CtrlK
BlogDocsLog inGet started
Tessl Logo

chef-inspec

Chef InSpec integration. Manage data, records, and automate workflows. Use when the user wants to interact with Chef InSpec data.

56

Quality

64%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/chef-inspec/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and action-oriented with executable Membrane CLI commands and a useful connection-readiness feedback loop. Its main weaknesses are inconsistent step numbering and the absence of any progressive-disclosure references, leaving a large single-file reference where splitting would help.

Suggestions

Fix the step numbering so 'Step 1'/'1b' and 'Step 2' form a consistent, labeled sequence rather than orphaned references.

Move the proxy flag table and connection-state reference into a separate references file (e.g. REFERENCES.md) linked from the body to improve progressive disclosure.

Trim the opening 'Chef InSpec is an open-source framework...' paragraph, which restates domain knowledge Claude already has.

DimensionReasoningScore

Conciseness

The body is mostly lean command examples with terse explanations, though the opening framework summary ('Chef InSpec is an open-source framework for automating security and compliance testing...') restates context Claude already knows, fitting anchor 4's 'minor instances of over-explanation that could be trimmed'.

4 / 5

Actionability

It provides copy-paste-ready commands throughout (npm install, membrane login, connection ensure, action run) plus a flag table, but some examples rely on unresolved placeholders like CONNECTION_ID rather than fully worked cases, landing at anchor 4.

4 / 5

Workflow Clarity

There is a clear install→login→connect→search→run sequence with a poll-until-READY feedback loop and state handling, but the step numbering is inconsistent ('Step 2', '1b' with no matching 1a/Step 1), leaving minor gaps typical of anchor 4.

4 / 5

Progressive Disclosure

No bundle files (references/scripts/assets) exist and all content is inline in a 157-line file; the CLI flag table and connection-state details could reasonably live in a separate reference file, matching anchor 3's 'content that should be separate is inline'.

3 / 5

Total

15

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly targets a clear niche (Chef InSpec) and includes an explicit 'Use when' trigger, but its capability verbs are generic ('manage data, records') rather than concrete InSpec actions. Trigger keyword coverage is narrow, relying almost entirely on the product name.

Suggestions

Replace generic verbs with concrete InSpec actions, e.g. 'Run compliance profiles, scan targets, and fetch control results'.

Add natural trigger terms users actually say, such as 'compliance scan', 'InSpec profile', or 'run controls', not just the product name.

Expand the 'Use when' clause with concrete trigger phrases like 'Use when the user wants to run InSpec scans, check compliance, or review profile results'.

DimensionReasoningScore

Specificity

It names the domain and gestures at actions ('Manage data, records, and automate workflows'), but the actions are generic data verbs rather than concrete InSpec operations (run profiles, scan targets, view compliance results), so it sits between anchors 2 and 3 and leans low.

2 / 5

Completeness

It answers both what ('Manage data, records, and automate workflows') and when ('Use when the user wants to interact with Chef InSpec data'), with the 'when' explicit but generic rather than listing concrete trigger phrases, fitting anchor 4.

4 / 5

Trigger Term Quality

'Chef InSpec data' and 'Chef InSpec integration' are relevant named terms, but coverage is thin with no natural synonyms users say ('compliance scan', 'InSpec profile', 'controls'), matching anchor 3's 'some relevant keywords but missing common variations'.

3 / 5

Distinctiveness Conflict Risk

'Chef InSpec' is a specific niche with minimal conflict risk, but the generic 'manage data, records, and automate workflows' phrasing could overlap with other data-integration skills, keeping it just below the fully-distinct anchor 5.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.