CtrlK
BlogDocsLog inGet started
Tessl Logo

contrast-security

Contrast Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Contrast Security data.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/contrast-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable Membrane CLI commands and a clear connection-to-action workflow including state validation, but it has a broken 'Step 2' cross-reference and minor redundancy. Strong overall with small structural fixes needed.

Suggestions

Fix the workflow numbering: define explicit 'Step 1' and 'Step 2' headings (or remove the dangling 'Step 2'/'1b' references) so the connection -> action sequence is unambiguous.

Remove the redundant 'Popular actions' section that repeats the `action list` command already given under 'Searching for actions', or merge them.

Consider moving the proxy flags table and agent-type list into a separate reference file to keep SKILL.md a lean overview, which would lift progressive disclosure toward a clear one-level-deep structure.

DimensionReasoningScore

Conciseness

The body is mostly efficient and command-driven, but it includes mild over-explanation (the opening platform summary and a redundant 'Popular actions' section repeating the earlier `action list` command) that could be trimmed, fitting the score-4 anchor.

4 / 5

Actionability

It provides copy-paste-ready, fully executable commands throughout (install, login, connection ensure/get with --wait, action list/run with --input, request proxy) plus a flags table covering the common cases, matching the score-5 anchor.

5 / 5

Workflow Clarity

There is a clear connection -> poll -> search -> run sequence with state-based checkpoints (READY/BUILDING/CLIENT_ACTION_REQUIRED/CONFIGURATION_ERROR) and retry loops, but the body references an undefined 'Step 2' and uses a '1b' heading with no '1a', leaving minor navigation gaps that hold it at score 4 rather than 5.

4 / 5

Progressive Disclosure

With no bundle files present, all content lives inline in well-organized sections (Overview, Install, Auth, Connecting, Searching, Popular actions, Proxy, Best practices); it is well structured with no nested references, though some reference-like material (proxy flags table, agent types) could be split out, fitting the score-4 anchor.

4 / 5

Total

17

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly includes an explicit 'Use when...' trigger and names a distinct domain, but its capability verbs ('manage data', 'records', 'automate workflows') are generic and it omits natural Contrast-specific trigger terms like vulnerabilities or traces. It is solid but could be sharpened.

Suggestions

Replace generic verbs with concrete Contrast Security actions, e.g. 'List and search vulnerabilities, inspect traces, and query application/organization data'.

Add natural trigger terms users would actually say, such as 'vulnerabilities', 'traces', 'security findings', or 'Contrast apps', to broaden keyword coverage.

Tighten the 'when' clause to concrete triggers, e.g. 'Use when the user wants to query or manage Contrast Security vulnerabilities, traces, applications, or users.'

DimensionReasoningScore

Specificity

Names the Contrast Security domain and a couple of actions ('Manage data, records, and automate workflows'), but the actions are generic rather than concrete capabilities, matching the score-3 anchor for 1-2 actions without comprehensive coverage.

3 / 5

Completeness

It states both what ('Contrast Security integration... Manage data, records, and automate workflows') and when ('Use when the user wants to interact with Contrast Security data'), but the 'when' is somewhat generic rather than concrete trigger phrases, matching the score-4 anchor.

4 / 5

Trigger Term Quality

'Contrast Security data' and 'records' provide some relevant keywords, but common variations and synonyms users would say (vulnerabilities, traces, security findings) are missing, fitting the score-3 anchor.

3 / 5

Distinctiveness Conflict Risk

'Contrast Security integration' defines a clear niche with minimal conflict risk against other skills, though the rest of the wording is generic enough to leave minor overlap, fitting the score-4 anchor.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.