CtrlK
BlogDocsLog inGet started
Tessl Logo

phone-verification

Verify phone numbers using SMS one-time codes via the Didit API. Use when you need to confirm a user owns a phone number, implement SMS-based 2FA, or validate phone during signup/onboarding flows.

62

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/research-tools/capabilities/phone-verification/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is well structured and its Quick Start is immediately executable, but the Workflow section both duplicates Quick Start and contains malformed curl commands, and error handling for failed verification is absent. Fixing the broken request format and consolidating the duplicated examples would raise quality substantially.

Suggestions

Fix the Workflow section's curl commands: merge the two -d flags into a single JSON body (as Quick Start correctly does) so the requests are actually executable.

Remove the duplication between Quick Start and Workflow — keep one canonical pair of send/check examples and use the other section for details like response formats and error cases.

Add the failure response for /v3/phone/check and brief guidance for handling wrong or expired codes (e.g., tell the user, offer to resend).

DimensionReasoningScore

Conciseness

The body is mostly efficient, but the Workflow section repeats the exact two curl calls already shown in Quick Start (~30 redundant lines), and the Use Cases section restates triggers from the description — content that could be tightened rather than minor trimming.

3 / 5

Actionability

Quick Start provides correct copy-paste-ready curl commands, but the Workflow section's examples split the JSON payload across two separate -d flags ("-d '{\"api\":\"didit\",\"path\":\"/v3/phone/send\"}'" followed by a second -d for the body), which curl concatenates into invalid JSON, and the TypeScript example constructs "new Orthogonal({})" with no auth configuration.

4 / 5

Workflow Clarity

The send-code → collect-code → verify sequence is clearly laid out, but there are no validation checkpoints: the check call's failure response is never shown, and there is no guidance for handling wrong or expired codes (retry, resend, or surface an error to the user).

3 / 5

Progressive Disclosure

With no bundle files, everything lives in SKILL.md under well-labeled sections (Setup, Quick Start, Workflow, Phone Number Format, Use Cases, Integration Example) with no nested references; the duplication between Quick Start and Workflow is the only organization gap keeping it from a clean top score.

4 / 5

Total

14

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states a concrete capability, names the provider, and includes an explicit use-when clause with natural, specific triggers. The only gap is that the send-code and check-code operations are folded into a single "verify" verb rather than listed as separate actions.

DimensionReasoningScore

Specificity

"Verify phone numbers using SMS one-time codes via the Didit API" names the domain, mechanism, and provider with concrete language, but it does not itemize the distinct send/check actions, leaving minor gaps in coverage rather than a comprehensive action list.

4 / 5

Completeness

It explicitly answers what ("Verify phone numbers using SMS one-time codes via the Didit API") and when, with a concrete "Use when..." clause listing three distinct trigger scenarios.

5 / 5

Trigger Term Quality

Natural phrases like "implement SMS-based 2FA", "validate phone during signup/onboarding flows", and "confirm a user owns a phone number" match what users would say, though common synonyms such as "OTP" or "one-time passcode" are missing.

4 / 5

Distinctiveness Conflict Risk

The description carves out a clear niche — SMS phone-number verification via a named API — with distinct trigger phrases (2FA, signup, ownership confirmation) that are unlikely to fire for unrelated skills.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
gooseworks-ai/goose-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.