CtrlK
BlogDocsLog inGet started
Tessl Logo

identity-verification-didit

Identity verification via phone/email OTP and AML screening using Didit API

59

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/research-tools/capabilities/identity-verification-didit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable — complete executable curl examples for all six capabilities with clear auth setup — and mostly token-efficient. Its weaknesses are the implicit send-then-check workflow with no error-handling guidance, and the monolithic inlining of full parameter references that would fit better in a reference file.

Suggestions

Explicitly sequence the OTP flow (e.g. "Send Phone Code → user receives code → Check Phone Code within three attempts") and add guidance for handling failed or declined results.

Move the verbose AML and Database Validation parameter references into a references/ file (e.g. references/aml.md), keeping one compact example per endpoint in SKILL.md.

Remove the duplicated capability descriptions (the Capabilities list repeats the Usage section intros verbatim) to save tokens.

DimensionReasoningScore

Conciseness

The body is dominated by terse parameter lists and compact curl commands, e.g. "phone_number* (string) - Phone number in E.164 format (e.g. +14155552671)" — efficient with only minor padding such as the duplicated AML intro sentence ("The AML Screening API allows you to screen individuals or companies against global watchlists...") in both Capabilities and Usage, and marketing prose like "mitigate risks associated with financial fraud and terrorism". Not a 5 because these few padded sentences could be trimmed.

4 / 5

Actionability

Every endpoint has a fully executable, copy-paste-ready curl command with auth headers and a realistic request body (e.g. the /v3/phone/check example with +1234567890 and code 123456), plus concrete credential setup including a fallback instruction ("If ~/.gooseworks/credentials.json does not exist, tell the user to run: npx gooseworks login"). Common cases for all six capabilities are covered.

5 / 5

Workflow Clarity

Endpoints are individually documented but the core OTP workflow (send code → user receives → check code) is only implied by section names, never explicitly sequenced, and there is no guidance on handling failed checks or declined actions (e.g. what to do when duplicated_phone_number_action returns DECLINE). Not a 4 because the pairing of send/check steps and error handling is left implicit rather than having only minor gaps.

3 / 5

Progressive Disclosure

The body is well-sectioned (Setup, Capabilities, Usage, Use Cases, Discover More) but is ~165 lines with the full 15-parameter AML reference and the database-validation parameter list inlined, and no bundle/reference files exist to offload them. Not a 4 because API reference content that clearly belongs in a separate file is inline; not a 2 because the section structure itself is clear and navigable.

3 / 5

Total

15

/

20

Passed

Description

65%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concrete and clearly scoped to a distinct niche, naming the Didit API and specific verification modalities. Its main weaknesses are the absent "Use when..." trigger guidance and incomplete capability coverage (database validation and KYC-related synonyms are missing).

Suggestions

Add an explicit trigger clause, e.g. "Use when the user needs to verify phone or email ownership with OTP codes, run AML/sanctions screening, or validate identity documents."

Mention the database validation capability and natural synonyms (KYC, sanctions/watchlist screening) to improve both completeness and trigger-term coverage.

Consider naming the one-time-code concept ("one-time verification codes") so users who say "send a verification code" match naturally.

DimensionReasoningScore

Specificity

"Identity verification via phone/email OTP and AML screening" names the domain and two concrete action families, but omits the Database Validation capability entirely, so coverage is not comprehensive as the anchor-3 example ('Processes PDF files and extracts content') reflects. Not a 4 because the missing database-validation API is a whole third capability, more than a 'minor gap'.

3 / 5

Completeness

It clearly answers "what" (phone/email OTP verification and AML screening via Didit API) but contains no "Use when..." clause or equivalent trigger guidance, which caps completeness at 3 per the judging guidelines. Not a 4 because the "when" is entirely absent rather than merely implicit.

3 / 5

Trigger Term Quality

"identity verification", "OTP", "AML screening" are natural phrases users would say when needing this skill, giving good keyword coverage. Not a 5 because common synonyms like "KYC", "sanctions screening", "watchlist", or "two-factor" are missing.

4 / 5

Distinctiveness Conflict Risk

"using Didit API" plus the specific verification modes (phone/email OTP, AML screening) establish a clear niche with distinct triggers and minimal overlap risk. Not a 4 because no closely related generic skill would be triggered ahead of it.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
gooseworks-ai/goose-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.