CtrlK
BlogDocsLog inGet started
Tessl Logo

cobalt-io

Cobalt integration. Manage data, records, and automate workflows. Use when the user wants to interact with Cobalt data.

55

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/cobalt-io/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable, with concrete CLI commands and a well-sequenced connection workflow that includes state checkpoints and a feedback loop. Its main weaknesses are minor redundancy (the action-list command appears twice) and a conceptual intro paragraph that pads the token budget.

Suggestions

Remove the introductory 'Cobalt.io is a pentesting as a service' paragraph or trim it to one line, since Claude does not need PTaaS explained.

Consolidate the duplicated `membrane action list` instructions in 'Searching for actions' and 'Popular actions' into a single section.

Consider moving the request-flags table and the detailed clientAction schema into a separate reference file to keep SKILL.md as a lean overview.

DimensionReasoningScore

Conciseness

The body is mostly command-focused but includes unnecessary material: the intro paragraph explains what Cobalt/PTaaS is, and the 'Popular actions' section repeats the action-list command already shown in 'Searching for actions'. This fits 'mostly efficient but includes some unnecessary explanation or could be tightened'; not a 2 because the bulk is lean CLI guidance, and not a 4 due to the duplication and conceptual padding.

3 / 5

Actionability

Concrete, copy-paste-ready commands cover the common cases (login, connection ensure, action list/run, request with a flags table), fitting 'mostly executable guidance with minor gaps'; the placeholders like CONNECTION_ID and the conceptual intro keep it just short of fully copy-paste ready.

4 / 5

Workflow Clarity

The connection flow is sequenced with explicit state-based checkpoints (READY / CLIENT_ACTION_REQUIRED / CONFIGURATION_ERROR) and a poll-again feedback loop, matching 'clear sequence with most checkpoints present'; minor numbering drift (a 'Step 2' reference and a '1b' heading without a matching 1a) keeps it from 5.

4 / 5

Progressive Disclosure

The body is a single file (~140 lines) with well-organized sections and no bundle files present, so structure is good and navigation is clear; it does not earn 5 because some inline reference-like material (the flags table, detailed clientAction schema) is over the simple-skill threshold and could live in a separate file.

4 / 5

Total

15

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description provides a clear what/when pair tied to a named platform, but its action language is generic and its trigger vocabulary is thin. It is mostly distinct but could be sharpened with concrete Cobalt-specific operations and richer trigger terms.

Suggestions

Replace generic actions ('manage data, records, automate workflows') with concrete Cobalt-specific operations such as 'manage pentest findings, assets, and reports'.

Expand trigger terms to cover natural phrasings users would say, e.g. 'pentests, pentesting findings, Cobalt assets, security test reports'.

Make the 'Use when' clause more specific than 'interact with Cobalt data' by listing the triggering scenarios.

DimensionReasoningScore

Specificity

"Manage data, records, and automate workflows" names the Cobalt domain but the actions are generic and not concrete, matching the 'names the domain but actions are minimal or generic' anchor rather than the 3-anchor which requires concrete actions.

2 / 5

Completeness

It states both what ("Cobalt integration. Manage data, records, and automate workflows") and when ("Use when the user wants to interact with Cobalt data"), matching the anchor where both are present but 'when' could be more explicit; not a 5 because the trigger phrases are not richly concrete.

4 / 5

Trigger Term Quality

"Use when the user wants to interact with Cobalt data" includes the natural keyword 'Cobalt data' but misses common variations or synonyms, fitting the 'some relevant keywords but missing common variations' anchor.

3 / 5

Distinctiveness Conflict Risk

"Cobalt integration" plus the Cobalt trigger phrase gives a clear named niche with minimal conflict risk, but the generic 'manage data, records' wording leaves minor overlap risk, so it sits at 4 rather than 5.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.