CtrlK
BlogDocsLog inGet started
Tessl Logo

cyberark

CyberArk integration. Manage data, records, and automate workflows. Use when the user wants to interact with CyberArk data.

58

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/cyberark/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with concrete, copy-paste Membrane CLI commands and a well-sequenced connection workflow with state-based checkpoints. Its main weakness is a brief but unnecessary background explanation of what CyberArk/PAM is, plus some inline detail that could be split into referenced files.

Suggestions

Delete or trim the opening background paragraph ('CyberArk is a privileged access management (PAM) solution...') since Claude already knows what PAM is.

Add a brief validation/verification step after running actions (e.g. check the `output` field or error state) to strengthen the action-running workflow.

Consider moving the detailed clientAction state machine and the proxy flags table into a separate reference file to keep SKILL.md an overview.

DimensionReasoningScore

Conciseness

The body is mostly efficient with copy-paste CLI commands, but opens by explaining what CyberArk/PAM is ('CyberArk is a privileged access management (PAM) solution... This helps prevent cyber attacks...') and includes light filler ('so you can focus on the integration logic rather than auth plumbing') that Claude does not need. Not score 4 because the background paragraph is exactly the kind of concept explanation the rubric penalizes; not score 2 because the bulk is lean, actionable command reference.

3 / 5

Actionability

Commands are fully executable and copy-paste ready across the common cases — install, login, connection ensure/get, action list/run, and proxy request — plus a concrete flags table. Matches the score-5 anchor of fully executable commands covering common cases.

5 / 5

Workflow Clarity

The connection workflow is a clear sequenced state machine (install → auth → ensure → poll) with explicit checkpoints and a feedback loop ('poll again... to check if the state moved to READY'). Not score 5 because the action-running path lacks validation/verification of results; not score 3 because most checkpoints are present and explicit.

4 / 5

Progressive Disclosure

No bundle files exist, and the single file is organized into clear, well-labeled sections (Overview, Working with CyberArk, Install, Auth, Connecting, Searching, Popular actions, Best practices) with one-level navigation. Not score 5 because the skill exceeds 50 lines and inlines fairly detailed material (the clientAction sub-bullets, the proxy options table) that could live in referenced files; not score 3 because structure and signaling are good rather than merely present.

4 / 5

Total

16

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly identifies the CyberArk niche and includes an explicit 'Use when' clause, making it distinct and reasonably complete. Its weakness is generic action language ('manage data, records, automate workflows') and narrow trigger vocabulary that omit common CyberArk/PAM terms.

Suggestions

Replace generic verbs with concrete CyberArk actions, e.g. 'Manage safes, privileged accounts, credentials, and access requests' to lift specificity.

Broaden trigger terms to include natural synonyms a user might say, such as 'PAM', 'privileged access', 'safes', 'vault', or 'credentials'.

Tighten the 'what' to name 2-3 specific operations so the description reads as comprehensive rather than generic.

DimensionReasoningScore

Specificity

The description names the domain ('CyberArk integration') but its actions — 'Manage data, records, and automate workflows' — are generic and not concrete CyberArk-specific operations (e.g. manage safes, rotate credentials, retrieve privileged accounts). It does not reach score 3 because the actions are minimal/generic rather than 1-2 concrete ones, and not score 1 because the domain is explicitly named.

2 / 5

Completeness

Both halves are present: 'what' ('CyberArk integration. Manage data, records, and automate workflows.') and an explicit 'when' ('Use when the user wants to interact with CyberArk data.'). Not score 5 because the 'what' is generic rather than concrete trigger phrases; not score 3 because the 'when' clause is explicit rather than weakly implied.

4 / 5

Trigger Term Quality

The natural keyword 'CyberArk' is present and a user would say it, but the trigger vocabulary is limited to 'CyberArk' / 'CyberArk data', missing common synonyms a user might say such as 'PAM', 'privileged access', 'safes', 'vault', or 'credentials'. Not score 4 because several natural terms are missing; not score 2 because there is a relevant, naturally-spoken keyword rather than only jargon.

3 / 5

Distinctiveness Conflict Risk

CyberArk is a specific named product, giving the skill a clear niche with a distinct trigger ('interact with CyberArk data') and minimal conflict risk with other skills. Matches the score-5 anchor of a clear niche with distinct triggers.

5 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.