CtrlK
BlogDocsLog inGet started
Tessl Logo

crowdstrike

CrowdStrike integration. Manage data, records, and automate workflows. Use when the user wants to interact with CrowdStrike data.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/crowdstrike/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill delivers highly actionable CLI guidance with a well-validated connection workflow, but carries orientation prose and redundancy that hurt token efficiency, and its single-file structure has minor organization gaps. Trimming explanatory padding and deduplicating the action-discovery sections would raise the score.

Suggestions

Remove the opening 'CrowdStrike is a cybersecurity platform...' paragraph and the filler line 'Use action names and parameters as needed.'; assume Claude knows what CrowdStrike is.

Merge the redundant 'Searching for actions' and 'Popular actions' sections into one action-discovery section to eliminate repeated `membrane action list` instructions.

Fix the step numbering (label the explicit 'Step 1 / Step 2' the text references, and resolve the dangling '1b') so the connection workflow reads as a coherent sequence.

DimensionReasoningScore

Conciseness

The body is mostly efficient with concrete CLI commands, but includes unnecessary orientation prose ('CrowdStrike is a cybersecurity platform that provides endpoint protection...'), filler ('Use action names and parameters as needed.'), and redundant action-list instructions across the 'Searching for actions' and 'Popular actions' sections.

3 / 5

Actionability

It provides concrete, copy-paste-ready commands for install, login, connection, action search/run, and proxy requests plus a flags table, with only minor gaps such as unresolved CONNECTION_ID placeholders and no end-to-end worked example.

4 / 5

Workflow Clarity

The connection setup is clearly sequenced with state-based validation (READY/BUILDING/CLIENT_ACTION_REQUIRED/CONFIGURATION_ERROR) and a re-poll feedback loop, but step numbering is inconsistent ('skip to Step 2' with no labeled Step 2, a lone '1b') and output verification for run actions is absent.

4 / 5

Progressive Disclosure

Content is organized into clear headed sections with no nested external references, but the single ~150-line file carries material (the proxy flags table, detailed clientAction handling) that could be split out, and the 'Popular actions' section overlaps with 'Searching for actions'.

4 / 5

Total

15

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly identifies a distinct niche (CrowdStrike) and answers both what and when, but the listed capabilities are generic and the trigger phrases lack variation. Tightening the action verbs and adding concrete trigger terms would lift it toward the top anchors.

Suggestions

Replace generic verbs ('Manage data, records, and automate workflows') with concrete CrowdStrike actions such as 'search indicators, run RTR sessions, query hosts, and submit files to sandbox'.

Expand the 'Use when' clause with concrete trigger phrases users would naturally say, e.g. 'Use when the user wants to search Falcon indicators, run Real Time Response sessions, or query CrowdStrike hosts'.

Add natural synonyms and product terms (Falcon, indicators of compromise, RTR, MalQuery) to improve trigger-term coverage.

DimensionReasoningScore

Specificity

Names the CrowdStrike domain plus a few action categories ('Manage data, records, and automate workflows'), but the actions are generic rather than concrete operations, matching the 'names domain and 1-2 concrete actions, but not comprehensive' anchor.

3 / 5

Completeness

It states both what ('Manage data, records, and automate workflows') and when ('Use when the user wants to interact with CrowdStrike data'), but the 'when' clause is generic rather than enumerating concrete trigger phrases, matching the 'both what and when; when could be more explicit' anchor.

4 / 5

Trigger Term Quality

'CrowdStrike' and 'interact with CrowdStrike data' provide the core natural keyword, but common variations or synonyms are missing, fitting the 'some relevant keywords but missing common variations' anchor.

3 / 5

Distinctiveness Conflict Risk

'CrowdStrike integration' targets a specific named product with a distinct trigger, giving it a clear niche and minimal conflict risk with other skills.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.