CtrlK
BlogDocsLog inGet started
Tessl Logo

curity

Curity integration. Manage data, records, and automate workflows. Use when the user wants to interact with Curity data.

52

Quality

59%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/curity/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill delivers strong, executable CLI guidance with a well-sequenced connection workflow and clear state handling. It is dragged down by a large, low-value inline term list that wastes tokens and by the absence of any progressive-disclosure file structure.

Suggestions

Remove or collapse the ~80-item 'Curity Overview' bullet list — most entries (Logout, Pricing, Blog, Roadmap, Settings) are generic app sections that add no actionable value and consume significant context.

Move detailed reference material (the full state-handling reference, proxy flag table, or action catalog) into a references/ file and link to it from SKILL.md to improve progressive disclosure.

Fix the step labeling inconsistency ('1b' with no '1a', and a 'Step 2' referenced without a clearly numbered Step 1) so the connection workflow sequence is unambiguous.

DimensionReasoningScore

Conciseness

The ~80-item 'Curity Overview' bullet list (Clients, Token Policies, ... Logout, Pricing, Blog, Roadmap) is a large block of generic one-word terms that adds no actionable value and the intro paragraph restates product basics, matching 'noticeably verbose; several unnecessary explanations or padded sections'.

2 / 5

Actionability

Concrete copy-paste commands are given throughout (npm install, membrane login, connection ensure, action list/run, request) with a flag table for proxying, matching 'mostly executable guidance; concrete code or commands with minor gaps' such as the CONNECTION_ID/QUERY placeholders.

4 / 5

Workflow Clarity

The connection flow is a clear sequenced process with state-based checkpoints (READY/BUILDING/CLIENT_ACTION_REQUIRED/CONFIGURATION_ERROR) and a re-poll feedback loop after user action, matching 'clear sequence with most checkpoints present' despite a slightly confusing 'Step 2' / '1b' labeling gap.

4 / 5

Progressive Disclosure

Sections are organized, but the massive inline 'Curity Overview' term list is content that should be split out or pruned, and no bundle files or external references are used to offload detail, matching 'some structure but could be better organized; content that should be separate is inline'.

3 / 5

Total

13

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description cleanly states both what the skill does and when to use it, anchored to a distinctive product name. Its main weakness is generic action verbs ('manage', 'automate') rather than concrete capabilities, leaving it solid but not exemplary.

DimensionReasoningScore

Specificity

Names the domain ('Curity integration') and lists several actions ('Manage data, records, and automate workflows'), but the actions are generic verbs rather than concrete operations, matching the 'names domain and 1-2 concrete actions, not comprehensive' anchor.

3 / 5

Completeness

Both 'what' ('Manage data, records, and automate workflows') and an explicit 'when' ('Use when the user wants to interact with Curity data') are present, though the 'when' trigger is somewhat general rather than scenario-specific, fitting 'has both what and when; when could be more explicit'.

4 / 5

Trigger Term Quality

'Use when the user wants to interact with Curity data' supplies the core natural keyword 'Curity' and a reasonable trigger phrase, but offers no synonyms or variations, matching 'some relevant keywords but missing common variations'.

3 / 5

Distinctiveness Conflict Risk

The named product 'Curity' is a distinct niche trigger unlikely to fire for unrelated skills, though the generic 'manage data, records' phrasing keeps minor overlap risk, matching 'mostly distinct; minor overlap risk'.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.