CtrlK
BlogDocsLog inGet started
Tessl Logo

granola-security-basics

Security and privacy configuration for Granola meeting data. Use when reviewing data handling practices, configuring encryption, ensuring SOC 2/GDPR compliance, or securing meeting recordings. Trigger: "granola security", "granola privacy", "granola encryption", "granola SOC 2", "granola GDPR", "secure granola".

60

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/saas-packs/granola-pack/skills/granola-security-basics/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable security-configuration guide with concrete menu paths, commands, and a ready consent notice. Its main weaknesses are Overview/Step 1 redundancy, missing validation checkpoints in the workflows, and an orphaned reference file that the body never points to.

Suggestions

Link the bundled references/security-controls.md from the body (e.g., a '## Detailed controls' section pointing to it) and move the duplicated data-flow diagram, sharing matrix, and incident-response material out of SKILL.md to reduce overlap.

Add an explicit validation checkpoint to the Sensitive Meeting Protocol (e.g., 'Verify external sharing is disabled and consent was announced before proceeding') and a verify step to retention/deletion changes so the workflow clears the destructive-cap threshold.

Tighten redundancy between the Overview and Step 1 (the diagram and 'Key security properties' repeat the Overview's SOC 2 date, encryption, and audio-not-stored points) and move the 'July 2025' date into a clearly marked version/deprecated note.

DimensionReasoningScore

Conciseness

Tables and code blocks are efficient and it avoids lecturing on AES-256/TLS, but Step 1's ASCII diagram and 'Key security properties' duplicate the Overview, and the time-sensitive 'July 2025' SOC 2 date sits in the Overview rather than a deprecated section; mostly efficient but could be tightened, so not a 4.

3 / 5

Actionability

Concrete settings paths ('Settings > Security > SSO', 'Settings > Privacy > Data Retention'), a copy-paste consent notice, and a runnable 'chmod 600' command cover the common cases; not a 5 because a few entries ('Contact Granola support' for IP allowlisting) and UI-navigation steps are not copy-paste executable.

4 / 5

Workflow Clarity

Steps 1-6 and the numbered Sensitive Meeting Protocol give a clear sequence, plus a reactive Error Handling table, but no workflow includes an explicit validate-then-proceed checkpoint; because the skill touches destructive ops (retention/deletion, redaction) the destructive-skill cap also limits this to 3.

3 / 5

Progressive Disclosure

The body is well-sectioned, but the bundled references/security-controls.md is never linked from the body while overlapping content (data architecture, sensitive protocol, compliance, retention) is inlined and the Resources section points only to external URLs; references are present but not signaled, so not a 4.

3 / 5

Total

13

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states what it does, when to use it, and supplies concrete trigger phrases scoped to Granola. The only mild gap is trigger-term synonym coverage.

DimensionReasoningScore

Specificity

Names the Granola domain plus several concrete actions ('configuring encryption', 'securing meeting recordings', 'ensuring SOC 2/GDPR compliance', 'reviewing data handling practices'), matching the 'several specific actions; minor gaps' anchor; not a 5 because the actions are more abstract than the anchor's concrete operations.

4 / 5

Completeness

Explicitly answers both what ('Security and privacy configuration for Granola meeting data') and when ('Use when reviewing…') with a dedicated concrete Trigger list, matching the top anchor exactly.

5 / 5

Trigger Term Quality

Six natural trigger phrases ('granola security', 'granola privacy', 'granola encryption', 'granola SOC 2', 'granola GDPR', 'secure granola') give good coverage a user would plausibly say; not a 5 because synonym variations like 'granola compliance', 'granola data protection', or 'granola SSO' are missing.

4 / 5

Distinctiveness Conflict Risk

All triggers are 'granola'-prefixed and scoped to a named SaaS product, giving a clear niche with minimal overlap risk against generic skills.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
jeremylongshore/claude-code-plugins-plus-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.