CtrlK
BlogDocsLog inGet started
Tessl Logo

checkmarx

Checkmarx integration. Manage data, records, and automate workflows. Use when the user wants to interact with Checkmarx data.

58

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/checkmarx/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with comprehensive executable commands and a generally clear workflow including validation checkpoints for connection setup. Its main weaknesses are an unnecessary conceptual opening paragraph and slightly inconsistent step numbering.

Suggestions

Remove or condense the opening SAST/Checkmarx background paragraph, which explains concepts Claude already knows.

Fix the step numbering (add a '1a' or relabel '1b' and label the 'Step 2' it references) so the connection workflow reads as a coherent numbered sequence.

Trim marketing phrasing like 'so you can focus on the integration logic rather than auth plumbing' to keep guidance lean.

DimensionReasoningScore

Conciseness

The body is mostly efficient command-based guidance, but opens with a paragraph explaining what SAST/Checkmarx is ('Checkmarx is a static application security testing (SAST) platform...') and includes light marketing phrasing ('so you can focus on the integration logic rather than auth plumbing') that could be trimmed.

3 / 5

Actionability

It provides copy-paste-ready, fully executable commands across install, login, headless auth, connection setup, action discovery, action execution, and proxying, with a concrete flag table covering the common cases.

5 / 5

Workflow Clarity

A clear install → auth → connect → search → run sequence exists with state-based polling checkpoints and a feedback loop for CLIENT_ACTION_REQUIRED, but the step numbering is inconsistent ('1b' with no '1a', references to an unlabeled 'Step 2'), leaving minor gaps.

4 / 5

Progressive Disclosure

The body is well-organized into clearly headed sections (Install, Authentication, Connecting, Searching, Running, Proxy, Best practices) with no nested references; at ~135 lines it exceeds the simple-skill threshold, so it does not earn the under-50-line exception but is otherwise well-structured.

4 / 5

Total

16

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly names the Checkmarx niche and includes an explicit 'Use when' trigger, making it distinct and complete. Its weakness is generic, non-concrete action language ('Manage data, records, and automate workflows') and limited keyword variation.

Suggestions

Replace generic verbs with concrete Checkmarx actions, e.g. 'Run SAST scans, review scan risk reports, and manage projects and queries' to improve specificity and trigger coverage.

Add natural trigger terms users would say, such as 'scans', 'vulnerabilities', 'SAST', or 'security testing', alongside 'Checkmarx'.

Tighten the 'what' clause so the capability list mirrors the concrete actions a user would request.

DimensionReasoningScore

Specificity

Names the Checkmarx domain but the stated actions ('Manage data, records, and automate workflows') are generic rather than concrete, matching the anchor where the domain is named but actions are minimal or generic.

2 / 5

Completeness

Both 'what' (Checkmarx integration, manage data/records/workflows) and an explicit 'when' ('Use when the user wants to interact with Checkmarx data') are present, though the 'what' is somewhat generic rather than fully concrete.

4 / 5

Trigger Term Quality

The natural keyword 'Checkmarx' and 'Checkmarx data' are present, but common variations a user would say (scan, vulnerabilities, SAST, security testing) are missing, leaving keyword coverage partial.

3 / 5

Distinctiveness Conflict Risk

'Checkmarx integration... Use when the user wants to interact with Checkmarx data' targets a specific named product with a clear niche and distinct triggers, giving minimal conflict risk with other skills.

5 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.