Usage block — each closes the -d argument prematurely ('...smartscraper"}' before website_url/user_prompt), leaving dangling lines that break the command.

Remove stray tokens from the Discover More section ('api show riveter' after the -d payload, and the stray backtick-quote in '/v1/scrapes`"}') so those commands are copy-paste runnable.

Add explicit validation checkpoints to the workflow, e.g. after each request: check the HTTP status code and response shape, and re-test with an invalid key or bad URL to exercise error paths.

DimensionReasoningScore

Conciseness

The body is lean with no explanation of concepts Claude already knows; sections are tight and command-focused. Only a minor trim is needed (the standalone line 'Test API endpoints, validate responses, and generate documentation examples.' restates the frontmatter description), so it does not reach 5.

4 / 5

Actionability

Steps 1 and 3 give executable curl commands, but roughly half the code blocks are syntactically broken as written: Step 2 closes the -d JSON early ('..."path":"/v1/smartscraper"}' followed by dangling lines), Step 4 has the same defect, the first Example Usage block repeats it, and Discover More contains stray tokens ('api show riveter', a stray quote in '/v1/scrapes`"'). This matches 'some concrete guidance but incomplete; missing key details' rather than the mostly-executable anchor at 4.

3 / 5

Workflow Clarity

Steps 1-4 give a recognizable test sequence, but there are no validation checkpoints (no status-code checks, no error-case runs, no 'verify the response matches the schema' step in the flow); the Tips section mentions error cases only as an aside. This fits 'steps listed but validation gaps' and does not reach 4.

3 / 5

Progressive Disclosure

No bundle files exist, and the body is organized into clear, well-scoped sections (Setup, Workflow, Example Usage, Tips, Discover More) with content mostly appropriately placed for a skill of this size. It falls short of 5 because the endpoint-catalog material in Discover More and the repeated proxy invocation boilerplate could be split into a reference file.

4 / 5

Total

14

/

20

Passed

Description

55%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description states a clear, moderately specific capability set with concrete action verbs, but it omits any 'Use when...' trigger guidance and has thin natural-keyword coverage. It would benefit most from an explicit trigger clause and common synonyms such as 'REST', 'curl', or 'API documentation'.

Suggestions

Add an explicit 'when' clause, e.g. 'Use when the user asks to test, hit, or debug API endpoints, validate responses, or generate API documentation examples.'

Broaden trigger terms with natural synonyms users would say: 'REST API', 'curl request', 'endpoint', 'API docs', 'status codes'.

Mention the validation scope (schemas, error cases, auth) to sharpen the niche and reduce overlap with generic documentation or HTTP-request skills.

DimensionReasoningScore

Specificity

Lists three concrete actions in the API domain ("validate responses, check status, generate examples"), matching the 'several specific actions; minor gaps' anchor. It is not a 5 because coverage is not comprehensive — no mention of auth testing, schema validation, or error-case handling.

4 / 5

Completeness

It has a clear 'what' ("Test and document API endpoints - validate responses, check status, generate examples") but no 'when' — there is no 'Use when...' clause or equivalent trigger guidance, which caps completeness at 3 per the rubric guidelines. It is above 2 because the 'what' is concrete rather than vague.

3 / 5

Trigger Term Quality

"API endpoints", "validate responses", and "check status" are natural terms, but common variations users would say ("REST", "curl", "API docs", "hit an endpoint") are missing, matching the 'some relevant keywords but missing common variations' anchor. Not a 4 because keyword coverage is thin relative to the natural phrases in that anchor's example.

3 / 5

Distinctiveness Conflict Risk

"Test and document API endpoints" is somewhat specific to API testing but would overlap with general HTTP-request skills, documentation-generation skills, and specific API client skills. It lacks a clear niche with distinct triggers, so it does not reach 4.

3 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
gooseworks-ai/goose-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.