CtrlK
BlogDocsLog inGet started
Tessl Logo

bright-security

Bright Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Bright Security data.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/bright-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, mostly executable guide to driving Bright Security through the Membrane CLI, with a clear connection workflow and explicit state-based feedback loops. It is efficient and actionable with only minor redundancy and slight room to trim explanatory prose.

DimensionReasoningScore

Conciseness

The body is efficient, leading with executable commands and assuming competence, with only minor over-explanation (e.g. "This will burn less tokens and make communication more secure").

4 / 5

Actionability

It provides concrete, copy-paste-ready CLI commands across install, auth, connection, action running, and proxy use, with a couple of minor gaps like the redundant "Popular actions" section restating the action list command.

4 / 5

Workflow Clarity

The connection flow is clearly sequenced with state polling (--wait) and explicit handling of READY / CLIENT_ACTION_REQUIRED / CONFIGURATION_ERROR states including a feedback loop to re-poll after a user action; only minor validation gaps remain.

4 / 5

Progressive Disclosure

Content is well-organized into clear section headers within a single SKILL.md with no nested references and no bundle files, leaving only minor organization gaps rather than a clean one-level reference structure.

4 / 5

Total

16

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly includes both a what and an explicit when clause and is anchored to a distinct product name. Its main weakness is vague, non-concrete action language that under-specifies what the skill actually does with Bright Security.

Suggestions

Replace generic verbs with concrete Bright Security actions, e.g. "Find and fix vulnerabilities, manage scan configurations, issues, and projects. Use when the user wants to run Bright Security scans or triage scan issues."

Add natural user trigger phrases and synonyms, e.g. mentioning "Bright Security scans", "vulnerabilities", "scan issues", or "Brightsec".

DimensionReasoningScore

Specificity

It names the Bright Security domain and a few nouns ("data, records") but the verbs are generic ("Manage", "automate workflows") with no concrete actions like scanning issues or creating projects, matching the score-2 anchor of minimal/generic actions.

2 / 5

Completeness

It provides both a "what" ("Manage data, records, and automate workflows") and an explicit "when" ("Use when the user wants to interact with Bright Security data"), though the when-clause could be more specific with concrete trigger phrases.

4 / 5

Trigger Term Quality

"Bright Security" is a relevant keyword and "interact with Bright Security data" gives a usable phrase, but coverage lacks common synonyms or variations a user would naturally say.

3 / 5

Distinctiveness Conflict Risk

Being tied to the named product "Bright Security" gives it a clear niche with minimal conflict risk, though the surrounding action language ("manage data, automate workflows") is generic enough to allow minor overlap.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.